How do I configure NetScreen-Remote using Preshared Keys? (KB ID: KB5746)
| Article ID: | KB5746 |
|---|---|
| Former Article ID: | nskb2382 |
| Published: | May 25, 2006 |
| Last Modified: | May 25, 2006 |
| Visible By: | Employee, PTAC, Partner, Customer, Public |
Back to Previous Page | Knowledge Base Home
Article URL
Synopsis
How do I configure NetScreen-Remote using Preshared Keys?
Problem
Environment:
- Preshared Secret
- VPN Client
- Do not have a choice to enter preshared secret after clicking My Identity
Solution
Creating a Dial Up VPN from NetScreen-Remote to NetScreen has been supported since ScreenOS 2.5. The minimum requirements are:
- NetScreen device running ScreenOS 2.5 or higher
- NetScreen-Remote 2.0 or higher
- The NetScreen device must have a statically assigned IP address on the Untrust interface. If the NetScreen obtains its IP address via DHCP or PPPoE, Dial Up VPN is not supported to that NetScreen
Basic Steps:
-
Create a Dial Up VPN User. If a Dial Up VPN Group is desired, add the Dial Up VPN User to that group
-
Create an IKE Gateway (P1), and specify a Preshared Secret to be used by everyone in that group
-
Create the VPN (P2), specifying the IKE Gateway that was defined in step 2.
-
Create the VPN Policy, using the tunnel as specified in step 3.
Example: Assume a remote user needs to VPN into the corporate network. The network topology is shown below:

Assume the Remote user is given an IKE ID with email address remote@acme.com. The untrust gateway of the NetScreen (which is the security gateway that NetScreen-Remote will talk to) is 1.1.1.1. The destination is the internal network 172.16.10.0/24 (or 172.16.10.0 255.255.255.0).
This example shows how to configure the VPN based on ScreenOS 2.6.0 and NetScreen-Remote 7.0:
Configure Address Book Entry for the Internal Network:
- Click Address
- Click Trust tab
- Click New Address
- Name: Internal Net
- IP Address: 172.16.10.0
- Netmask: 255.255.255.0
- Click OK.
Create the Dial Up VPN User
- Click Users
- Click New IKE/L2TP Users/Group
- Name: Remote User
- Click Enable
- Select IKE User
- IKE Identity: remote@acme.com
Create the Phase 1 Proposals:
- Click the VPN Button
- Click IKE Gateway tab
- Click New Remote Gateway
- Name: Remote GW
- Click Dial Up User
- User Group: Remote User
- Click Aggressive mode
- Phase 1 Proposal: pre-g2-3des-md5
- Preshared Key: NetScreen
- Click OK.
Create the Phase 2 Proposals:
- Name: Remote VPN
- Gateway: Select Remote GW
- Phase 2 Proposal: nopfs-esp-3des-md5
- Replay Protection: Leave disabled
- VPN Monitor: Leave disabled
- Click OK
Configure the Policy for the Dial Up VPN
In ScreenOS 2.6 and higher, the Dial Up VPN policy requires one incoming policy. For ScreenOS 2.5 and below, the Dial Up VPN policy requires only one outgoing policy.
For ScreenOS 2.6:
- Click Policy button
- Click the Incoming tab
- Click New Policy
- Source Address: Dial-Up VPN
- Destination Address: Internal Net
- Service: Any
- VPN Tunnel: Remote VPN
- Click OK
Note: In ScreenOS 3.0.0 or higher, the Tunnel field is equivalent to the VPN Tunnel field in ScreenOS 2.6.0.
NetScreen Remote Configuration
- Create a New Connection
- ID Type: IP Subnet
- Subnet: 172.16.10.0
- Mask: 255.255.255.0
- Click Connect using Secure Gateway Tunnel
- ID Type: IP address, 1.1.1.1
- Expand the New Connection
- Click Security Policy
- Under Select Phase 1 Negotiation Mode, select Aggressive Mode.
- De-select Replay Protection
- Expand Security Policy
- Expand Authentication (Phase 1)
- Click Proposal 1
- Authentication Method: Pre-Shared Key
- Encrypt Alg: Triple DES
- Hash Alg: MD5
- Key Group: Diffie-Helman Group 2
- Expand Key Exchange (Phase 2)
- Click Proposal 1
- Encrypt Alg: Triple DES
- Hash Alg: MD5
- Click My Identity
- Click Preshared Key
- Click Enter Key
- Enter the Preshared Key NetScreen
- Click OK
- Select Certificate: None
- ID Type: Email Address
- Enter the email address remote@acme.com in the field below ID Type
- Save the security policy by clicking the floppy disk icon
Category Description
By Product » Software » Network Operating Systems » ScreenOS Software » 2.6.x » 2.6.1
By Product » Software » Network Operating Systems » ScreenOS Software » 2.6.x » 2.6.0
By Product » Software » Network Operating Systems » ScreenOS Software » 2.5.x » 2.5.0
By Product » Software » VPN Clients » NetScreen-Remote Security Client
By Product » Software » VPN Clients » NetScreen-Remote VPN Client
By Network Technology » IP Protocols » Tunneling Protocols » IPSec
Purpose
Troubleshooting

