This example was taken from the Juniper Concepts and Examples guide located here:
http://kb.juniper.net/kb/documents/public/VPN/Interface_Failoverv14.pdf
set interface "tunnel.1" zone "Untrust"
Tunnel.1 should be the next available tunnel interface. Untrust represents the interface that terminates the VPN
set interface "tunnel.2" zone "Untrust"
This is the failover tunnel
set interface tunnel.1 ip unnumbered interface ethernet0/2
Physical interface that terminates the tunnel
set interface tunnel.2 ip unnumbered interface ethernet0/2
set ike gateway "ssg140gw primary" address 3.3.3.1 Main outgoing-interface "ethernet0/2"
preshare "7IdjSGXsNaD+jFsKKECjMI+YoEnL6AIo3w==" sec-level standard
Phase 1 settings
set ike gateway "ssg140gw backup" address 1.1.1.1 Main outgoing-interface "ethernet0/2"
preshare "4xoSwfrMNJqhzxs6xPCGiuCIginE8DWo3A==" sec-level standard
set ike respond-bad-spi 1
set vpn "ssg140vpn primary" gateway "ssg140gw primary" no-replay tunnel idletime 0 seclevel
standard
Phase 2
set vpn " ssg140vpn primary " monitor optimized rekey
set vpn " ssg140vpn primary " id 1 bind interface tunnel.1
set vpn "ssg140vpn backup" gateway " ssg140gw backup " no-replay tunnel idletime 0 seclevel
standard
set vpn " ssg140vpn backup " monitor optimized rekey
set vpn " ssg140vpn backup " id 2 bind interface tunnel.2
set vpn " ssg140vpn primary " proxy-id local-ip 172.16.10.0/24 remote-ip 10.1.1.0/24
"ANY"
set vpn " ssg140vpn backup " proxy-id local-ip 172.16.10.0/24 remote-ip 10.1.1.0/24 "ANY"
Friday, February 27, 2009
Juniper Route based VPN wth Failover VPN
Labels:
Juniper Netscreen,
VPN
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment