{"id":156,"date":"2008-11-16T14:26:36","date_gmt":"2008-11-16T14:26:36","guid":{"rendered":"https:\/\/fir3netwp.gmsrrpobkbd.com\/2008\/11\/16\/netscreen-create-a-policy-based-vpn\/"},"modified":"2023-02-04T08:23:29","modified_gmt":"2023-02-04T08:23:29","slug":"netscreen-create-a-policy-based-vpn","status":"publish","type":"post","link":"https:\/\/www.fir3net.com\/Firewalls\/Juniper\/netscreen-create-a-policy-based-vpn.html","title":{"rendered":"Netscreen – Create a Policy based VPN"},"content":{"rendered":"

This guide will show you how to create a policy based VPN on a Netscreen firewall.<\/p>\n

The encryption domain will be,<\/p>\n

Local Gateway : 2.2.2.2
\nLocal Endpoint : 10.1.1.0 \/24
\nRemote Gateway : 1.1.1.1
\nRemote Endpoint : 192.1.1.0 \/24<\/p>\n

1. Log into the Netscreens GUI
\n2. Click VPNs > Autokey IKE <\/strong>(Autokey IKE Screen is Below)<\/p>\n

3. Enter VPN Name<\/strong>
\n4. Select ‘Create a Simple Gateway’<\/strong>
\n5. Enter the Gateway Name<\/strong> (This will be the remote peer)
\n6. Enter the IP address<\/strong> of the Gateway
\n7. Enter Pre-shared Key<\/strong>
\n8. Select Outgoing Interface<\/strong>
\n9. Select ‘Advanced’<\/strong> (Advanced Autokey IKE screen is below)<\/p>\n

\"Netscreen <\/picture><\/p>\n

10. Select ‘Replay Protection’<\/strong>
\n11. Tick Proxy-ID<\/strong> and enter your encryption domain details. <\/span>* This is not required as the proxy id`s are created from the policy addresses.
\n12. Click ‘Return’<\/strong>
\n13. Click ‘OK’<\/strong><\/p>\n

Create a Policy<\/strong><\/p>\n

15. Goto Policy > Policies <\/strong>
\n16. Select ‘From Trust To Untrust’<\/strong>
\n17. Select ‘New’<\/strong><\/p>\n

\"Netscreen <\/picture><\/p>\n

18. Enter Source<\/strong> (local Endpoint)
\n19. Enter Destination<\/strong> (remote Endpoint)
\n20. Under Action select Tunnel<\/strong>
\n21. Under Tunnel select the Tunnel you just created
\n22. Tick ‘Modify matching bidirectional VPN policy’<\/strong>
\n23. Tick ‘Position at Top’<\/strong>
\n
\n<\/strong><\/p>\n

Troubleshooting<\/strong><\/p>\n

Heres a few commands that you can use in the event of any issues. The top 2 commands are (in my opinion) the most useful,<\/p>\n