Netscreen 500 Firewall & PIX Cisco firewall
Afrah Ahmed <[email protected]> Sun, 21 Nov 2004 01:25:16 -0800 (PST)
| Newsgroups | gmane.comp.security.vpn |
|---|---|
| Message-ID | <[email protected]> |
Hi all, I need urgent help to establish Policy-Based VPN between our Netscreen 500 Firewall & PIX Cisco Firewall at the other end. Can any body help me with this please ? Is something wrong with my settings ? Why the VPN doesnt come up at both sides ? We want to configure a bi-directional Policy-Based VPN between a server in the DMZ Zone in our Netscreen 500 firewall and a server on the Internet Untrust Zone. Our sever (which is in the DMZ Zone) has a MIP on the Untrust Interface and therefore in the Global Zone. Our problem is that we cant establish the bi-directional policy if we started configuring Untrust to Global policy; i.e. we it gives us error. However we can establish bi-directional policy if we configure Untrust-to-DMZ policy, but no IP address translation to our server IP address. Both DMZ & Untrust Interfaces are in the Route mode. Blow is our configuration Zones & Intefaces Settings : set zone "Untrust" vrouter "untrust-vr" set zone "DMZ" vrouter "untrust-vr" set interface ethernet2/1 ip 192.168.36.1/24 set interface ethernet2/1 route set interface ethernet2/2 ip 193.188.117.65/29 set interface ethernet2/2 route set interface "ethernet2/2" mip 217.17.247.52 host 192.168.36.37 netmask 255.255.255.255 vrouter "trust-vr" set interface "ethernet2/2" mip 217.17.247.53 host 192.168.36.39 netmask 255.255.255.255 vrouter "trust-vr" Addresses Settings : set address "Untrust" "213.139.63.207/32" 213.139.63.207 255.255.255.255 set address "Untrust" "MobileCom1" 213.139.63.200 255.255.255.255 set address "Untrust" "MobileCom2" 213.139.63.201 255.255.255.255 set address "Untrust" "MobileComIn" 213.139.63.207 255.255.255.255 set address "DMZ" "Mail In" 192.168.36.39 255.255.255.255 set address "DMZ" "Mail Out" 192.168.36.37 255.255.255.255 set group address "Untrust" "MobileCom" set group address "Untrust" "MobileCom" add "MobileCom1" set group address "Untrust" "MobileCom" add "MobileCom2" set group address "DMZ" "MMS MTA" set group address "DMZ" "MMS MTA" add "Mail In" set group address "DMZ" "MMS MTA" add "Mail Out" VPN Settings : set ike gateway "MobileCom-GW" address 213.139.32.52 Main outgoing-interface "ethernet2/2" preshare "" proposal "pre-g2-3des-sha" set ike gateway "MobileCom-GW" cert peer-cert-type pkcs7 set ike respond-bad-spi 1 set ike p2-proposal "Mobilecom-P2" group2 esp 3des sha-1 second 3600 kbyte 4194303 set vpn " MobileCom-VPN " gateway "MobileCom-GW" no-replay tunnel idletime 0 proposal "Mobilecom-P2" Policies : set policy id 103 from "Untrust" to "Global" "MobileCom" "MIP(217.17.247.53)" "ANY" tunnel vpn "MobileCom-VPN" id 96 log count set policy id 102 from "DMZ" to "Untrust" "Mail Out" "MobileComIn" "ANY" tunnel vpn "MobileCom-VPN" id 101 log count --------------------------------- Do you Yahoo!? Discover all thats new in My Yahoo! _______________________________________________ VPN mailing list [email protected] http://lists.shmoo.com/mailman/listinfo/vpn