11-18-2010 04:19 AM
You know, I had to look this up. I had forgotten. The answer is: No. Both JunOS Pulse and the SRX-supplied dynamic VPN client only work on Windows. For now.
Unless you really like RADIUS servers, you want to wait for JunOS 10.4r2 anyway before deploying dynamic VPN (10.4r1 of you are feeling adventurous, of course). By that time, who knows, a Pulse client for OSX that supports SRX VPNs may have been released.
I wouldn't hold my breath, though.
11-18-2010 04:52 AM
Snow Leopard has an IPSEC VPN client built in, doesn't it? Previous versions show L2TP/IPSEC, but I think 10.6 can do native IPSEC. You'll know more about that than I do.
Similarly, Linux has native IPSEC VPN clients.
I'd use one of those clients with JunOS 10.4 (due out any day now). I think 10.4 will have support for pre-shared key on dynamic VPN - release notes will be the final word on that - and that means 3rdparty clients should work with a minimum of pain. I know 10.4 will drop the RADIUS server requirement, which is welcome.
07-01-2011 05:06 PM
how must I configure the SRX 210 to support the Snow Leopard native IPSec Client? In the configuration menu it says it is a "Cisco IPSec" Client.
With standard dynamic vpn setup it don't work.
Jul 2 01:44:19 KMD_PM_P1_POLICY_LOOKUP_FAILURE: Policy lookup for Phase-1 [responder] failed for p1_local=ipv4(any:0,[0..3]=22.214.171.124) p1_remote=ipv4(any:0,[0..3]=126.96.36.199)
07-04-2011 09:00 PM - edited 07-04-2011 09:01 PM
You could try looking at the Shrew client - I've installed this on a Mac and got it connected to an SSG OK. Other posts here describe configuring Shrew to connect to an SRX.
07-04-2011 09:27 PM
Is this compatible with Dynamic VPN on the SRX?
I look at shrew and on the homepage there are only official builds for linux and windows?!?
Other people in this forum have posted configs for Shrew to SRX Dynamic VPN, and I can definitely confirm a Shrew OSX client works fine to a ScreenOS firewall.
Details on a Shrew OSX client can be found here : http://lists.shrew.net/pipermail/vpn-help/2010-November/003223.html
It requires are pretty large download for the QT package.