{"id":233,"date":"2017-08-13T16:43:47","date_gmt":"2017-08-13T20:43:47","guid":{"rendered":"http:\/\/puluka.com\/home\/?p=233"},"modified":"2017-08-13T16:43:47","modified_gmt":"2017-08-13T20:43:47","slug":"configuration-of-auto-complete-vpn-with-ospf","status":"publish","type":"post","link":"http:\/\/puluka.com\/home\/networking\/screenos\/configuration-of-auto-complete-vpn-with-ospf\/","title":{"rendered":"Configuration of Auto-Complete VPN with OSPF"},"content":{"rendered":"<p><strong>Product<\/strong>: ScreenOS SSG Series<br \/>\n<strong>Version<\/strong>: 6.2<\/p>\n<h2>Network Topology:<\/h2>\n<p><strong>Network diagram:<\/strong><\/p>\n<p><a href=\"http:\/\/puluka.com\/home\/wp-content\/uploads\/2017\/08\/ScreenOS-OSPF-ACVPN.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-234\" src=\"http:\/\/puluka.com\/home\/wp-content\/uploads\/2017\/08\/ScreenOS-OSPF-ACVPN-300x180.jpg\" alt=\"\" width=\"300\" height=\"180\" srcset=\"http:\/\/puluka.com\/home\/wp-content\/uploads\/2017\/08\/ScreenOS-OSPF-ACVPN-300x180.jpg 300w, http:\/\/puluka.com\/home\/wp-content\/uploads\/2017\/08\/ScreenOS-OSPF-ACVPN-768x460.jpg 768w, http:\/\/puluka.com\/home\/wp-content\/uploads\/2017\/08\/ScreenOS-OSPF-ACVPN-1024x613.jpg 1024w, http:\/\/puluka.com\/home\/wp-content\/uploads\/2017\/08\/ScreenOS-OSPF-ACVPN.jpg 1238w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nHub and spoke VPN with multiple sites using point to multipoint<br \/>\nUsing OSPF for route distribution<br \/>\nUsing Auto-complete VPN for spoke to spoke traffic<\/p>\n<h2>Description:<\/h2>\n<p>The combines two of the convenience vpn features on the ScreenOS platform, dynamic routing protocol vpn and the on demand auto-complete vpn between spokes on a hub and spoke network.\u00a0 This allows a relatively standard spoke configuration process where only a few parameters are changed in the creation of a new spoke.\u00a0 But when the new site is added to the network full routing is established and efficient direct tunnels are created as needed.<\/p>\n<p>The process relies on these basic technologies:<\/p>\n<p>\u2022 IPSEC VPN in route mode<br \/>\n\u2022 Point to multipoint tunnel interface<br \/>\n\u2022 OSPF dynamic protocol configuration to distribute routes<br \/>\n\u2022 AutoComplete-VPN to create the on demand tunnels to avoid looping all traffic through the hub<\/p>\n<p>The configuration requires a base setup on the hub location where primary services are connected.\u00a0 Each spoke then has a configuration set to connect and provide these services to the hub.\u00a0 While the hub adds a section for each new spoke that is created in the system.<\/p>\n<p>1. Configure base services on the hub location.\u00a0 This occurs only once and remains the same no matter how many spokes are added to the system.<br \/>\n2. For each spoke there are two sets of configuration<\/p>\n<blockquote><p>A-Hub configuration for VPN access to the spoke<br \/>\nB-Spoke configuration settting up basic services and the VPN to the hub<\/p><\/blockquote>\n<p><strong>Zone Layout<\/strong><\/p>\n<p>untrust interface is ethernet0\/0<br \/>\ntrust interface is bgroup0<br \/>\ntunnel.1 interface is in trust zone<\/p>\n<p>This zone layout puts all sites and tunnels into the same security zone.\u00a0 No policies need to be created on any device for full communications across the entire hub and spoke network.\u00a0 This is assuming that intra zone blocking is NOT enabled on any of the firewalls for the trust zone.\u00a0 This is the default behavior for the trust zone.<\/p>\n<p>1. Hub location base configuration:<\/p>\n<blockquote><p>This sets up and configures all needed services on the hub shared by all tunnels<br \/>\n<strong>Create VPN tunnel interface<\/strong><br \/>\nset interface tunnel.1 zone Trust<br \/>\nset interface tunnel.1 ip 10.0.0.1\/24<br \/>\n<strong>Create AC-VPN gateway profile<\/strong><br \/>\nset ike gateway ac-spoke-gw acvpn-profile sec-level standard<br \/>\n<strong>Create AC-VPN profile<\/strong><br \/>\nset vpn ac-vpn acvpn-profile ac-spoke-gw no-replay tunnel idletime 0 sec-level standard<br \/>\n<strong>Enable &amp; Configure NHRP for VPN usage<\/strong><br \/>\nset vrouter trust-vr<br \/>\nset protocol nhrp<br \/>\nset protocol nhrp acvpn-profile ac-vpn<br \/>\nexit<br \/>\nset interface tunnel.1 protocol nhrp enable<br \/>\n<strong>Enable &amp; Configure OSPF<\/strong><br \/>\nset vr trust protocol ospf<br \/>\nset vr trust protocol ospf enable<br \/>\nset vr trust protocol ospf area 1<br \/>\nset interface bgroup0 protocol ospf area 1<br \/>\nset interface bgroup0 protocol ospf enable<br \/>\nset interface tunnel.1 protocol ospf area 0<br \/>\nset interface tunnel.1 protocol ospf link-type p2mp<br \/>\nset interface tunnel.1 protocol ospf enable<\/p><\/blockquote>\n<p>2. A. Hub location per spoke configuration:<\/p>\n<blockquote><p>Repeat only these commands for additional spoke sites<br \/>\nCreate VPN Gateway to spoke<br \/>\nset ike gateway SpokeA-GW address 2.2.2.2 Main outgoing-interface &#8220;ethernet0\/0&#8221; preshare Juniper== sec-level standard<br \/>\nset ike gateway SpokeB-GW address 3.3.3.3 Main outgoing-interface &#8220;ethernet0\/0&#8221; preshare Juniper== sec-level standard<br \/>\nset ike gateway SpokeC-GW address 4.4.4.4 Main outgoing-interface &#8220;ethernet0\/0&#8221; preshare Juniper== sec-level standard<br \/>\nset ike gateway SpokeD-GW address 5.5.5.5 Main outgoing-interface &#8220;ethernet0\/0&#8221; preshare Juniper== sec-level standard<br \/>\nCreate VPN tunnel bound to tunnel interface<br \/>\nset vpn SpokeA gateway SpokeA-GW no-replay tunnel idletime 0 sec-level standard<br \/>\nset vpn SpokeA bind interface tunnel.1<br \/>\nset vpn SpokeB gateway SpokeB-GW no-replay tunnel idletime 0 sec-level standard<br \/>\nset vpn SpokeB bind interface tunnel.1<br \/>\nset vpn SpokeC gateway SpokeC-GW no-replay tunnel idletime 0 sec-level standard<br \/>\nset vpn SpokeC bind interface tunnel.1<br \/>\nset vpn SpokeD gateway SpokeD-GW no-replay tunnel idletime 0 sec-level standard<br \/>\nset vpn SpokeD bind interface tunnel.1<\/p><\/blockquote>\n<p>2. B. Spoke location:<\/p>\n<blockquote><p>All steps on spokes are identical with exceptions noted below.\u00a0 Change the indicated parameters to match the spoke location on the network as each new spoke is added.<br \/>\nCreate VPN tunnel interface<br \/>\nset interface tunnel.1 zone Trust<br \/>\nset interface tunnel.1 ip 10.0.0.2\/24<br \/>\n**Change the ip address to match the spoke location<br \/>\nCreate VPN Gateway to hub<br \/>\nset ike gateway Hub-gw address 1.1.1.1 Main outgoing-interface ethernet0\/0 preshare juniper== sec-level standard<br \/>\nCreate VPN tunnel bound to tunnel interface<br \/>\nset vpn Hub gateway Hub-GW no-replay tunnel idletime 0 sec-level standard<br \/>\nset vpn Hub bind interface tunnel.1<br \/>\nCreate AC-VPN Dynamic gateway<br \/>\nset ike gateway ac-hub-gw acvpn-dynamic<\/p>\n<p>Create ACVPN Dynamic VPN<br \/>\nset vpn ac-hub-vpn acvpn-dynamic ac-hub-gw hub<br \/>\nEnable &amp; Configure NHRP on router<br \/>\nset vrouter trust-vr<br \/>\nset protocol nhrp<br \/>\nset protocol nhrp nhs 10.0.0.1<br \/>\nset protocol nhrp cache 10.0.2.0\/24<br \/>\n**Change the ip address to match the bgroup0 LAN on spoke<br \/>\nexit<br \/>\nset interface tunnel.1 protocol nhrp enable<br \/>\nEnable &amp; Configure OSPF<br \/>\nset vr trust protocol ospf<br \/>\nset vr trust protocol ospf enable<br \/>\nset vr trust protocol ospf area 2<br \/>\n**Change area to match Spoke LAN assignment<br \/>\nset interface bgroup0 protocol ospf area 2<br \/>\n**Change area to match Spoke LAN assignment<br \/>\nset interface bgroup0 protocol ospf enable<br \/>\nset interface tunnel.1 protocol ospf area 0<br \/>\nset interface tunnel.1 protocol ospf enable<\/p><\/blockquote>\n<h2>Verification:<\/h2>\n<p><strong>routing table checks<\/strong><\/p>\n<p>Running &#8220;get route protocol ospf&#8221; on a spoke should show the routes to all other spokes and the hub as learned from OSPF the capital &#8220;O&#8221; label below.\u00a0\u00a0 This should contain all the connected spokes and the hub if routes are fully distributed properly.<br \/>\nThis output is from spoke C<br \/>\nget route protocol ospf<br \/>\nIPv4 Dest-Routes for &lt;untrust-vr&gt; (0 entries)<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\nH: Host C: Connected S: Static A: Auto-Exported<br \/>\nI: Imported R: RIP P: Permanent D: Auto-Discovered<br \/>\nN: NHRP<br \/>\niB: IBGP eB: EBGP O: OSPF E1: OSPF external type 1<br \/>\nE2: OSPF external type 2 trailing B: backup routeIPv4 Dest-Routes for &lt;trust-vr&gt; (14 entries)<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\nID\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 IP-Prefix\u00a0\u00a0\u00a0\u00a0\u00a0 Interface\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Gateway\u00a0\u00a0 P Pref\u00a0\u00a0\u00a0 Mtr\u00a0\u00a0\u00a0\u00a0 Vsys<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.1\/32\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tun.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.1\u00a0\u00a0 O\u00a0\u00a0 60\u00a0\u00a0\u00a0\u00a0 10\u00a0\u00a0\u00a0\u00a0 Root<br \/>\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 13\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.1.0\/24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tun.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.1\u00a0\u00a0 O\u00a0\u00a0 60\u00a0\u00a0\u00a0\u00a0 21\u00a0\u00a0\u00a0\u00a0 Root<br \/>\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 12\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.2.0\/24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tun.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.1\u00a0\u00a0 O\u00a0\u00a0 60\u00a0\u00a0\u00a0\u00a0 11\u00a0\u00a0\u00a0\u00a0 Root<br \/>\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 11\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.3.0\/24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tun.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.1\u00a0\u00a0 O\u00a0\u00a0 60\u00a0\u00a0\u00a0\u00a0 21\u00a0\u00a0\u00a0\u00a0 Root<br \/>\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 14\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.5.0\/24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tun.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.1\u00a0\u00a0 O\u00a0\u00a0 60\u00a0\u00a0\u00a0\u00a0 21\u00a0\u00a0\u00a0\u00a0 Root<br \/>\nTotal number of ospf routes: 5<br \/>\nOn the hub verify NHRP full connectivity<br \/>\nget route protocol nhrpIPv4 Dest-Routes for &lt;untrust-vr&gt; (0 entries)<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\nH: Host C: Connected S: Static A: Auto-Exported<br \/>\nI: Imported R: RIP P: Permanent D: Auto-Discovered<br \/>\nN: NHRP<br \/>\niB: IBGP eB: EBGP O: OSPF E1: OSPF external type 1<br \/>\nE2: OSPF external type 2 trailing B: backup routeIPv4 Dest-Routes for &lt;trust-vr&gt; (19 entries)<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\nID\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 IP-Prefix\u00a0\u00a0\u00a0\u00a0\u00a0 Interface\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Gateway\u00a0\u00a0 P Pref\u00a0\u00a0\u00a0 Mtr\u00a0\u00a0\u00a0\u00a0 Vsys<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 19\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.2\/32\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tun.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.2\u00a0\u00a0 N\u00a0\u00a0 35\u00a0\u00a0\u00a0\u00a0\u00a0 0\u00a0\u00a0\u00a0\u00a0 Root<br \/>\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 16\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.3\/32\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tun.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.3\u00a0\u00a0 N\u00a0\u00a0 35\u00a0\u00a0\u00a0\u00a0\u00a0 0\u00a0\u00a0\u00a0\u00a0 Root<br \/>\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 17\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.4\/32\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tun.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.3\u00a0\u00a0 N\u00a0\u00a0 35\u00a0\u00a0\u00a0\u00a0\u00a0 0\u00a0\u00a0\u00a0\u00a0 Root<br \/>\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 17\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.5\/32\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tun.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.3\u00a0\u00a0 N\u00a0\u00a0 35\u00a0\u00a0\u00a0\u00a0\u00a0 0\u00a0\u00a0\u00a0\u00a0 Root<br \/>\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 19\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.2.0\/24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tun.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.3\u00a0\u00a0 N\u00a0\u00a0 35\u00a0\u00a0\u00a0\u00a0\u00a0 0\u00a0\u00a0\u00a0\u00a0 Root<br \/>\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 21\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.3.0\/24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tun.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.4\u00a0\u00a0 N\u00a0\u00a0 35\u00a0\u00a0\u00a0\u00a0\u00a0 0\u00a0\u00a0\u00a0\u00a0 Root<br \/>\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 20\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.4.0\/24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tun.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.2\u00a0\u00a0 N\u00a0\u00a0 35\u00a0\u00a0\u00a0\u00a0\u00a0 0\u00a0\u00a0\u00a0\u00a0 Root<br \/>\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 23\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.5.0\/24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 tun.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.5\u00a0\u00a0 N\u00a0\u00a0 35\u00a0\u00a0\u00a0\u00a0\u00a0 0\u00a0\u00a0\u00a0\u00a0 Root<br \/>\nTotal number of nhrp routes: 8<br \/>\nget vrouter trust protocol nhrp cache<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\nflags: R-registered, C-cached, L-replied, P-pushed, S-static, I-imported,<br \/>\nF-in FIB, D-being deleted.<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\nPrefix\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 nhop-public-IP nhop-private-IP Pref\u00a0\u00a0\u00a0 Flags Expire(in sec)<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\n10.0.0.4\/32\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 4.4.4.4\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.4\u00a0 128\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 C 257<br \/>\n10.0.3.0\/24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 3.3.3.3\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.3\u00a0 128\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RF 283<br \/>\n10.0.0.2\/32\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 2.2.2.2\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.2\u00a0 128\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 CF 283<br \/>\n10.0.0.2\/32\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 5.5.5.5\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.5\u00a0 128\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 CF 283<br \/>\n10.0.0.3\/32\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 3.3.3.3\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.3\u00a0 128\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 CF 283<br \/>\n10.0.2.0\/24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 2.2.2.2\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.2\u00a0 128\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RF 283<br \/>\n10.0.5.0\/24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 5.5.5.5\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.2\u00a0 128\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RF 283<br \/>\n10.0.4.0\/24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 4.4.4.4\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.0.0.4\u00a0 128\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RF 257<\/p>\n<p>Confirm setup of ac-vpn<\/p>\n<p>On spoke look for the sa configuration for the AC-VPN<br \/>\nget sa<br \/>\nsa: 2<br \/>\nHEX ID\u00a0\u00a0\u00a0 Gateway\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Port Algorithm\u00a0\u00a0\u00a0\u00a0 SPI\u00a0\u00a0\u00a0\u00a0\u00a0 Life:sec kb Sta\u00a0\u00a0 PID vsys<br \/>\n00000006&lt;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 1.1.1.1\u00a0 500 esp:3des\/sha1 677cddab\u00a0 1987 unlim A\/-\u00a0\u00a0\u00a0 -1 0<br \/>\n00000006&gt;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 1.1.1.1\u00a0 500 esp:3des\/sha1 8e6fb985\u00a0 1987 unlim A\/-\u00a0\u00a0\u00a0 -1 0<br \/>\n00000007&lt;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 0.0.0.0\u00a0 500 esp:3des\/sha1 00000000 expir unlim I\/I\u00a0\u00a0\u00a0 -1 0<br \/>\n00000007&gt;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 0.0.0.0\u00a0 500 esp:3des\/sha1 00000000 expir unlim I\/I\u00a0\u00a0\u00a0 -1 0<\/p>\n<h2>References:<\/h2>\n<p><strong>ScreenOS Concepts &amp; Examples Guides<\/strong><br \/>\n<a href=\"http:\/\/www.juniper.net\/techpubs\/software\/screenos\/screenos6.2.0\/index.html\">http:\/\/www.juniper.net\/techpubs\/software\/screenos\/screenos6.2.0\/index.html<\/a><\/p>\n<p><em><strong>Route based VPN tunnels<\/strong><\/em><br \/>\nConcepts &amp; Examples Guide<br \/>\nVolume 5 Virtual Private Networks<br \/>\nChapter 3 VPN Guidelines<br \/>\nChapter 4 VPN: Sit-to-site VPN Configurations<br \/>\n<em><strong>Point to multi-point tunnels to share tunnel interfaces<\/strong><\/em><br \/>\nConcepts &amp; Examples Guide<br \/>\nVolume 5 Virtual Private Networks<br \/>\nChapter 7 Advanced VPN Features: Multple Tunnels per Tunnel Interface<br \/>\nOSPF<br \/>\nConcepts &amp; Examples Guide<br \/>\nVolume 7 Routing<br \/>\nChapter 3<br \/>\n<em><strong>AutoConnect-VPN<\/strong><\/em><br \/>\nConcepts &amp; Examples Guide<br \/>\nVolume 5 Virtual Private Networks<br \/>\nChapter 8<\/p>\n<p>Originally Posted October 16, 2010<br \/>\nLast Revised on May 22, 2011<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Product: ScreenOS SSG Series Version: 6.2 Network Topology: Network diagram: Hub and spoke VPN with multiple sites using point to multipoint Using OSPF for route distribution Using Auto-complete VPN for spoke to spoke traffic Description: [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-233","post","type-post","status-publish","format-standard","hentry","category-screenos"],"_links":{"self":[{"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/posts\/233","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/comments?post=233"}],"version-history":[{"count":1,"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/posts\/233\/revisions"}],"predecessor-version":[{"id":235,"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/posts\/233\/revisions\/235"}],"wp:attachment":[{"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/media?parent=233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/categories?post=233"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/tags?post=233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}