SRX Services Gateway
Showing results for 
Search instead for 
Do you mean 
Reply
Visitor
Posts: 6
Registered: ‎10-30-2008
0 Kudos
Accepted Solution

How to change SRX route-based VPN proxy id

Hi there, I've searched the Junos security config guide and this forum too but it's still unclear on how to manually set proxy-id for route-based VPN. The manuals just said it has to match on both ends but it didn't mention how to set it up to match the other end especially the other end is a 3rd party device. And also is there a way to use "ip unnumbered" like SSG for the st0 interface? If SRX is connecting to 3rd party VPN endpoint, they don't care about st0 interface IP at all. So does it matter which IP to use? I just tested in our lab to connect SRX to SSG and I didn't set any IP address in st0.0 at all. The VPN tunnel seems to be working too. So I wonder what's the point of st0 IP? Rgds, Lawrence
Juniper Employee
Posts: 6
Registered: ‎10-04-2010
0 Kudos

Re: How to change SRX route-based VPN proxy id

root@SRX5800# set ike proxy-identity local 10.0.0.0/8 remote 192.168.1.0/24

 

Super Contributor
Posts: 241
Registered: ‎11-06-2007
0 Kudos

Re: How to change SRX route-based VPN proxy id

... correction

 

set security ipsec vpn vpn-name ike proxy-identity local 10.0.0.0/8 remote 192.168.1.0/24 service any

Highlighted
Juniper Employee
Posts: 6
Registered: ‎10-04-2010

Re: How to change SRX route-based VPN proxy id

[ Edited ]

Guess it is important to provide the configuration stanza. Sorry about that!

 

[edit security ipsec vpn vpn-name]

root@SRX5800# set ike proxy-identity local 10.0.0.0/8 remote 192.168.1.0/24

 


 Thanks for catching that oldtimer. Appreciate it

Visitor
Posts: 6
Registered: ‎10-30-2008
0 Kudos

Re: How to change SRX route-based VPN proxy id

Thanks all. I'll test it in lab later on.
Contributor
Posts: 227
Registered: ‎01-12-2010
0 Kudos

Re: How to change SRX route-based VPN proxy id

sorry but i need to ask this question ...

 

what is the purpose of specifying proxy-id ?

Ajaz Nawaz
JNCIE-SEC#254 CCIE#15721
JNCIA-FWV | JNCIS-FWV
JNCIA-JUNOS | JNCIS-SEC
JNCIP-SEC | JNCIE-SEC
CCNP-Collaboration