Configuring the NetScreen-Remote Client to a Juniper Firewall Device VPN With XAuth
Knowledge Base ID: KB4182
Version: 4.0
Published: 07 Oct 2008
Updated: 07 Oct 2008
Categories: . NS-5GT
. NS-5XP
. NS-5XT
. NS-25
. NS-50
. NS-204
. NS-208
. NS-5200
. NS-5400
. IPSec

Synopsis:
Configuring the NetScreen-Remote Client to a Juniper Firewall Device VPN With XAuth

Solution:


Extended Authentication (XAuth) was added to ScreenOS to incorporate with NetScreen-Remote Client.

XAuth allows another layer of authentication for VPN between a Remote Client and a Juniper Firewall VPN device. You may verify authentication to the firewall device's local authentication database using a Radius, Secure ID, or an LDAP server. You may also use groups to combine the dial-up users or use individual dial-up users. You cannot use the group function if you are using Secure-ID or an LDAP server.

To configure the NetScreen-Remote to a Firewall device VPN with XAuth, perform the following:

Step one: Configure the Firewall device side with XAuth. For more information on configuring the Firewall device side with XAuth, go to Configuring the Juniper Firewall Device Side VPN With XAuth.

Step two: Configure the NetScreen-Remote side. For more information on configuring the NetScreen-Remote side, go to Configuring the NetScreen-Remote Client Side VPN With XAuth.

Purpose:
Troubleshooting