elbeshti mohamed wrote:dear all
i connect the other company that have cisco asa and give me thair configuration
From Juniper:
VPN Parameters
Peer Device / IOS:
Cisco-ASA
Authentication:
Pre-shared Keys
Will be exchanged through SMS Or Skype
ISAKMP Hashing:
SHA
ISAKMP Encryption:
AES-256, IKEv2
ISAKMP group:
Group2
IPSec Transform-set:
esp-AES-256, esp-SHA-hmac
SA Lifetime:
Isakmp(86400 Secs) Ipsec(3600s)
Peer Addresses:
x.x.x.2
Interesting traffic:
a.a.a.206 (sFTP server) port 22 and 443
a.a.a.201 (Citrix Production) port 443
a.a.a.202 (Citrix Production) port 443
a.a.a.207 (Production Server) Port will be provided by PM team.
a.a.a.210 (Citrix Test) port 443
a.a.a.211 (Citrix Test) port 443
a.a.a.214 (Test Server) port will be provided by PM team.
Traffic selectors cannot be configured with the following features:
- Policy-based VPNs
- IKE version 2
- VPNs configured with proxy identity values used in negotiation
- Remote address value 0.0.0.0/0 (IPv4) or 0::0 (IPv6)
Unless there is some new development, it seems like your setup will not work for multiple reasons. However I will keep track so I can learn when a solution is arrived at.