Access to IPSec VPN through Netscreen-10 fw

Access to IPSec VPN through Netscreen-10 fw

NewsGroups | Search | Tools
 comp.dcom.vpn  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Access to IPSec VPN through Netscreen-10 fw srp336 03-28-2006
Posted by on March 28, 2006, 2:38 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I've got a situation where about 3 or 4 users will need to access an
IPSec VPN. They're all coming from a LAN which is behind a Netscreen-10
firewall which is using NAT. The device they're trying to connect to is
a Netgear FVL328. I don't think NAT-T is available on the Netgear box,
unless there's a new firmware out that I'm not aware of which supports
it (which could very well be...)

I thought about setting up a LAN-to-LAN vpn, but it looks like that
idea might be hard to sell to the remote side. I don't know if they'd
be open to replacing their VPN device with something NAT-T compatible.

Is there anything on the Netscreen-10 that can make this work? I'm kind
of new to this particular firewall.

Thanks!


Pure Networks
Posted by Somebody. on March 28, 2006, 3:51 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> I've got a situation where about 3 or 4 users will need to access an
> IPSec VPN. They're all coming from a LAN which is behind a Netscreen-10
> firewall which is using NAT. The device they're trying to connect to is
> a Netgear FVL328. I don't think NAT-T is available on the Netgear box,
> unless there's a new firmware out that I'm not aware of which supports
> it (which could very well be...)
>
> I thought about setting up a LAN-to-LAN vpn, but it looks like that
> idea might be hard to sell to the remote side. I don't know if they'd
> be open to replacing their VPN device with something NAT-T compatible.
>
> Is there anything on the Netscreen-10 that can make this work? I'm kind
> of new to this particular firewall.
>
> Thanks!

The NetScreen 10 is probably find nat'ing the ipsec packets, just make sure
it's the latest firmware for it which I believe is 3.03r8 or something like
that. Yes, it's an old box.

The NS10 is quite capable of doing a lan to lan vpn, I've still got clients
using pairs of those for corporate vpn concentrators, they're tough as nails
and very dependable.

-Russ.



Posted by on March 29, 2006, 6:05 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Do any changes need to be made on the Netscreen, or should it just work
as-is?

Thanks!


Posted by Somebody. on March 29, 2006, 6:59 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> Do any changes need to be made on the Netscreen, or should it just work
> as-is?
>
> Thanks!

It's been a long time since I worked on version 3 firmware. I have a vague
recollection of a setting like "ipsec-passthrough enable" or some such?
Have a look through the CLI reference for it.

-Russ.



Posted by on March 31, 2006, 11:07 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I see a line 'unset firewall bypass-others-ipsec' in the config, but I
can't seem to set it (the CLI doesn't seem to know what it is). Is this
a feature in ScreenOS that the Netscreen-10 doesn't support?


Similar ThreadsPosted
IKE and IPSEC October 10, 2007, 8:54 am
Need help routing IPX over IPsec February 10, 2005, 11:35 pm
GRE traffic over PIX IPSEC VPN June 6, 2005, 5:55 pm
trouble connecting XP over IPSec VPN March 4, 2005, 5:37 pm
IPSec over L2TP - Snapgear + NAT December 2, 2005, 3:07 am
Bintec VPN 25 - Zyxel VPN IPSec December 2, 2005, 4:30 am
IPSEC VPN using Belgian EID Card ? March 21, 2006, 9:06 am
Questions about IPSec Identifier January 16, 2007, 2:55 pm
vpn 3000 to checkpoint ipsec May 28, 2007, 6:06 am
A question for IPsec ---ISAKMP September 24, 2008, 10:49 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map