I have followed this tutorial to a T.
http://www.shrew.net/support/wiki/HowtoJuniperSsg
I am able to connect using XAUTH to the VPN. I am only able to communicate to my SSG via the local IP 10.1.1.1.
I can ping the router and telnet in however I am not able to talk to the machines behine my SSG from a remote location using the shrew client.
My Policy Log:
2009-12-27 11:12:30 10.1.1.10:65112 10.1.1.5:53 10.1.1.10:65112 10.1.1.5:53 DNS 60 sec. 97 0 Close - AGE OUT 2009-12-27 11:12:30 10.1.1.10:65466 10.1.1.5:53 10.1.1.10:65466 10.1.1.5:53 DNS 60 sec. 90 0 Close - AGE OUT 2009-12-27 11:12:30 10.1.1.10:58084 10.1.1.5:53 10.1.1.10:58084 10.1.1.5:53 DNS 60 sec. 94 0 Close - AGE OUT 2009-12-27 11:12:00 10.1.1.10:55996 10.1.1.3:2492 10.1.1.10:55996 10.1.1.3:2492 TCP PORT 2492 22 sec. 70 0 Close - AGE OUT 2009-12-27 11:11:38 10.1.1.10:55996 10.1.1.3:2492 10.1.1.10:55996 10.1.1.3:2492 TCP PORT 2492 0 sec. 0 0 Creation 2009-12-27 11:11:34 10.1.1.10:56181 10.1.1.5:53 10.1.1.10:56181 10.1.1.5:53 DNS 0 sec. 0 0 Creation 2009-12-27 11:11:34 10.1.1.10:315 10.1.1.7:1 10.1.1.10:315 10.1.1.7:1 ICMP 0 sec. 0 0 Creation 2009-12-27 11:11:33 10.1.1.10:54185 10.1.1.5:53 10.1.1.10:54185 10.1.1.5:53 DNS 0 sec. 0 0 Creation 2009-12-27 11:11:31 10.1.1.10:63074 10.1.1.5:53 10.1.1.10:63074 10.1.1.5:53 DNS 0 sec. 0 0 Creation 2009-12-27 11:11:30 10.1.1.10:58084 10.1.1.5:53 10.1.1.10:58084 10.1.1.5:53 DNS 0 sec. 0 0 Creation
The 10.1.1.10 is my Virtual IP which I succsessfully get from the IP Pool I created within the SSG
the 10.1.1.5 is my DNS server.
I am able to ping SSG via 10.1.1.1
I have added a VPN Policy from trust to untrust which made the policy bidirectional (which I do not think I need) did not make a difference. i never needed that before however I saw that someone said to do that from within this forum.
I am not sure what to do next. Thanks
UPDATE:
I have been using an IP Pool of the same IP as my internal subnet (behind my firewall). I have read that you should use a unique IP POOL. I have since changed it and will test this tomorrow when I am off my network.
If I am wrong please let me know.