To configure the NetScreen-Remote client side VPN with XAuth, perform the following steps:

From the
Start menu, select
Programs, select
NetScreen-Remote, and then click
Security Policy Editor.


From the
Security Policy Editor dialog box, click the 'Add a new connection' icon.


Enter a name for your new connection.

For this example, we used the default name
New Connection.


From
Remote Party Identity and Addressing, in the
ID Type drop-down menu, click to select
IP Subnet.


In the
Subnet and
Mask text boxes, enter a
Subnet and
Mask.

For this example, we used
172.16.10.0 and
255.255.255.0.


Click to select
Connect using, and then from the drop-down menu, click to select
Secure Gateway Tunnel.


From the
ID Type drop-down menu, click to select
IP Address, then enter the untrusted IP Address of the Firewall.

For this example, we have entered
1.1.1.1 for the untrusted IP address of the Firewall.

Click the
+ to expand
New Connection.


Click to select
My Identity, and then from the
Select Certificate drop-down menu, click to select
None.


From the
ID Type drop-down menu, click to select
E-mail Address.


Enter the email address corresponding to the ID. From the
Virtual Adapter drop-down menu, click to select
Preferred.

For this example, we have used
xauth@auth.com. This is the IKE user's simple identity and not their username. The email address can be a username or an actual email address; it does need to match the settings on the Juniper Firewall.

From the
Pre-Shared Key dialog box, click
Enter Key, and then enter the
Pre-Shared Key.

The
Pre-Shared Key will need to match the one configured on the Firewall device for this connection.


Click
OK.

Click to select
Security Policy, and then click to select
Aggressive Mode.


Click the
+ to expand
Security Policy.


Click the
+ to expand
Authentication (Phase 1).

Click to select Proposal 1.
From the Authentication Method drop-down menu, click to choose Pre-Shared Key; Extended Authentication.
From the Encrypt Alg drop-down menu, click to choose an encryption type. From the Hash Alg drop-down menu, click to choose an authentication type.
For this example, we have used DES for Encrypt Alg and MD5 for Hash Alg.


From the
Key Group drop-down menu, click to select
Diffie-Hellman Group 1.

Click the
+ to expand
Key Exchange (Phase 2).


Click to select
Proposal 1.

From the
Encrypt Alg drop-down menu, click to choose encryption type. From the
Hash Alg drop-down menu, click to choose authentication type.

For this example, we have used
DES for
Encrypt Alg and
MD5 for
Hash Alg.


In the
Encapsulation drop-down menu, click to select
Tunnel.

From the
Security Policy Editor dialog box, click
File, and then click
Save Changes.
