Create the Paris VPN
1.
In the device navigation tree, select
VPN Settings
>
AutoKey IKE/Manual VPN
.
2.
Select the Manual tab, then click the Add icon. The Properties screen appears.
3.
Configure the following:
•
For Name, enter
Paris_Tokyo
.
•
For Gateway, enter
2.2.2.2
.
•
For Local SP, enter
3020
.
•
For Remote SPI, enter
3030
.
•
For Outgoing Interface, select
ethernet3
.
•
For ESP/AH, select
ESP CBC
.
•
For Encryption Algorithm, select
3DES-CBC
, then select
Generate Key by Password
and enter the password
asdlk24234
.
•
For Authentication Algorithm, select
SHA-1
, then select
Generate Key by Password
and enter the password
PNas134a
.
4.
Select the Binding tab. Enable Tunnel Zone and select
untrust-tun
.
5.
Click
OK
to save the new VPN.
6.
Create Paris Routes.
Create the security policy
1.
In the main navigation tree, select
Policies
. Click the Add icon to display the new
Security Policy dialog box.
2.
Configure the following, then click
OK
:
•
For Security Policy Name, enter
Corporate Policy-Based VPN
.
•
Optionally, enter comments.
3.
In the main navigation tree, select
Policies
>
Corporate
Policy-Based VPN. The
security policy appears in the main display area. Configure two VPN rules.
•
Rule 1 creates the VPN tunnel from the Tokyo device to the Paris device.
•
Rule 2 creates the VPN tunnel from the Paris device to the Tokyo device.
4.
Save the security policy.
Example: Configuring a Policy-Based RAS VPN, L2TP
In this example, you create a RAS user group called Field Sales and configure an L2TP
tunnel called Sales_Corp, using ethernet3 (Untrust zone) as the outgoing interface for
the L2TP tunnel. The security device applies the default L2TP tunnel settings to the RAS
user group.
Copyright © 2010, Juniper Networks, Inc.
614
Network and Security Manager Administration Guide
Содержание NETWORK AND SECURITY MANAGER 2010.3
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Страница 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Страница 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Страница 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Страница 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Страница 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Страница 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Страница 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Страница 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Страница 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Страница 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Страница 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Страница 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Страница 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Страница 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Страница 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Страница 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Страница 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Страница 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...