Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- HUB SITE:
- set version 22.4R1.10
- set security ike proposal HUB authentication-method pre-shared-keys
- set security ike proposal HUB dh-group group19
- set security ike proposal HUB encryption-algorithm aes-256-gcm
- set security ike proposal HUB lifetime-seconds 28800
- set security ike policy HUB proposals HUB
- set security ike policy HUB pre-shared-key ascii-text "$9$/kHa9uBIRclv8GDuBEyvMaJGUjk"
- set security ike gateway SPOKE1 ike-policy HUB
- set security ike gateway SPOKE1 dynamic hostname SPOKE1
- set security ike gateway SPOKE1 local-identity hostname HUB
- set security ike gateway SPOKE1 external-interface ge-0/0/1
- set security ike gateway SPOKE1 version v2-only
- set security ipsec proposal HUB protocol esp
- set security ipsec proposal HUB encryption-algorithm aes-256-gcm
- set security ipsec proposal HUB lifetime-seconds 3600
- set security ipsec policy HUB perfect-forward-secrecy keys group19
- set security ipsec policy HUB proposals HUB
- set security ipsec vpn SPOKE1 bind-interface st0.1
- set security ipsec vpn SPOKE1 df-bit clear
- set security ipsec vpn SPOKE1 copy-outer-dscp
- set security ipsec vpn SPOKE1 ike gateway SPOKE1
- set security ipsec vpn SPOKE1 ike ipsec-policy HUB
- set security ipsec vpn SPOKE1 traffic-selector ts-1 local-ip 192.168.0.0/24
- set security ipsec vpn SPOKE1 traffic-selector ts-1 remote-ip 192.168.1.0/24
- set security ipsec vpn SPOKE1 establish-tunnels immediately
- set security address-book global address 192.168.0.0/24 192.168.0.0/24
- set security address-book global address 192.168.1.0/24 192.168.1.0/24
- set security policies from-zone DMZ to-zone VPN policy SPOKE-1 match source-address 192.168.0.0/24
- set security policies from-zone DMZ to-zone VPN policy SPOKE-1 match destination-address 192.168.1.0/24
- set security policies from-zone DMZ to-zone VPN policy SPOKE-1 match application any
- set security policies from-zone DMZ to-zone VPN policy SPOKE-1 then permit
- set security policies from-zone DMZ to-zone VPN policy SPOKE-1 then log session-close
- set security policies from-zone VPN to-zone DMZ policy SPOKE-2 match source-address 192.168.1.0/24
- set security policies from-zone VPN to-zone DMZ policy SPOKE-2 match destination-address 192.168.2.0/24
- set security policies from-zone VPN to-zone DMZ policy SPOKE-2 match destination-address 192.168.0.0/24
- set security policies from-zone VPN to-zone DMZ policy SPOKE-2 match application any
- set security policies from-zone VPN to-zone DMZ policy SPOKE-2 then permit
- set security policies from-zone VPN to-zone DMZ policy SPOKE-2 then log session-close
- set security zones security-zone UNTRUST host-inbound-traffic system-services all
- set security zones security-zone UNTRUST host-inbound-traffic protocols all
- set security zones security-zone UNTRUST interfaces ge-0/0/0.0
- set security zones security-zone TRUST host-inbound-traffic system-services all
- set security zones security-zone TRUST host-inbound-traffic protocols all
- set security zones security-zone TRUST interfaces ge-0/0/1.0
- set security zones security-zone VPN host-inbound-traffic system-services all
- set security zones security-zone VPN host-inbound-traffic protocols all
- set security zones security-zone VPN interfaces st0.1
- set security zones security-zone DMZ host-inbound-traffic system-services all
- set security zones security-zone DMZ host-inbound-traffic protocols all
- set security zones security-zone DMZ interfaces ge-0/0/2.0
- set interfaces ge-0/0/0 description UNTRUST
- set interfaces ge-0/0/0 unit 0 family inet address 1.1.0.2/24
- set interfaces ge-0/0/1 description TRUST
- set interfaces ge-0/0/1 unit 0 family inet address 1.1.1.1/24
- set interfaces ge-0/0/2 description DMZ
- set interfaces ge-0/0/2 unit 0 family inet address 192.168.0.1/24
- set interfaces fxp0 unit 0 family inet dhcp
- set interfaces st0 unit 1 family inet
- set routing-options static route 0.0.0.0/0 next-hop 1.1.0.1
- SPOKE-1 CONFIG:
- set system host-name vSRX-Spoke1
- set security ike proposal HUB authentication-method pre-shared-keys
- set security ike proposal HUB dh-group group19
- set security ike proposal HUB encryption-algorithm aes-256-gcm
- set security ike proposal HUB lifetime-seconds 28800
- set security ike policy HUB proposals HUB
- set security ike policy HUB pre-shared-key ascii-text "$9$/kHa9uBIRclv8GDuBEyvMaJGUjk"
- set security ike gateway HUB ike-policy HUB
- set security ike gateway HUB address 1.1.1.1
- set security ike gateway HUB local-identity hostname SPOKE1
- set security ike gateway HUB remote-identity hostname HUB
- set security ike gateway HUB external-interface ge-0/0/0
- set security ike gateway HUB version v2-only
- set security ipsec proposal HUB protocol esp
- set security ipsec proposal HUB encryption-algorithm aes-256-gcm
- set security ipsec proposal HUB lifetime-seconds 3600
- set security ipsec policy HUB perfect-forward-secrecy keys group19
- set security ipsec policy HUB proposals HUB
- set security ipsec vpn HUB bind-interface st0.0
- set security ipsec vpn HUB df-bit clear
- set security ipsec vpn HUB copy-outer-dscp
- set security ipsec vpn HUB ike gateway HUB
- set security ipsec vpn HUB ike ipsec-policy HUB
- set security ipsec vpn HUB traffic-selector ts-1 local-ip 192.168.1.0/24
- set security ipsec vpn HUB traffic-selector ts-1 remote-ip 192.168.0.0/24
- set security ipsec vpn HUB establish-tunnels immediately
- set security address-book global address 192.168.0.0/24 192.168.0.0/24
- set security address-book global address 192.168.1.0/24 192.168.1.0/24
- set security policies from-zone TRUST to-zone VPN policy HUB-1 match source-address 192.168.1.0/24
- set security policies from-zone TRUST to-zone VPN policy HUB-1 match destination-address 192.168.0.0/24
- set security policies from-zone TRUST to-zone VPN policy HUB-1 match application any
- set security policies from-zone TRUST to-zone VPN policy HUB-1 then permit
- set security policies from-zone TRUST to-zone VPN policy HUB-1 then log session-close
- set security policies from-zone VPN to-zone TRUST policy HUB-2 match source-address 192.168.0.0/24
- set security policies from-zone VPN to-zone TRUST policy HUB-2 match destination-address 192.168.1.0/24
- set security policies from-zone VPN to-zone TRUST policy HUB-2 match application any
- set security policies from-zone VPN to-zone TRUST policy HUB-2 then permit
- set security policies from-zone VPN to-zone TRUST policy HUB-2 then log session-close
- set security zones security-zone UNTRUST host-inbound-traffic system-services all
- set security zones security-zone UNTRUST host-inbound-traffic protocols all
- set security zones security-zone UNTRUST interfaces ge-0/0/0.0 host-inbound-traffic system-services all
- set security zones security-zone TRUST host-inbound-traffic system-services all
- set security zones security-zone TRUST host-inbound-traffic protocols all
- set security zones security-zone TRUST interfaces ge-0/0/1.0
- set security zones security-zone VPN host-inbound-traffic system-services all
- set security zones security-zone VPN host-inbound-traffic protocols all
- set security zones security-zone VPN interfaces st0.0 host-inbound-traffic system-services ping
- set interfaces ge-0/0/0 description UNTRUST
- set interfaces ge-0/0/0 unit 0 family inet dhcp
- set interfaces ge-0/0/1 description TRUST
- set interfaces ge-0/0/1 unit 0 family inet address 192.168.1.1/24
- set interfaces st0 unit 0 family net
Advertisement
Add Comment
Please, Sign In to add comment