Configuring Phase 1 Proposals for Dial Up VPN Users
Knowledge Base ID: KB4115
Version: 5.0
Published: 07 Oct 2008
Updated: 07 Oct 2008
Categories: . Firewall/IPSec_VPN
. IPSec
. ScreenOS

Synopsis:
Configuring Phase 1 Proposals for Dial Up VPN Users

Solution:

To configure a phase 1 proposal for dial up VPN users, perform the following steps:

Step one: Open the WebUI. For more information on accessing the WebUI, go to Accessing Your NetScreen, SSG, or ISG Firewall Using the WebUI

Step two: From the Juniper firewall menu, click VPNs, select AutoKey Advanced, and then click Gateway.

Image of step two

Step three: From the Gateway Name text box, enter a gateway name.

Note: For this example, we entered vpngateway1.

Image of step three and four

Step four: From Security Level, click to select Custom.

Step five: From Remote Gateway Type, click to select Dialup User, and then from the User drop-down menu, click to select your IKE username. For more information on configuring a dial up VPN user, go to Configuring a Dial Up VPN User.

Note: For this example, we selected vpnuser.

Image of step five


Step six: In the Preshared Key text box, enter a Preshared Key, and then click Advanced.

Image of step six

Step seven: From the Phase 1 Proposal drop-down menu, click to select a phase 1 proposal.

Note: Your Juniper firewall supports up to four proposals for Phase 1 negotiations, allowing you to define how restrictive a range of security parameters for key negotiation you will accept.

Note: For this example, we selected pre-g1-des-sha.

Image of step seven

Step eight: Click Return.

Image of step eight

Step nine: From the Edit page, click OK.

Image of step nine

Purpose:
Troubleshooting