Great Blog – I have a Netscreen-Cisco vpn tunnel. Policy-based. Cisco-side: permit ip s.s.s.s m.m.m.m d.d.d.d m.m.m.m NetScreen-side: policy (action:tunnel). services configured are: FTP Telnet – i can configure ftp and telnet on the netscreen side and i’m fine. i can also configure ‘any’ and i’m fine. however when the cisco side is changed from just permit ip ….. to ‘permit tcp ssss mmm eq telnet’ and ‘…eq ftp’ the only way it works on the netscreen is to have individual policies. not efficient. it doesn’t appear to allow multiple services to be specified and gives an error ‘not policy for proxy-id received’ can this be done?
Hi, Yeah, this is a limitation when setting up tunnels between Juniper and non-Juniper devices. I read something, however, about the latest ScreenOS versions (6.3 I think), and the ability to auto-generate proxy ID’s…. not sure if that applies to IP ranges and/or services, but if you have a support contract for the netscreen, you may want to get the latest screenos version and give it a try