I will show you howto do a ike group-based vpn . It's similar to standard dynamic-group-vpn, but the ike user type is set to shared
e.g
set security ike gateway myvpngw dynamic ike-user-type shared-ike-id <-------
I will explain the difference on shared-ike-id vr user+group later.
Here's a few details of the platforms involved from the VPNserver and RADIUS-aaS
JUNOS 15.1X49-D110.4
NCP Macosx verson3 rev35061
AUTH XAUTH
RADIUS_REMOTE ( JUMPCLOUD )
For this vpn settings, I decided to use defined proposal of AES256 with auth md5/sha1/sha256 types which we will use in the NCP client settings
ike
set security ike proposal AES256SHA1 authentication-method pre-shared-keys
set security ike proposal AES256SHA1 dh-group group5
set security ike proposal AES256SHA1 authentication-algorithm sha1
set security ike proposal AES256SHA1 encryption-algorithm aes-256-cbc
set security ike proposal AES256MD5 authentication-method pre-shared-keys
set security ike proposal AES256MD5 dh-group group5
set security ike proposal AES256MD5 authentication-algorithm md5
set security ike proposal AES256MD5 encryption-algorithm aes-256-cbc
set security ike proposal AES256SHA256 authentication-method pre-shared-keys
set security ike proposal AES256SHA256 dh-group group5
set security ike proposal AES256SHA256 authentication-algorithm sha-256
set security ike proposal AES256SHA256 encryption-algorithm aes-256-cbc
NOTE BCPs suggest using dhgrp 14 or stronger, but to support clients who might have a older vpn-client software I'm using PFS+group5
IPSEC
set security ipsec proposal AES256SHA256 protocol esp
set security ipsec proposal AES256SHA256 authentication-algorithm hmac-sha-256-128
set security ipsec proposal AES256SHA256 encryption-algorithm aes-256-cbc
set security ipsec proposal AES256SHA256 lifetime-seconds 3600
set security ipsec proposal AES256SHA1 protocol esp
set security ipsec proposal AES256SHA1 authentication-algorithm hmac-sha1-96
set security ipsec proposal AES256SHA1 encryption-algorithm aes-256-cbc
set security ipsec proposal AES256SHA1 lifetime-seconds 3600
set security ipsec proposal AES256MD5 protocol esp
set security ipsec proposal AES256MD5 authentication-algorithm hmac-md5-96
set security ipsec proposal AES256MD5 encryption-algorithm aes-256-cbc
set security ipsec proposal AES256MD5 lifetime-seconds 3600
=======================================================
Now to wrap this up you need to set the ike and ipsec policies for the gateway
set security ike policy ike_pol_wizard_dyn_vpn mode aggressive
set security ike policy ike_pol_wizard_dyn_vpn proposals AES256MD5
set security ike policy ike_pol_wizard_dyn_vpn proposals AES256SHA1
set security ike policy ike_pol_wizard_dyn_vpn proposals AES256SHA256
set security ike policy ike_pol_wizard_dyn_vpn pre-shared-key ascii-text "mystrongpsk"
set security ipsec policy ipsec_pol_wizard_dyn_vpn perfect-forward-secrecy keys group5
set security ipsec policy ipsec_pol_wizard_dyn_vpn proposals AES256SHA256
set security ipsec policy ipsec_pol_wizard_dyn_vpn proposals AES256SHA1
set security ipsec policy ipsec_pol_wizard_dyn_vpn proposals AES256MD5
set security ipsec vpn wizard_dyn_vpn ike gateway gw_wizard_dyn_vpn
Now the fun starts, you will need to set the remote-access-profile to use your jumpcloud radius servers and set the src_ipv4 address for the radius-client
set access profile remote_access_profile authentication-order radius
set access profile remote_access_profile client socpuppets firewall-user password "$9$r47KLxVwY2oJYgJDiH5TRhSyvWLxN"
set access profile remote_access_profile address-assignment pool dyn-vpn-address-pool
set access profile remote_access_profile radius-server 104.154.91.253 port 1812
set access profile remote_access_profile radius-server 104.154.91.253 secret "$9$RFcSKML7-dwY5QESyeLXUjHq.53nCtu129K8Xx-d"
set access profile remote_access_profile radius-server 104.154.91.253 source-address 10.10.10.98
set access profile remote_access_profile radius-server 104.196.54.120 port 1812
set access profile remote_access_profile radius-server 104.196.54.120 secret "$9$esuW7-wYg4JG/CKW8xbwmfTzF/pu1RKr0B7Vwsg4"
set access profile remote_access_profile radius-server 104.196.54.120 source-address 10.10.10.98
set access firewall-authentication pass-through default-profile remote_access_profile
In the jumpcloud portal, you have to define the radius-client and set the shared secret and have remote-users defined
data:image/s3,"s3://crabby-images/a9594/a959491e9fe6fecc4e0fd005a4f82da02f348766" alt=""
data:image/s3,"s3://crabby-images/83609/83609828ff3d6a62f969d5d60d78cacf5c5572aa" alt=""
( a no-success login )
( a success login )
The NCP-vpn-client-side is configured very easily, by setting both a IKE and IPSEC proposals and defined these in your NCP profiles.
e.g defined IPSEC transform and IKEproposals
data:image/s3,"s3://crabby-images/fd56a/fd56a6feee8f2c459018f2e1d37f5aab68e8d9bf" alt=""
data:image/s3,"s3://crabby-images/bba16/bba16914b3423926b34322540bbd91274ba29d2f" alt=""
data:image/s3,"s3://crabby-images/9df01/9df018ee07413320564de7824235daee66dfa8c1" alt=""
user details;
data:image/s3,"s3://crabby-images/3f6c0/3f6c060824048729def5120593237e4cb2f79363" alt=""
You remember the shared-ike-id thing, that I mention earlier ?
When you connect into the SRX, the NCPvpnclient identity would be just the client-ipv4-addr and the groupname.
e.g IKE SA details ( shared-ike-id)
data:image/s3,"s3://crabby-images/e99ab/e99abf0ebe5e659cefe70d54b23e348a8e62fce4" alt=""
vrs the typical user+group-ike-id combination
data:image/s3,"s3://crabby-images/23e3f/23e3f09110f89ac61d6c0ba7222672c34c18afea" alt=""
The one cool item about the NCP client, it can display almost too much details for logging and diagnostics purposes.
data:image/s3,"s3://crabby-images/65823/65823d95f8584bfe98939b51dd9d4035c9d5135e" alt=""
Here's the final vpn configuration for dynamic-vpn
data:image/s3,"s3://crabby-images/55575/555754f23cd3d692c10c86948f6597ec6a8e1c2d" alt=""
NSE ( network security expert) and Route/Switching Engineer
kfelix -----a----t---- socpuppets ---dot---com
^ ^
=( @ @ )=
o
/ \
No comments:
Post a Comment