JuniperForum.com
September 09, 2010, 02:40:03 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: If you have an interesting idea for an article or knowledgebase entry, please submit it!
 
  Home Help Login Register  
* *
Pages: [1]
  Print  
Author Topic: NS25 and NS Remote - Want all client traffic to route through tunnel  (Read 202 times)
mbrown
Newbie
*
Posts: 7


View Profile
« on: July 27, 2010, 02:46:25 PM »

All:

I have searched and searched for an answer to this, and I haven't found it for sure yet.  I need one roaming external laptop (behind various NAT firewalls with dynamic public IPs) to be able to VPN into our NetScreen 25 and have all its traffic route through the tunnel and out the Internet access on the NS25's public IP address.  What is so frustrating is that years ago I did have this configured using an Xauth-based VPN, and now I can't figure it out.

I currently have a working policy-based Dial-Up VPN, but the external laptop has only LAN access through it.  Internet access does NOT come down the tunnel.  When I force "Use default gateway on remote network" on the Safenet Virtual Adapter, Internet access does not work at all (though LAN access still does, of course).

  • NS25 is running 5.3.0r7.0 (Firewall+VPN)
  • NSR is 10.3.5 (Build 6)
  • Laptop is WinXP Pro Sp3 fully up-to-date
  • LAN subnet is 10.100.1.0/24
  • LAN default gateway is NOT NS25, is another firewall
  • NSR is forcing 10.100.2.15 as Internal Network IP address
  • LAN gateway is routing 10.100.2.0/24 traffic to NS25 Trust interface

Even though the NS25 is not the default gateway of the LAN, the external laptop can ping everything inside properly due to the forced 10.100.2.15 IP and the routing I mentioned in the last bullet point.

If I can get Internet traffic to route through my existing Dial-UP VPN, that would be great.  If not, I am completely open to trashing this Dial-UP VPN and building a new one that will successfully route ALL traffic through the tunnel.

Thank you in advance for your help.

Logged
mbrown
Newbie
*
Posts: 7


View Profile
« Reply #1 on: July 28, 2010, 10:38:14 AM »

OK, today I figured out what I was doing wrong.  My two bi-directional policies were allowing only "Dial-Up VPN <--> LAN Subnet".  I changed these to "Dial-UP VPN <--> Any".  On the NS Remote, I changed the "Remote Party Identity and Addressing" section to "IP Subnet" and "0.0.0.0" for both the Subnet and Mask fields.  Now all traffic routes down the tunnel.

The NSR part I found in this article:
http://kb.juniper.net/KB4397

Logged
Pages: [1]
  Print  
 
Jump to:  

Navigation

Donate

Please consider donating if we've saved you time or money. It helps pay for the bandwidth, equipment, and hosting charges to keep this site running

Tools

Submit Article/KB - Do not submit questions here.

Recent

Stats

Members
Stats
  • Total Posts: 40719
  • Total Topics: 11389
  • Online Today: 82
  • Online Ever: 393
  • (August 06, 2008, 07:40:57 AM)
Users Online
Users: 0
Guests: 51
Total: 51
TinyPortal v1.0 beta 4 © Bloc
Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!

Sponsored in part by CollarWise

Page created in 0.209 seconds with 37 queries.