ScreenOS Firewalls (NOT SRX)
Showing results for 
Search instead for 
Do you mean 
Reply
Contributor
Posts: 21
Registered: ‎09-25-2012
0
Accepted Solution

How to set up second VPN interface on the same UnTrust zone

[ Edited ]

Hi All,

 

How can I setup second VPN connection on untrust zone which has already another VPN interface?
If yes, can I use the same untrust IP address(wich I got from my ISP) as the first VPN using for the second tunnel or should I provide different IP address?

For example I have: 192.92.99.1 (UnTrust IP address).
Should I define : 192.92.99.2?Or can I use the 192.92.99.1.

 

I'm using ScreenOS WebUI Version: 6.2.0r5.0 (Firewall+VPN) 

 

Thanks in advance,

 

Trusted Contributor
Posts: 90
Registered: ‎01-24-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

Hi if you set up the tunnel and use unnumbered it borrows the ip address of the interface the tunnel is bound for. You can find out about this on kb4492

Pier
Network and telephony support engineer
JNCIA-FWV, CCNP Voice, CCNA
Trusted Contributor
Posts: 90
Registered: ‎01-24-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

Also http://kb.juniper.net/InfoCenter/index?page=content&id=KB8533 might help you on setting up the other route-based vpn.

Pier
Network and telephony support engineer
JNCIA-FWV, CCNP Voice, CCNA
Contributor
Posts: 21
Registered: ‎09-25-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

Hi Stac,

 

Thanks a lot for quick response, I did as you suggested, since there is first VPN interface defined on Policy, do I have to change or add another policy rule? 

Any 192.168.0.0/24

 

 

Thanks in advance,

Trusted Contributor
Posts: 90
Registered: ‎01-24-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

Can you share your config please?

Pier
Network and telephony support engineer
JNCIA-FWV, CCNP Voice, CCNA
Contributor
Posts: 21
Registered: ‎09-25-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

Stac sorry, since I'm relatively new to the VPN/FireWall stuff and here in forum, how is secure to post all the configuration, is there any certain part from config file that do you want to see?

Trusted Contributor
Posts: 90
Registered: ‎01-24-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

You could edit out the public ip addresses and any company names from the config.

If you want to set up another vpn, then yes you need another policy from your internal network to the clients network as the described in the kb article.

Pier
Network and telephony support engineer
JNCIA-FWV, CCNP Voice, CCNA
Contributor
Posts: 21
Registered: ‎09-25-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

[ Edited ]

OK,thanks a lot for your assistance.I'll try to follow your instruction.

Contributor
Posts: 21
Registered: ‎09-25-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

Hi Stac,

 

I got confused now, I have already Trust Zone define for the first VPN interface on plociy.

 

Trust ---> Untrust 


Any
192.168.0.0/24 ANY

 

Should I define additional policy for the same IP address: 192.168.0.0/24 ?

Is it makes sense?

 

Thanks,

Trusted Contributor
Posts: 90
Registered: ‎01-24-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

Hi Vadella,

 

I think you are mixing up VPN's and interface, they are two different things.

Do you want to create another interface? Or do you want to create a second vpn?

Pier
Network and telephony support engineer
JNCIA-FWV, CCNP Voice, CCNA
Contributor
Posts: 21
Registered: ‎09-25-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

Hi Stac,

 

May be,I want to set up second VPN connection.

 

Thanks,

 

Trusted Contributor
Posts: 90
Registered: ‎01-24-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

Where does the second vpn go to?

Did you set up a new network internally on your firewall for the new vpn?

Pier
Network and telephony support engineer
JNCIA-FWV, CCNP Voice, CCNA
Contributor
Posts: 21
Registered: ‎09-25-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

[ Edited ]

The second VPN should be to another external site.

I didn't set up network internally. I thought that I can use the same network which I have now for the first VPN.

Trusted Contributor
Posts: 90
Registered: ‎01-24-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

Hi Vadella,

 

Yes you can use the same internal network with a hub and spoke vpn, you should consider your firewall as the hub.

You can read about it in the following document

http://kb.juniper.net/kb/documents/public/VPN/routebasedhubandspokevpn_rev_1_3.pdf

Pier
Network and telephony support engineer
JNCIA-FWV, CCNP Voice, CCNA
Contributor
Posts: 21
Registered: ‎09-25-2012
0

Re: How to set up second VPN interface on the same UnTrust zone

Stac, thank you a lot for assistance!I'll read about it.