SRX Services Gateway
Reply
Visitor
fire2power
Posts: 6
Registered: ‎10-30-2008
0
Accepted Solution

How to change SRX route-based VPN proxy id

Hi there, I've searched the Junos security config guide and this forum too but it's still unclear on how to manually set proxy-id for route-based VPN. The manuals just said it has to match on both ends but it didn't mention how to set it up to match the other end especially the other end is a 3rd party device. And also is there a way to use "ip unnumbered" like SSG for the st0 interface? If SRX is connecting to 3rd party VPN endpoint, they don't care about st0 interface IP at all. So does it matter which IP to use? I just tested in our lab to connect SRX to SSG and I didn't set any IP address in st0.0 at all. The VPN tunnel seems to be working too. So I wonder what's the point of st0 IP? Rgds, Lawrence
Juniper Employee
masterof1
Posts: 6
Registered: ‎10-04-2010
0

Re: How to change SRX route-based VPN proxy id

root@SRX5800# set ike proxy-identity local 10.0.0.0/8 remote 192.168.1.0/24

 

Super Contributor
oldtimer
Posts: 227
Registered: ‎11-06-2007
0

Re: How to change SRX route-based VPN proxy id

... correction

 

set security ipsec vpn vpn-name ike proxy-identity local 10.0.0.0/8 remote 192.168.1.0/24 service any

Juniper Employee
masterof1
Posts: 6
Registered: ‎10-04-2010

Re: How to change SRX route-based VPN proxy id

[ Edited ]

Guess it is important to provide the configuration stanza. Sorry about that!

 

[edit security ipsec vpn vpn-name]

root@SRX5800# set ike proxy-identity local 10.0.0.0/8 remote 192.168.1.0/24

 


 Thanks for catching that oldtimer. Appreciate it

Visitor
fire2power
Posts: 6
Registered: ‎10-30-2008
0

Re: How to change SRX route-based VPN proxy id

Thanks all. I'll test it in lab later on.
Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.