Great writeup! I’ve been looking for this exact documentation and finally found your site last night. Juniper needs to update their documentation to match the latest technology. I’ve followed this step-by-step on my SSG140 and my connections are failing. I get the following message in my firewall event log. Rejected an IKE packet on ethernet0/1() because an initial Phase 1 packet arrived from an unrecognized peer gateway. I’ve double checked and I’m using the outside or untrust interface as the outgoing interface. I have two untrust interfaces on this firewall. One is used only for VPN traffice (site to site and I hope dialup soon) and the other is all other untrusted traffic (internet, e-mail, etc). Do you have any suggestions on what to look at next? Thanks for the help! Randy Smith
Hey Randy, Would you mind creating a forum post for this question ? You can create a new thread (and subscribe to updates) at http://www.corelan.be:8800/index.php/forum/screenos-vpn-1 thanks
Thanks for manual. Could i use this dialup vpn for accessing branch office LAN, which is connected via route-based site-to-site tunnel with manual key? I tried to create a policy from vpnbuffer to branch-office zone and configured vpn-client’s route to branch-office ip net, but nothing works. Am i doing right?