SRX Services Gateway
Reply
Contributor
rotearc
Posts: 82
Registered: ‎07-10-2010
0

setup dynamic vpn as non-split vpn tunnel

[ Edited ]

Hi JNet experts,

 

I am trying to setup the dynamic vpn as non-split vpn.  All user traffics will forward through the vpn tunnel and then route to internet from the SRX.  Is it possible to do that?

 

Thanks,

 

rotearc

 

 

Contributor
rotearc
Posts: 82
Registered: ‎07-10-2010
0

Re: setup dynamic vpn as non-split vpn tunnel

I got it to work, it is quite interesting..  I have the vpn terminated at vpn zone, and I need to setup a NAT and firewall policy to allow from untrust zone to untrust zone.  Also, the remote resource is 0.0.0.0/0 in my case.

 

        from-zone untrust to-zone vpn {
            policy policy_in_wizard_dyn_vpn {
                match {
                    source-address any;
                    destination-address any;
                    application any;
                }
                then {
                    permit {
                        tunnel {
                            ipsec-vpn wizard_dyn_vpn;
                        }
                    }
                }
            }
        }
        from-zone untrust to-zone untrust {
            policy stupid-vpn-poilicy {
                match {
                    source-address 10.10.3.248/29;
                    destination-address any;
                    application any;
                }
                then {
                    permit;
                }
            }
        }

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.