aricade

vpn_gre_tunnel_srx-to-asa V3

Feb 4th, 2016
58
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.84 KB | None | 0 0
  1. interfaces {
  2. /* GRE Tunnel was not working . Why because I didn't put it in any zone! DOH! */
  3. gr-0/0/0 {
  4. unit 0 {
  5. tunnel {
  6. source 10.127.0.6;
  7. destination 192.168.244.1;
  8. }
  9. family inet;
  10. }
  11. }
  12. fe-0/0/1 {
  13. unit 0 {
  14. family inet {
  15. address 10.10.20.1/24;
  16. }
  17. }
  18. }
  19. fe-0/0/2 {
  20. unit 0 {
  21. family inet {
  22. address 1.1.1.1/27;
  23. }
  24. }
  25. }
  26.  
  27.  
  28. lo0 {
  29. unit 0 {
  30. family inet {
  31. address 10.127.0.6/32;
  32. }
  33. }
  34. }
  35. st0 {
  36.  
  37. unit 1 {
  38. family inet {
  39. mtu 1500;
  40. /* ephemeral interface */
  41. next-hop-tunnel 10.128.1.2 ipsec-vpn ASA_vpn;
  42. address 10.128.1.1/27
  43. }
  44. }
  45. }
  46. }
  47.  
  48. routing-options {
  49. static {
  50. route 0.0.0.0/0 next-hop 1.1.1.7;
  51. route 192.168.244.1/32 next-hop 10.128.1.2;
  52. route 10.10.10.0/24 next-hop gr-0/0/0.0;
  53. }
  54. router-id 10.127.0.6;
  55. }
  56.  
  57. security {
  58.  
  59. ike {
  60. traceoptions {
  61. file iketrace size 1m;
  62. flag ike;
  63. flag policy-manager;
  64. }
  65. /* Changed to 3des and md5 on request of other side */
  66. proposal my_p1 {
  67. authentication-method pre-shared-keys;
  68. dh-group group2;
  69. authentication-algorithm md5;
  70. encryption-algorithm 3des-cbc;
  71. lifetime-seconds 28800;
  72. }
  73.  
  74. policy ASA_gw {
  75. mode main;
  76. proposals my_p1;
  77. pre-shared-key ascii-text "xxxxxxxxxxx"; ## SECRET-DATA
  78. }
  79.  
  80. gateway orbcomm_gw {
  81. ike-policy ASA_gw;
  82. address 2.2.2.2;
  83. external-interface fe-0/0/2;
  84. }
  85. }
  86. ipsec {
  87. /* Changed to 3des and MD5 at request of Otherside */
  88. proposal my_p2 {
  89. protocol esp;
  90. authentication-algorithm hmac-md5-96;
  91. encryption-algorithm 3des-cbc;
  92. lifetime-seconds 3600;
  93. }
  94. policy my_pol {
  95. perfect-forward-secrecy {
  96. keys group2;
  97. }
  98. proposals my_p2;
  99. }
  100.  
  101. vpn ASA_vpn {
  102. bind-interface st0.1;
  103. ike {
  104. gateway ASA_gw;
  105. no-anti-replay;
  106. proxy-identity {
  107. local 10.127.0.6/32;
  108. remote 192.168.244.1/32;
  109. }
  110. ipsec-policy my_pol;
  111. }
  112. establish-tunnels immediately;
  113. }
  114. }
  115. flow {
  116. tcp-mss {
  117. ipsec-vpn {
  118. mss 1350;
  119. }
  120. }
  121. }
  122. }
Add Comment
Please, Sign In to add comment