Netscreen 500 Firewall & PIX Cisco firewall

Afrah Ahmed <[email protected]> Sun, 21 Nov 2004 01:25:16 -0800 (PST)
Newsgroups gmane.comp.security.vpn
Message-ID <[email protected]>
Hi all,
 I need urgent help to establish Policy-Based VPN between our Netscreen 500 Firewall & PIX Cisco Firewall at the other end. Can any body help me with this please ? Is something wrong with my settings ? Why the VPN doesn’t come up at both sides ?

 

 We want to configure a bi-directional Policy-Based VPN between a server in the “DMZ Zone” in our Netscreen 500 firewall and a server on the Internet “Untrust Zone”. Our sever (which is in the DMZ Zone) has a MIP on the “Untrust Interface” and therefore in the “Global Zone”.

 

 Our problem is that we can’t establish the bi-directional policy if we started configuring “Untrust –to Global” policy; i.e. we it gives us error. However we can establish bi-directional policy if we configure “Untrust-to-DMZ” policy, but no IP address translation to our server IP address.

 Both “DMZ” & “Untrust” Interfaces are in the “Route” mode.

 Blow is our configuration 

 Zones & Intefaces Settings :



set zone "Untrust" vrouter "untrust-vr"

set zone "DMZ" vrouter "untrust-vr"

 

set interface ethernet2/1 ip 192.168.36.1/24

set interface ethernet2/1 route

set interface ethernet2/2 ip 193.188.117.65/29

set interface ethernet2/2 route         

 

set interface "ethernet2/2" mip 217.17.247.52 host 192.168.36.37 netmask 255.255.255.255 vrouter "trust-vr"

 

set interface "ethernet2/2" mip 217.17.247.53 host 192.168.36.39 netmask 255.255.255.255 vrouter "trust-vr"   

Addresses Settings :



set address "Untrust" "213.139.63.207/32" 213.139.63.207 255.255.255.255

set address "Untrust" "MobileCom1" 213.139.63.200 255.255.255.255

set address "Untrust" "MobileCom2" 213.139.63.201 255.255.255.255

set address "Untrust" "MobileComIn" 213.139.63.207 255.255.255.255

 

set address "DMZ" "Mail In" 192.168.36.39 255.255.255.255

set address "DMZ" "Mail Out" 192.168.36.37 255.255.255.255

 

set group address "Untrust" "MobileCom"

set group address "Untrust" "MobileCom" add "MobileCom1"

set group address "Untrust" "MobileCom" add "MobileCom2"          

 

set group address "DMZ" "MMS MTA"

set group address "DMZ" "MMS MTA" add "Mail In"

set group address "DMZ" "MMS MTA" add "Mail Out"               

 

 VPN Settings :                                                                           

set ike gateway "MobileCom-GW" address 213.139.32.52 Main outgoing-interface "ethernet2/2" preshare "" proposal "pre-g2-3des-sha"

 

set ike gateway "MobileCom-GW" cert peer-cert-type pkcs7

set ike respond-bad-spi 1

 

set ike p2-proposal "Mobilecom-P2" group2 esp 3des sha-1 second 3600 kbyte 4194303

 

set vpn " MobileCom-VPN " gateway "MobileCom-GW" no-replay tunnel idletime 0 proposal "Mobilecom-P2"

 Policies :



set policy id 103 from "Untrust" to "Global"  "MobileCom" "MIP(217.17.247.53)" "ANY" tunnel vpn "MobileCom-VPN" id 96 log count

 

set policy id 102 from "DMZ" to "Untrust"  "Mail Out" "MobileComIn" "ANY" tunnel vpn "MobileCom-VPN" id 101 log count





		
---------------------------------
Do you Yahoo!?
 Discover all that’s new in My Yahoo!

_______________________________________________
VPN mailing list
[email protected]
http://lists.shmoo.com/mailman/listinfo/vpn