RE: [fw-wiz] Netscreen compatibility

From: Melson, Paul (PMelson_at_sequoianet.com)
Date: 08/26/04

  • Next message: suren: "[fw-wiz] Instance Messengers and Firewalls"
    To: <Pierre.ROUMEGOUX@criltechnology.com>, <firewall-wizards@honor.icsalabs.com>
    Date: Thu, 26 Aug 2004 09:51:52 -0400
    
    

    Yes, the new versions of ScreenOS are backward compatible to most of the
    older versions as far as site-to-site IPSec VPN tunnels go.

    There are definite client compatibility issues. Newer NetScreen clients
    cannot connect to older NetScreen firewalls and so on. (This has less
    to do with IPSec and more to do with supported client authentication
    mechanisms.)

    Additionally, the NetScreen-10 and NetScreen-5XP are both EOL/EOS
    products. If you've got them running in production environments, you
    should consider replacing them with something newer. (Especially the
    NS-10, which has known security flaws that have gone unfixed since it
    was EOL-ed.)

    PaulM

    > -----Original Message-----
    > I wonder if new Netscreen 5GTE are compatible with old
    > Netscreen 10 or 5XP regarding VPN IPSec Tunnel.
    >
    > Apparently, VPN IPSec Tunnel may be different from one
    > construster to another (at last the interpretation of the
    > standard IPSec). It seems that Microsoft IPSec client doesn't
    > work well with Netscreen IPSec. Your opinion ?
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: suren: "[fw-wiz] Instance Messengers and Firewalls"

    Relevant Pages

    • [fw-wiz] VPN: Citrix IPSEC experiences?
      ... Is anyone using a Citrix IPSEC product with any luck? ... compatibility with other IPSEC clients nor servers. ... We currently use Nortel Contivity Extranet Switches and Cisco's IPSEC IOS ... would be a lot easier--no client setup, no administration, etc. ...
      (Firewall-Wizards)
    • Re: User authentication IPsec
      ... View Output Logs for details ... Ping Diagnosis: ... NAP Client Diagnosis: ... IPsec Service Diagnosis: ...
      (microsoft.public.windows.server.active_directory)
    • RE: Microsoft IPSec via group policy
      ... IPsec could accomplish this. ... Microsoft IPSec via group policy ... Requiring ipsec between a client and a DC via GPO is problematic. ...
      (Security-Basics)
    • re: Microsoft IPSec
      ... My original intention for enabling IPsec was the prevent users from ... Microsoft IPSec via group policy ... Requiring ipsec between a client and a DC via GPO is problematic. ...
      (Security-Basics)
    • RE: Microsoft IPSec via group policy
      ... IPsec could accomplish this. ... Microsoft IPSec via group policy ... Requiring ipsec between a client and a DC via GPO is problematic. ...
      (Security-Basics)