RE: [fw-wiz] Netscreen compatibility
From: Bruce Platt (Bruce_at_ei3.com)
Date: 08/26/04
- Previous message: Matt Curtin: "Re: [fw-wiz] Off-Topic: Memo of Understanding for Using an Ethical Hacker"
- Maybe in reply to: ROUMEGOUX Pierre: "[fw-wiz] Netscreen compatibility"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: Pierre.ROUMEGOUX@criltechnology.com, firewall-wizards@honor.icsalabs.com Date: Thu, 26 Aug 2004 08:31:33 -0400
>
> I wonder if new Netscreen 5GTE are compatible with old
> Netscreen 10 or 5XP regarding VPN IPSec Tunnel.
Pierre,
To my knowledge there is no Netscreen model 5GTE, but there is a model 5GT.
I have been using these devices for some time now and they interoperate
extremely well both among members of the product family and with other
vendors.
My experience does not allow me to answer your specific question
of whether a 5GT will make a VPN with a Netscreeen 10, but I am certain it
will.
I do know from experience that the 5GT can make VPN with the model 5, the
model 5XP,
and the 200 series models very easily.
>
> Apparently, VPN IPSec Tunnel may be different from one
> construster to another (at last the interpretation of the
> standard IPSec). It seems that Microsoft IPSec client doesn't
> work well with Netscreen IPSec. Your opinion ?
>
Yes, different vendors often use different default Phase 1 and Phase 2
parameters.
What is nice about Netscreen VPN products is that it is very easy for one to
create a
Phase 1 and Phase 2 proposal which will work with almost any other vendor.
I have
created VPNs from Netscreens to Cisco Pix and to Symantec firewalls and
appliances. Other folks have wider positive experience.
Specifically to your question regarding interoperability with Microsoft, I
point you to the following
mailing list archives:
http://www.qorbit.net/nn/index.html
In the last week or so, there has been an extensive thread regarding how to
set up a VPN using the MS native
client to a Netscreen. This thread had some very good instructions in it.
If you are new to Netscreens, you might want to subscribe to the nn mailing
list and also visit the Netscreen Forum at
Good luck and regards,
Bruce
_______________________________________________
firewall-wizards mailing list
firewall-wizards@honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
- Previous message: Matt Curtin: "Re: [fw-wiz] Off-Topic: Memo of Understanding for Using an Ethical Hacker"
- Maybe in reply to: ROUMEGOUX Pierre: "[fw-wiz] Netscreen compatibility"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|