Switching from policy-based to route-based VPN with Juniper SSG5 and Shrew Soft

I used this guide to set up the VPN between my Juniper SSG5 and Shrew Soft client, however, it has a disadvantage; the VPN can only be tunnelled into one zone.  To fix this, you can change the VPN from policy-based to route-based.

  1. Backup your config…
  2. Delete the VPN policies
  3. Create a new zone for your VPN – I called mine “VPN”
  4. Create a new tunnel interface in the new zone, make it unnumbered, and set the interface to whatever interface the incoming VPN will be going through (probably WAN)
  5. Go into VPNs > AutoKey IKE > edit > advanced, and select to bind to your tunnel interface
  6. Network > Routing > Destination, create a new route from the IP pool to the tunnel interface
  7. Create policies allowing communication between your VPN zone and whatever zones it should communicate with
  8. Test! (No changes needed on Shrew Soft)

I did read a forum post about adding multiple policies, but my SSG5 gave errors that the IKE was already part of another policy when I tried to set up the additional policies.  This method seems to work though.

Leave a Reply

Your email address will not be published. Required fields are marked *