Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- set interfaces st0 unit 0 description RAS
- set interfaces st0 unit 0 family inet
- set security zones security-zone VPN interfaces st0.0
- set system services web-management https pki-local-certificate ACME-RA-CERT
- set security zones security-zone UNTRUST interfaces ge-0/0/0.0 host-inbound-traffic system-services tcp-encap
- set security zones security-zone UNTRUST interfaces ge-0/0/0.0 host-inbound-traffic system-services https
- set security zones security-zone UNTRUST interfaces ge-0/0/0.0 host-inbound-traffic system-services ike
- set security zones security-zone UNTRUST interfaces ge-0/0/0.0 host-inbound-traffic system-services http
- set access address-assignment pool RA-POOL family inet network 172.16.2.0/24
- set access address-assignment pool RA-POOL family inet range USER_POOL_1 low 172.16.2.10
- set access address-assignment pool RA-POOL family inet range USER_POOL_1 high 172.16.2.100
- set access address-assignment pool RA-POOL family inet xauth-attributes primary-dns 9.9.9.9/32
- set access address-assignment pool RA-POOL family inet xauth-attributes secondary-dns 8.8.8.8/32
- set access profile RA-ACCESS authentication-order password
- set access profile RA-ACCESS client user1 firewall-user password "XXXXXXXXXXXXXX"
- set access profile RA-ACCESS client user2 firewall-user password "XXXXXXXXXXXXXx"
- set access profile RA-ACCESS address-assignment pool RA-POOL
- set access firewall-authentication web-authentication default-profile RA-ACCESS
- set security ike proposal REMOTE-ACCESS authentication-method pre-shared-keys
- set security ike proposal REMOTE-ACCESS dh-group group19
- set security ike proposal REMOTE-ACCESS authentication-algorithm sha-256
- set security ike proposal REMOTE-ACCESS encryption-algorithm aes-256-cbc
- set security ike proposal REMOTE-ACCESS lifetime-seconds 28800
- set security ike policy REMOTE-ACCESS mode aggressive
- set security ike policy REMOTE-ACCESS proposals REMOTE-ACCESS
- set security ike policy REMOTE-ACCESS pre-shared-key ascii-text "XXXXXXXXXXXXXXXX"
- set security ike gateway REMOTE-ACCESS ike-policy REMOTE-ACCESS
- set security ike gateway REMOTE-ACCESS dynamic user-at-hostname "[email protected]"
- set security ike gateway REMOTE-ACCESS dynamic ike-user-type shared-ike-id
- set security ike gateway REMOTE-ACCESS nat-keepalive 5
- set security ike gateway REMOTE-ACCESS external-interface ge-0/0/0
- set security ike gateway REMOTE-ACCESS aaa access-profile RA-ACCESS
- set security ike gateway REMOTE-ACCESS version v1-only
- set security ipsec proposal REMOTE-ACCESS protocol esp
- set security ipsec proposal REMOTE-ACCESS encryption-algorithm aes-256-gcm
- set security ipsec proposal REMOTE-ACCESS lifetime-seconds 3600
- set security ipsec policy REMOTE-ACCESS perfect-forward-secrecy keys group19
- set security ipsec policy REMOTE-ACCESS proposals REMOTE-ACCESS
- set security ipsec vpn REMOTE-ACCESS bind-interface st0.0
- set security ipsec vpn REMOTE-ACCESS df-bit clear
- set security ipsec vpn REMOTE-ACCESS copy-outer-dscp
- set security ipsec vpn REMOTE-ACCESS ike gateway REMOTE-ACCESS
- set security ipsec vpn REMOTE-ACCESS ike idle-time 60
- set security ipsec vpn REMOTE-ACCESS ike ipsec-policy REMOTE-ACCESS
- set security ipsec vpn REMOTE-ACCESS ike install-interval 1
- set security ipsec vpn REMOTE-ACCESS traffic-selector 172.16.1.0_24 local-ip 172.16.1.0/24
- set security ipsec vpn REMOTE-ACCESS traffic-selector 172.16.1.0_24 remote-ip 0.0.0.0/0
- set security ipsec vpn REMOTE-ACCESS traffic-selector 10.0.5.0_24 local-ip 10.0.5.0/24
- set security ipsec vpn REMOTE-ACCESS traffic-selector 10.0.5.0_24 remote-ip 0.0.0.0/0
- set security remote-access profile vpn.domain.com ipsec-vpn REMOTE-ACCESS
- set security remote-access profile vpn.domain.com access-profile RA-ACCESS
- set security remote-access profile vpn.domain.com client-config REMOTE-ACCESS
- set security remote-access profile REMOTE-ACCESS ipsec-vpn REMOTE-ACCESS
- set security remote-access profile REMOTE-ACCESS access-profile RA-ACCESS
- set security remote-access profile REMOTE-ACCESS client-config REMOTE-ACCESS
- set security remote-access client-config REMOTE-ACCESS connection-mode manual
- Add Policies from zone VPN to zone TRUST or whatever... Also, I have not enabled TCP-Encap here for ssl fallback.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement