To configure phase 2 proposals, perform the following steps:

Open the
WebUI. For more information on accessing the WebUI, go to
Accessing Your NetScreen, SSG, or ISG Firewall Using the WebUI

From the Juniper Firewall menu, click
VPNs, and then click
AutoKey IKE.


From the
AutoKey IKE page, click
New.


In the
VPN Name text box, enter a VPN Name.

For this example, we entered
dialupvpn1.


From
Security Level, click to select
Custom.

From
Remote Gateway, in the
Predefined drop-down menu, click to select your predefined gateway. For more information about configuring predefined gateways, go to
Configuring Phase 1 Proposals.

For this example, we selected
vpngateway1.


Click
Advanced.


From the
Phase 2 Proposal drop-down menu, click to select a Phase 2 Proposal.

Your Juniper Firewall supports up to four proposals for Phase 2 negotiations, allowing you to define how restrictive a range of security parameters for key negotiation you will accept.

For this example, we chose one proposal, and selected
nopfs-esp-des-sha.


Click
Return.


Click
OK.
