
This article applies to NetScreen-Remote VPN Client 8.0 and above.
To log into the VPN with NetScreen-Remote using pre-shared secrets, perform the following steps:

From the
Start menu, click
Programs, click
NetScreen-Remote, and then click
Security Policy Editor.


From the
Security Policy Editor dialog box, click the
Add a new connection icon.


Click
New Connection.


From
Remote Party Identity and Addressing, in the
ID Type drop-down menu, click to choose either
IP Address, or
IP Subnet.

For this example, we chose
IP Subnet.


Enter the destination
Subnet and
Mask.

For this example, we entered a
Subnet of
192.168.1.0 with a
Mask of
255.255.255.0.


Click
Connect using.


From the
ID Type drop-down menu, select
IP Address, and then enter the remote gateway IP address.

For this example, we entered
1.1.1.1.

Expand the
New Connection icon.


Click
Security Policy, and then click to select
Aggressive Mode.


Click to select
My Identity.


From
My Identity, in the
Select Certificate drop-down menu, click to select
None.


From the
ID Type drop-down menu, click to select
E-mail Address, and then enter your IKE Identity.

For this example, we entered
vpnuser@abc.com.


Click
Pre-Shared Key.


From the
Pre-Shared Key dialog box, click
Enter Key, and then enter your Pre-Shared key.


Click
OK.

Expand
Security Policy, expand
Authentication (Phase 1), and then click
Proposal 1.


From
Encryption and Data Integrity Algorithms, click to select your
Encrypt Alg,
Hash Alg, and
Key Group.

For this example, we chose the default values of
DES,
SHA-1, and
Diffie-Hellman Group 1.


Expand
Key Exchange (Phase 2), and click
Proposal 1.


From
Encapsulation Protocol (ESP), select your
Encrypt Alg and
Hash Alg.

For this example, we chose the default values of
DES and
SHA-1.


Click
File, and then click
Save.


After the NetScreen-Remote client has been configured, you can make the IKE VPN negotiate by sending traffic through the VPN. In this example, we have sent a ping to
192.168.1.10 (an IP Address on the Trust side of the Juniper Firewall) from the client. After 3 or 4 pings, the VPN should be established.
