Juniper Networks ScreenOS Firewall
To configure the tunnel in the Juniper Networks ScreenOS Management Portal:
-
Log in to the Juniper Networks ScreenOS Management Portal with the Administrator account.
-
From the left pane. go to Network > Interfaces.
-
Create a new Unnumbered tunnel interface.
-
From the left pane, go to Network > Routing > Source:
-
Select an appropriate zone and click New.
-
In the IP Address/Netmask field, enter the Harmony SASE network subnet.
-
For Next Hop, select gateway.
-
Click OK.
-
-
From the left pane, click VPN:
-
Select AutoKey Advanced.
-
Verify that the PI Proposal is listed as shown in the following graphic.
-
Go to P2 Proposal and ensure the proposal is listed as shown in the following graphic.
-
-
From the left pane, click Gateway:
-
In the Gateway Name field, enter a name for the gateway.
-
Select Remote Gateway and then select Static IP Address.
-
In the IP Address/Hostname field, enter the public IP address of Harmony SASE gateway.
-
Click Advanced:
-
In the Preshared Key field, enter the secret key specified in Configuring the Tunnel in the Harmony SASE Administrator Portal.
-
In the Security Level section, select Custom and from the Phase 1 Proposal list, select pre-g5-aes256-sha1-28800s.
-
Enable DPD and set DPD Interval to 10s and DPD Retry to 5s.
-
-
-
From the left pane, click VPN > Autokey IKE:
-
In the VPN Name field, enter a name for the VPN. For example, Harmony SASE.
-
Select Remote Gateway and then select Predefined.
-
Select the AutoKey Advanced Gateway that you created in the previous step.
-
-
From the left pane, click VPN > Advanced:
-
In the Security Level section, select Custom and from the Phase 2 Proposal list, select g5-aes256-sha1-3600s.
-
In the Bind to section, click Tunnel Interface and select the tunnel interface you created in step 3.
-
Select the Proxy-ID Check checkbox.
-
-
From the left pane, click VPN > Autokey IKE, configure Proxy ID with these details:
Field
Enter
Local proxy ID Your local LAN subnet. For example, 192.168.120.0/24. Remote Proxy ID Harmony SASE network subnet. The default is 10.255.0.0./16. Service Any