<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Juniper: Create a policy based VPN tunnel between two sites for NetScreen devices</title>
	<atom:link href="http://insanelabs.com/networking/juniper-create-a-policy-based-vpn-tunnel-between-two-sites-for-netscreen-devices/feed/" rel="self" type="application/rss+xml" />
	<link>http://insanelabs.com/networking/juniper-create-a-policy-based-vpn-tunnel-between-two-sites-for-netscreen-devices/</link>
	<description>Umm... Unorthodox?</description>
	<lastBuildDate>Tue, 24 Jan 2012 15:56:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Stena</title>
		<link>http://insanelabs.com/networking/juniper-create-a-policy-based-vpn-tunnel-between-two-sites-for-netscreen-devices/comment-page-1/#comment-3696</link>
		<dc:creator>Stena</dc:creator>
		<pubDate>Fri, 21 Oct 2011 05:05:21 +0000</pubDate>
		<guid isPermaLink="false">http://insanelabs.com/?p=305#comment-3696</guid>
		<description>Ali, perfect. Thanks.</description>
		<content:encoded><![CDATA[ <img src='http://insanelabs.com/wp-content/plugins/wp-useragent/img/24/net/msie7.png' title='Internet Explorer 8.0' style='border:0px;vertical-align:middle;' alt='Internet Explorer 8.0'> Internet Explorer 8.0  <img src='http://insanelabs.com/wp-content/plugins/wp-useragent/img/24/os/win-4.png' title='Windows 7' style='border:0px;vertical-align:middle;' alt='Windows 7'> Windows 7<br><small>Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; EasyBits GO v1.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.3; .NET4.0C; Tablet PC 2.0)</small><p>Ali, perfect. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ali</title>
		<link>http://insanelabs.com/networking/juniper-create-a-policy-based-vpn-tunnel-between-two-sites-for-netscreen-devices/comment-page-1/#comment-3694</link>
		<dc:creator>Ali</dc:creator>
		<pubDate>Thu, 20 Oct 2011 14:33:49 +0000</pubDate>
		<guid isPermaLink="false">http://insanelabs.com/?p=305#comment-3694</guid>
		<description>Creating a tunnel from a subnet to subnet doesn&#039;t necessarily mean you will have access to every computer or service on the other side. In a policy based tunnel you will have to create a policy after a tunnel is created to allow access from one side to the other. Therefore, you can have the provider&#039;s IT limit their policy to allow your subnet access to those IP&#039;s only instead of creating a two way any-any policy. There might be other ways of doing that but this is what I would recommend.

As far as multiple IP&#039;s, you can either create three policies or add the IP&#039;s in Policy Elements, then select Multiple when you are creating the policy.</description>
		<content:encoded><![CDATA[ <img src='http://insanelabs.com/wp-content/plugins/wp-useragent/img/24/net/firefox.png' title='Firefox 7.0.1' style='border:0px;vertical-align:middle;' alt='Firefox 7.0.1'> Firefox 7.0.1  <img src='http://insanelabs.com/wp-content/plugins/wp-useragent/img/24/os/win-4.png' title='Windows 7 x64 Edition' style='border:0px;vertical-align:middle;' alt='Windows 7 x64 Edition'> Windows 7 x64 Edition<br><small>Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1</small><p>Creating a tunnel from a subnet to subnet doesn&#8217;t necessarily mean you will have access to every computer or service on the other side. In a policy based tunnel you will have to create a policy after a tunnel is created to allow access from one side to the other. Therefore, you can have the provider&#8217;s IT limit their policy to allow your subnet access to those IP&#8217;s only instead of creating a two way any-any policy. There might be other ways of doing that but this is what I would recommend.</p>
<p>As far as multiple IP&#8217;s, you can either create three policies or add the IP&#8217;s in Policy Elements, then select Multiple when you are creating the policy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stena</title>
		<link>http://insanelabs.com/networking/juniper-create-a-policy-based-vpn-tunnel-between-two-sites-for-netscreen-devices/comment-page-1/#comment-3693</link>
		<dc:creator>Stena</dc:creator>
		<pubDate>Thu, 20 Oct 2011 09:03:27 +0000</pubDate>
		<guid isPermaLink="false">http://insanelabs.com/?p=305#comment-3693</guid>
		<description>Ali,

I need you expert advise. I have to connect my office site with a service providers site over site to site ipsec vpn tunnel. I&#039;m using juniper ssg5. Now the service provider is not giving me access to their subnet but to specific host ip&#039;s within their network eg.192.168.4, 192.168.1.9 and 192.168.1.11. 

So how do i configure these remote ip details in the AUTOKE IKE screen of the Pase 2 proposal because on that screen it allows you to enter only 1 remote ip /netmask ?</description>
		<content:encoded><![CDATA[ <img src='http://insanelabs.com/wp-content/plugins/wp-useragent/img/24/net/msie7.png' title='Internet Explorer 8.0' style='border:0px;vertical-align:middle;' alt='Internet Explorer 8.0'> Internet Explorer 8.0  <img src='http://insanelabs.com/wp-content/plugins/wp-useragent/img/24/os/win-4.png' title='Windows 7' style='border:0px;vertical-align:middle;' alt='Windows 7'> Windows 7<br><small>Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; EasyBits GO v1.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.3; .NET4.0C; Tablet PC 2.0)</small><p>Ali,</p>
<p>I need you expert advise. I have to connect my office site with a service providers site over site to site ipsec vpn tunnel. I&#8217;m using juniper ssg5. Now the service provider is not giving me access to their subnet but to specific host ip&#8217;s within their network eg.192.168.4, 192.168.1.9 and 192.168.1.11. </p>
<p>So how do i configure these remote ip details in the AUTOKE IKE screen of the Pase 2 proposal because on that screen it allows you to enter only 1 remote ip /netmask ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tbde</title>
		<link>http://insanelabs.com/networking/juniper-create-a-policy-based-vpn-tunnel-between-two-sites-for-netscreen-devices/comment-page-1/#comment-3684</link>
		<dc:creator>tbde</dc:creator>
		<pubDate>Thu, 08 Sep 2011 08:39:13 +0000</pubDate>
		<guid isPermaLink="false">http://insanelabs.com/?p=305#comment-3684</guid>
		<description>Just to add more flesh to my earlier post,
Site-to-Site VPN is Route-Based (configured on router A btw internet interface in untrust zone and remote peer device;  Dialup VPN is Policy-Based and the remote clients have access to all resources on the LAN but as earlier indicated, do not have access to resources on LAN B.</description>
		<content:encoded><![CDATA[ <img src='http://insanelabs.com/wp-content/plugins/wp-useragent/img/24/net/firefox.png' title='Firefox 6.0.2' style='border:0px;vertical-align:middle;' alt='Firefox 6.0.2'> Firefox 6.0.2  <img src='http://insanelabs.com/wp-content/plugins/wp-useragent/img/24/os/win-3.png' title='Windows Vista' style='border:0px;vertical-align:middle;' alt='Windows Vista'> Windows Vista<br><small>Mozilla/5.0 (Windows NT 6.0; rv:6.0.2) Gecko/20100101 Firefox/6.0.2</small><p>Just to add more flesh to my earlier post,<br />
Site-to-Site VPN is Route-Based (configured on router A btw internet interface in untrust zone and remote peer device;  Dialup VPN is Policy-Based and the remote clients have access to all resources on the LAN but as earlier indicated, do not have access to resources on LAN B.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tbde</title>
		<link>http://insanelabs.com/networking/juniper-create-a-policy-based-vpn-tunnel-between-two-sites-for-netscreen-devices/comment-page-1/#comment-3683</link>
		<dc:creator>tbde</dc:creator>
		<pubDate>Thu, 08 Sep 2011 05:23:01 +0000</pubDate>
		<guid isPermaLink="false">http://insanelabs.com/?p=305#comment-3683</guid>
		<description>Hi Ali,

Am a newbie to the Juniper world and my enquiry is similar to one raisd by Murtuza. Forgive if I missed the answer. Site-to-Site IPSEC VPN exists between LAN (router)A and LAN (router)B. Client VPNs terminate on router A but have no connection to LAN B. Appreciate your help</description>
		<content:encoded><![CDATA[ <img src='http://insanelabs.com/wp-content/plugins/wp-useragent/img/24/net/firefox.png' title='Firefox 6.0.2' style='border:0px;vertical-align:middle;' alt='Firefox 6.0.2'> Firefox 6.0.2  <img src='http://insanelabs.com/wp-content/plugins/wp-useragent/img/24/os/win-3.png' title='Windows Vista' style='border:0px;vertical-align:middle;' alt='Windows Vista'> Windows Vista<br><small>Mozilla/5.0 (Windows NT 6.0; rv:6.0.2) Gecko/20100101 Firefox/6.0.2</small><p>Hi Ali,</p>
<p>Am a newbie to the Juniper world and my enquiry is similar to one raisd by Murtuza. Forgive if I missed the answer. Site-to-Site IPSEC VPN exists between LAN (router)A and LAN (router)B. Client VPNs terminate on router A but have no connection to LAN B. Appreciate your help</p>
]]></content:encoded>
	</item>
</channel>
</rss>

