<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:www.nabble.com,2006:forum-20745</id>
	<title>Nabble - Netscreen at Compsoc.com</title>
	<updated>2008-12-11T00:31:28Z</updated>
	<link rel="self" type="application/atom+xml" href="http://www.nabble.com/Netscreen-at-Compsoc.com-f20745.xml" />
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Netscreen-at-Compsoc.com-f20745.html" />
	<subtitle type="html">&lt;a href=&quot;http://www.qorbit.net/nn/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Netscreen&lt;/a&gt;&amp;nbsp;mailing list at compsoc.com.
&lt;br&gt;Discussion dedicated to the sharing of knowledge regarding Netscreen products. 
&lt;br&gt;We hope you find it helpful and use it to share your expertise as well as benefit from the experience of others as it pertains to Netscreen gear.</subtitle>
	
<entry>
	<id>tag:www.nabble.com,2006:post-20951686</id>
	<title>understanding traffic shaping</title>
	<published>2008-12-11T00:31:28Z</published>
	<updated>2008-12-11T00:31:28Z</updated>
	<author>
		<name>Kai Krebber</name>
	</author>
	<content type="html">Hi!
&lt;br&gt;&lt;br&gt;I'm currently trying to understand traffic shaping on the SSGs and have
&lt;br&gt;a hard time.
&lt;br&gt;&lt;br&gt;Prep for JNCIS FWV has the following question:
&lt;br&gt;&lt;br&gt;You have 4 policies configured for the egress interface with 10Mbps
&lt;br&gt;physical bandwith:
&lt;br&gt;Policy1: Prio0, 1Mbps GBW, 3Mbps MBW
&lt;br&gt;Policy2: Prio1, 1Mbps GBW, 4Mbps MBW
&lt;br&gt;Policy3: Prio1, 2Mbps GBW, 2Mbps MBW
&lt;br&gt;Policy4: Prio0, 2Mbps GBW, 4Mbps MBW
&lt;br&gt;&lt;br&gt;The book states that under full load policy 4 would drop packets first.
&lt;br&gt;&lt;br&gt;I tried to simulate this and got a different result. I assume, my
&lt;br&gt;assumptions are wrong, but I would need help to spot the error:
&lt;br&gt;&lt;br&gt;Let's say a constant stream of 1 Mbit-packets - one fitting each policy
&lt;br&gt;- hits the device with 40Mbps.
&lt;br&gt;I'll name the packtes after the policy-id, they will fit:
&lt;br&gt;1,2,3,4,1,2,3,4,1,2,3,4, and so on.
&lt;br&gt;Since the egress speed is only 10Mbps, the SSG can only send out one
&lt;br&gt;packet for every four packets, it receives.
&lt;br&gt;&lt;br&gt;Lets go:
&lt;br&gt;&lt;br&gt;First packet hit's the device. It's policy 1. Since Policy 1 has 1Mbps
&lt;br&gt;GBW, the packet goes straight out to the egress interface.
&lt;br&gt;Second packet - this time for policy 2. Again 1 Mbps GBW, so the packet
&lt;br&gt;get's straight queued on the interface, since the first packet is still
&lt;br&gt;being put on the wire.
&lt;br&gt;Same with packet 3 and 4.
&lt;br&gt;Now packet 5 arrives- again for policy 1. GBW is exhausted, but MBW is
&lt;br&gt;not even reached, so this packet is been pushed to Queue 0
&lt;br&gt;Meanwhile packet 1 has left the building and packet 2 is been processed
&lt;br&gt;to be put on the wire.
&lt;br&gt;&lt;br&gt;Next packet 6 arrives (policy 2) - again that GBW is exhausted, but not
&lt;br&gt;the MBW, so this packet is placed in Queue 1.
&lt;br&gt;Next packet 7 (policy 3) comes along - here we're even still in the GWB,
&lt;br&gt;so this packet goes straight to the out-queue for the egress interface.
&lt;br&gt;The last bits of packet 2 have just hit the wire.
&lt;br&gt;&lt;br&gt;Packet 8 arrives (policy 4). Again a GBW-Packet, so it joins Pakets 4
&lt;br&gt;and 7 (3 has just started to be put on the wire).
&lt;br&gt;Packet 9 comes in - Policy1 - This packet is just inside the MBW-limit.
&lt;br&gt;It's the third 1Mb-Paket for policy 1 within this second and we got
&lt;br&gt;3Mbps MBW, so that packet joins packet 5 in Queue 0.
&lt;br&gt;&lt;br&gt;Packet 10 comes in - policy 2. Here we've used up 3 of the 4 Mbps MBW,
&lt;br&gt;so that packet goes into Queue 1.
&lt;br&gt;&lt;br&gt;And according to my understanding, packet 11 finally gets dropped, since
&lt;br&gt;this would be 3Mbps for a 2 Mbps - MBW in policy 3.
&lt;br&gt;&lt;br&gt;Where's my mistake?
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;Kai
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=20951686&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/understanding-traffic-shaping-tp20951686p20951686.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19552543</id>
	<title>IGMP snooping with NetScreen firewall?</title>
	<published>2008-09-18T06:10:10Z</published>
	<updated>2008-09-18T06:10:10Z</updated>
	<author>
		<name>F J-2</name>
	</author>
	<content type="html">&lt;html&gt;
&lt;head&gt;

&lt;/head&gt;
&lt;body class='hmmessage'&gt;
Hi,&lt;BR&gt;Does the small NS5-GT support IGMP-snooping?&lt;BR&gt;&amp;nbsp;&lt;BR&gt;If not, is there another Netscreen model that support IGMP-snooping?&lt;BR&gt;&amp;nbsp;&lt;BR&gt;If not, does anyone have experience using a small switch that support IGMP-snooping. &lt;BR&gt;I knew the 'small' Extreme Summit200 works fine but I would like to replace that switch &lt;BR&gt;with a smaller one...&lt;BR&gt;&amp;nbsp;&lt;BR&gt;Best Regards&lt;BR&gt;Fredrik&lt;BR&gt;&lt;br /&gt;&lt;hr /&gt;Get news, entertainment and everything you care about at Live.com. &lt;a href='http://www.live.com/getstarted.aspx ' target='_new' rel=&quot;nofollow&quot;&gt;Check it out!&lt;/a&gt;&lt;/body&gt;
&lt;/html&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19552543&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/IGMP-snooping-with-NetScreen-firewall--tp19552543p19552543.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19445961</id>
	<title>OpenSSH-5.1p1 issue with ScreenOS</title>
	<published>2008-09-11T15:21:11Z</published>
	<updated>2008-09-11T15:21:11Z</updated>
	<author>
		<name>John Parker-2</name>
	</author>
	<content type="html">Just FYI in case others haven't run into this yet: after upgrading my
&lt;br&gt;OpenSSH client to the latest 5.1-portable, I found to my horror that
&lt;br&gt;ssh sessions to NetScreens (ScreenOS 5.4r10, 6.1.0r3) were immediately
&lt;br&gt;disconnecting. &amp;nbsp;Looking at the event log through webui showed
&lt;br&gt;successful-auth, but no real error messages. &amp;nbsp;Same basic symptoms for
&lt;br&gt;both password and pubkey-auth. &amp;nbsp;Running ssh in verbose mode gave a few
&lt;br&gt;hints, it looks like a new 5.1 security feature isn't being handled
&lt;br&gt;correctly by the NetScreen sshd:
&lt;br&gt;&lt;br&gt;--------------
&lt;br&gt;&lt;a href=&quot;http://openssh.com/txt/release-5.1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openssh.com/txt/release-5.1&lt;/a&gt;&lt;br&gt;&amp;lt;snip&amp;gt;
&lt;br&gt;New features:
&lt;br&gt;&amp;nbsp;* Added a &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19445961&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;no-more-sessions@...&lt;/a&gt; global request extension that is
&lt;br&gt;&amp;nbsp; &amp;nbsp;sent from ssh(1) to sshd(8) when the client knows that it will never
&lt;br&gt;&amp;nbsp; &amp;nbsp;request another session (i.e. when session multiplexing is disabled).
&lt;br&gt;&amp;nbsp; &amp;nbsp;This allows a server to disallow further session requests and
&lt;br&gt;&amp;nbsp; &amp;nbsp;terminate the session in cases where the client has been hijacked.
&lt;br&gt;--------------
&lt;br&gt;&lt;br&gt;I can only venture to guess that, when ScreenOS receives the client
&lt;br&gt;message &amp;quot;no more sessions after this one&amp;quot;, it's interpreting as
&lt;br&gt;&amp;quot;...including this one&amp;quot;? &amp;nbsp;Anyway, by the Edisonian approach &amp;nbsp;:) &amp;nbsp; I
&lt;br&gt;discovered that the following option will get you back in:
&lt;br&gt;&lt;br&gt;ControlMaster=ask (or &amp;quot;yes&amp;quot;, or &amp;quot;auto&amp;quot; -- anything but the default &amp;quot;no&amp;quot;)
&lt;br&gt;&lt;br&gt;As in, &amp;quot;ssh -o ControlMaster=ask &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19445961&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;me@...&lt;/a&gt;&amp;quot;
&lt;br&gt;&lt;br&gt;I wouldn't recommend adding this to your ssh_config, unless you can do
&lt;br&gt;it per-host. &amp;nbsp;It's a good idea to disable where not needed.
&lt;br&gt;&lt;br&gt;FWIW,
&lt;br&gt;&lt;br&gt;John
&lt;br&gt;&lt;br&gt;PS -- If anyone has a less-kludgy workaround, I'd love to hear it.
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19445961&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/OpenSSH-5.1p1-issue-with-ScreenOS-tp19445961p19445961.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19266386</id>
	<title>Re: Policy traffic shaping netscreen</title>
	<published>2008-09-02T01:48:40Z</published>
	<updated>2008-09-02T01:48:40Z</updated>
	<author>
		<name>Kai Krebber</name>
	</author>
	<content type="html">&lt;html xmlns:v=&quot;urn:schemas-microsoft-com:vml&quot; xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns:x=&quot;urn:schemas-microsoft-com:office:excel&quot; xmlns:p=&quot;urn:schemas-microsoft-com:office:powerpoint&quot; xmlns:a=&quot;urn:schemas-microsoft-com:office:access&quot; xmlns:dt=&quot;uuid:C2F41010-65B3-11d1-A29F-00AA00C14882&quot; xmlns:s=&quot;uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882&quot; xmlns:rs=&quot;urn:schemas-microsoft-com:rowset&quot; xmlns:z=&quot;#RowsetSchema&quot; xmlns:b=&quot;urn:schemas-microsoft-com:office:publisher&quot; xmlns:ss=&quot;urn:schemas-microsoft-com:office:spreadsheet&quot; xmlns:c=&quot;urn:schemas-microsoft-com:office:component:spreadsheet&quot; xmlns:odc=&quot;urn:schemas-microsoft-com:office:odc&quot; xmlns:oa=&quot;urn:schemas-microsoft-com:office:activation&quot; xmlns:html=&quot;http://www.w3.org/TR/REC-html40&quot; xmlns:q=&quot;http://schemas.xmlsoap.org/soap/envelope/&quot; xmlns:D=&quot;DAV:&quot; xmlns:x2=&quot;http://schemas.microsoft.com/office/excel/2003/xml&quot; xmlns:ois=&quot;http://schemas.microsoft.com/sharepoint/soap/ois/&quot; xmlns:dir=&quot;http://schemas.microsoft.com/sharepoint/soap/directory/&quot; xmlns:ds=&quot;http://www.w3.org/2000/09/xmldsig#&quot; xmlns:dsp=&quot;http://schemas.microsoft.com/sharepoint/dsp&quot; xmlns:udc=&quot;http://schemas.microsoft.com/data/udc&quot; xmlns:xsd=&quot;http://www.w3.org/2001/XMLSchema&quot; xmlns:sub=&quot;http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/&quot; xmlns:ec=&quot;http://www.w3.org/2001/04/xmlenc#&quot; xmlns:sp=&quot;http://schemas.microsoft.com/sharepoint/&quot; xmlns:sps=&quot;http://schemas.microsoft.com/sharepoint/soap/&quot; xmlns:xsi=&quot;http://www.w3.org/2001/XMLSchema-instance&quot; xmlns:udcxf=&quot;http://schemas.microsoft.com/data/udc/xmlfile&quot; xmlns:st=&quot;&amp;#1;&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot; xmlns:ns0=&quot;http://schemas.microsoft.com/sharepoint/soap/workflow/&quot; xmlns:ns1=&quot;http://schemas.openxmlformats.org/markup-compatibility/2006&quot; xmlns:ns2=&quot;http://schemas.microsoft.com/office/2004/12/omml&quot; xmlns:ns3=&quot;http://schemas.openxmlformats.org/package/2006/relationships&quot; xmlns:ns4=&quot;http://schemas.microsoft.com/exchange/services/2006/types&quot; xmlns:ns5=&quot;http://schemas.microsoft.com/exchange/services/2006/messages&quot; xmlns:ns6=&quot;urn:schemas-microsoft-com:&quot;&gt;

&lt;head&gt;
&lt;meta http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 11 (filtered medium)&quot;&gt;
&lt;!--[if !mso]&gt;
&lt;style&gt;
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body lang=DE link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;Hi, Praveen!&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;You can download the
NSRemote from the Juniper-Site (Support / Download Software)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;You have to log in, choose
&amp;#8216;NetScreen Remote VPN Client&amp;#8217; and then enter the serial-Number from
your bought NS-Remote to be able to download the current version.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;In case you havent&amp;#8217;t
bougth the client yet &amp;#8211; it&amp;#8217;s really cheap (I guess about 10 Dollars
when bought in a pack of 100).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;Cheers,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;&amp;nbsp; Kai &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;div&gt;

&lt;div class=MsoNormal align=center style='text-align:center'&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:12.0pt'&gt;

&lt;hr size=2 width=&quot;100%&quot; align=center tabindex=-1&gt;

&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 face=Tahoma&gt;&lt;span style='font-size:10.0pt;
font-family:Tahoma;font-weight:bold'&gt;Von:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 face=Tahoma&gt;&lt;span style='font-size:10.0pt;font-family:Tahoma'&gt; Praveen Sankar
[mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19266386&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;praveen.sankar@...&lt;/a&gt;] &lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Gesendet:&lt;/span&gt;&lt;/b&gt; Dienstag, 2. September
2008 07:15&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;An:&lt;/span&gt;&lt;/b&gt; Kai Krebber&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Cc:&lt;/span&gt;&lt;/b&gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19266386&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Betreff:&lt;/span&gt;&lt;/b&gt; RE: [nn] Policy traffic
shaping netscreen&lt;/span&gt;&lt;/font&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Hi Kai,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Tried below
mentioned software , but no luck. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Getting error
message as &amp;#8220;Tunnel &amp;nbsp;Disabled&amp;#8221;. I used to connect vpn to IKE
authentication. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Do you/anyone know
from where I can download Net screen Remote VPN client Ver. 9.0 .&amp;nbsp; It is
quite urgent for me to set vpn for&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Marketing guys who
is travelling with in two days. Please help .&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Thanks ,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Praveen.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;div&gt;

&lt;div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm'&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 face=Tahoma&gt;&lt;span lang=EN-US style='font-size:10.0pt;font-family:Tahoma;font-weight:bold'&gt;From:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 face=Tahoma&gt;&lt;span lang=EN-US style='font-size:10.0pt;font-family:Tahoma'&gt;
Kai Krebber [mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19266386&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Kai.Krebber@...&lt;/a&gt;] &lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Sent:&lt;/span&gt;&lt;/b&gt; Wednesday, August 27, 2008
11:55 AM&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;To:&lt;/span&gt;&lt;/b&gt; Praveen Sankar&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Cc:&lt;/span&gt;&lt;/b&gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19266386&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Subject:&lt;/span&gt;&lt;/b&gt; AW: [nn] Policy traffic
shaping netscreen&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span lang=EN-US style='font-size:12.0pt'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;&lt;a href=&quot;http://www.shrew.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;&lt;span lang=EN-GB&gt;http://www.shrew.net/&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:
Arial;color:navy'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;Didn&amp;#8217;t try it yet,
but supposed to work just fine.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;Cheers,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;Kai&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;div&gt;

&lt;div class=MsoNormal align=center style='text-align:center'&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:12.0pt'&gt;

&lt;hr size=2 width=&quot;100%&quot; align=center&gt;

&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 face=Tahoma&gt;&lt;span style='font-size:10.0pt;
font-family:Tahoma;font-weight:bold'&gt;Von:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 face=Tahoma&gt;&lt;span style='font-size:10.0pt;font-family:Tahoma'&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19266386&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn-bounces@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19266386&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn-bounces@...&lt;/a&gt;] &lt;b&gt;&lt;span style='font-weight:bold'&gt;Im Auftrag von &lt;/span&gt;&lt;/b&gt;Praveen Sankar&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Gesendet:&lt;/span&gt;&lt;/b&gt; Mittwoch, 27. August
2008 08:17&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;An:&lt;/span&gt;&lt;/b&gt; 'Juniper-Nsp'; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19266386&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Betreff:&lt;/span&gt;&lt;/b&gt; Re: [nn] Policy traffic
shaping netscreen&lt;/span&gt;&lt;/font&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Hi All, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;I m looking for
vpn_client_juniper software which is suitable for Windows Vista. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;I m having the
software which is suitable for XP , and it is working well too. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;In coming week, I
need to configure VPN for vista user. I would be grateful if anyone can provide
me the link where I can get the software. &amp;nbsp;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Looking forward to
hearing from you.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Thanks and regards,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Praveen. &amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19266386&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Policy-traffic-shaping-netscreen-tp19027684p19266386.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19264226</id>
	<title>Re: Policy traffic shaping netscreen</title>
	<published>2008-09-01T22:12:32Z</published>
	<updated>2008-09-01T22:12:32Z</updated>
	<author>
		<name>Praveen Sankar</name>
	</author>
	<content type="html">&lt;html xmlns:v=&quot;urn:schemas-microsoft-com:vml&quot; xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns:x=&quot;urn:schemas-microsoft-com:office:excel&quot; xmlns:p=&quot;urn:schemas-microsoft-com:office:powerpoint&quot; xmlns:a=&quot;urn:schemas-microsoft-com:office:access&quot; xmlns:dt=&quot;uuid:C2F41010-65B3-11d1-A29F-00AA00C14882&quot; xmlns:s=&quot;uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882&quot; xmlns:rs=&quot;urn:schemas-microsoft-com:rowset&quot; xmlns:Z=&quot;urn:schemas-microsoft-com:&quot; xmlns:b=&quot;urn:schemas-microsoft-com:office:publisher&quot; xmlns:ss=&quot;urn:schemas-microsoft-com:office:spreadsheet&quot; xmlns:c=&quot;urn:schemas-microsoft-com:office:component:spreadsheet&quot; xmlns:odc=&quot;urn:schemas-microsoft-com:office:odc&quot; xmlns:oa=&quot;urn:schemas-microsoft-com:office:activation&quot; xmlns:html=&quot;http://www.w3.org/TR/REC-html40&quot; xmlns:q=&quot;http://schemas.xmlsoap.org/soap/envelope/&quot; xmlns:D=&quot;DAV:&quot; xmlns:x2=&quot;http://schemas.microsoft.com/office/excel/2003/xml&quot; xmlns:ois=&quot;http://schemas.microsoft.com/sharepoint/soap/ois/&quot; xmlns:dir=&quot;http://schemas.microsoft.com/sharepoint/soap/directory/&quot; xmlns:ds=&quot;http://www.w3.org/2000/09/xmldsig#&quot; xmlns:dsp=&quot;http://schemas.microsoft.com/sharepoint/dsp&quot; xmlns:udc=&quot;http://schemas.microsoft.com/data/udc&quot; xmlns:xsd=&quot;http://www.w3.org/2001/XMLSchema&quot; xmlns:sub=&quot;http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/&quot; xmlns:ec=&quot;http://www.w3.org/2001/04/xmlenc#&quot; xmlns:sp=&quot;http://schemas.microsoft.com/sharepoint/&quot; xmlns:sps=&quot;http://schemas.microsoft.com/sharepoint/soap/&quot; xmlns:xsi=&quot;http://www.w3.org/2001/XMLSchema-instance&quot; xmlns:udcxf=&quot;http://schemas.microsoft.com/data/udc/xmlfile&quot; xmlns:wf=&quot;http://schemas.microsoft.com/sharepoint/soap/workflow/&quot; xmlns:mver=&quot;http://schemas.openxmlformats.org/markup-compatibility/2006&quot; xmlns:m=&quot;http://schemas.microsoft.com/office/2004/12/omml&quot; xmlns:mrels=&quot;http://schemas.openxmlformats.org/package/2006/relationships&quot; xmlns:ex12t=&quot;http://schemas.microsoft.com/exchange/services/2006/types&quot; xmlns:ex12m=&quot;http://schemas.microsoft.com/exchange/services/2006/messages&quot; xmlns:st=&quot;&amp;#1;&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;META HTTP-EQUIV=&quot;Content-Type&quot; CONTENT=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 12 (filtered medium)&quot;&gt;
&lt;!--[if !mso]&gt;
&lt;style&gt;
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Hi Kai,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Tried below mentioned software , but no luck. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Getting error message as &amp;#8220;Tunnel &amp;nbsp;Disabled&amp;#8221;. I used to connect
vpn to IKE authentication. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Do you/anyone know from where I can download Net screen Remote
VPN client Ver. 9.0 .&amp;nbsp; It is quite urgent for me to set vpn for&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Marketing guys who is travelling with in two days. Please help .&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Thanks ,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Praveen.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;div&gt;

&lt;div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;From:&lt;/span&gt;&lt;/b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt; Kai Krebber
[mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264226&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Kai.Krebber@...&lt;/a&gt;] &lt;br&gt;
&lt;b&gt;Sent:&lt;/b&gt; Wednesday, August 27, 2008 11:55 AM&lt;br&gt;
&lt;b&gt;To:&lt;/b&gt; Praveen Sankar&lt;br&gt;
&lt;b&gt;Cc:&lt;/b&gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264226&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;
&lt;b&gt;Subject:&lt;/b&gt; AW: [nn] Policy traffic shaping netscreen&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span lang=DE style='font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:navy'&gt;&lt;a href=&quot;http://www.shrew.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;&lt;span lang=EN-GB&gt;http://www.shrew.net/&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:navy'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:navy'&gt;Didn&amp;#8217;t try it yet, but supposed to work just fine.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:navy'&gt;Cheers,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:navy'&gt;Kai&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;div&gt;

&lt;div class=MsoNormal align=center style='text-align:center'&gt;&lt;span lang=DE&gt;

&lt;hr size=2 width=&quot;100%&quot; align=center&gt;

&lt;/span&gt;&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;span lang=DE style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;Von:&lt;/span&gt;&lt;/b&gt;&lt;span lang=DE style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264226&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn-bounces@...&lt;/a&gt;
[mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264226&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn-bounces@...&lt;/a&gt;] &lt;b&gt;Im Auftrag von &lt;/b&gt;Praveen Sankar&lt;br&gt;
&lt;b&gt;Gesendet:&lt;/b&gt; Mittwoch, 27. August 2008 08:17&lt;br&gt;
&lt;b&gt;An:&lt;/b&gt; 'Juniper-Nsp'; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264226&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;
&lt;b&gt;Betreff:&lt;/b&gt; Re: [nn] Policy traffic shaping netscreen&lt;/span&gt;&lt;span lang=DE&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;span lang=DE&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Hi All, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;I m looking for vpn_client_juniper software which is suitable
for Windows Vista. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;I m having the software which is suitable for XP , and it is
working well too. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;In coming week, I need to configure VPN for vista user. I would
be grateful if anyone can provide me the link where I can get the software.
&amp;nbsp;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Looking forward to hearing from you.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Thanks and regards,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Praveen. &amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264226&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Policy-traffic-shaping-netscreen-tp19027684p19264226.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19192197</id>
	<title>Unencrypted 6over4 tunnel config?</title>
	<published>2008-08-27T17:13:25Z</published>
	<updated>2008-08-27T17:13:25Z</updated>
	<author>
		<name>Kevin Stevens-3</name>
	</author>
	<content type="html">I'm trying to set up a plain unemcrypted, encapsulated tunnel to my tunnel 
&lt;br&gt;broker (Hurricane).
&lt;br&gt;&lt;br&gt;All the C&amp;E examples deal with using IPSEC tunnels, with NS devices on both 
&lt;br&gt;ends. &amp;nbsp;Any quick config examples?
&lt;br&gt;&lt;br&gt;KeS
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19192197&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Unencrypted-6over4-tunnel-config--tp19192197p19192197.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19181004</id>
	<title>Re: Policy traffic shaping netscreen</title>
	<published>2008-08-27T06:30:56Z</published>
	<updated>2008-08-27T06:30:56Z</updated>
	<author>
		<name>Praveen Sankar</name>
	</author>
	<content type="html">Thanks Greg.
&lt;br&gt;&lt;br&gt;Will test it and update the status.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Praveen.
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Greg Conroy [mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19181004&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;gconroy@...&lt;/a&gt;]
&lt;br&gt;Sent: Wednesday, August 27, 2008 6:55 PM
&lt;br&gt;To: Kai Krebber
&lt;br&gt;Cc: Praveen Sankar; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19181004&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;Subject: Re: [nn] Policy traffic shaping netscreen
&lt;br&gt;&lt;br&gt;The Netscreen remote client version 9.0 works with 32bit Vista, but not
&lt;br&gt;with 64bit Vista. &amp;nbsp;If you need a client for 64bit Vista (or 64 bit XP)
&lt;br&gt;you can use the NCP Universal IPSec VPN Client. &amp;nbsp;That client also works
&lt;br&gt;with XP 32/64 and Windows 2000 as well as CE. &amp;nbsp;I believe they also have
&lt;br&gt;a Linux client as well.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.ncp-e.com/en/vpn-szenarien-produkte/vpn-produkte/secure-entry-client.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ncp-e.com/en/vpn-szenarien-produkte/vpn-produkte/secure-entry-client.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Greg
&lt;br&gt;&lt;br&gt;Kai Krebber wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.shrew.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.shrew.net/&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Didn’t try it yet, but supposed to work just fine.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cheers,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Kai
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; *Von:* &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19181004&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn-bounces@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19181004&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn-bounces@...&lt;/a&gt;] *Im
&lt;br&gt;&amp;gt; Auftrag von *Praveen Sankar
&lt;br&gt;&amp;gt; *Gesendet:* Mittwoch, 27. August 2008 08:17
&lt;br&gt;&amp;gt; *An:* 'Juniper-Nsp'; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19181004&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&amp;gt; *Betreff:* Re: [nn] Policy traffic shaping netscreen
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hi All,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I m looking for vpn_client_juniper software which is suitable for
&lt;br&gt;&amp;gt; Windows Vista.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I m having the software which is suitable for XP , and it is working
&lt;br&gt;&amp;gt; well too.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; In coming week, I need to configure VPN for vista user. I would be
&lt;br&gt;&amp;gt; grateful if anyone can provide me the link where I can get the
&lt;br&gt;&amp;gt; software.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Looking forward to hearing from you.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks and regards,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Praveen.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; nn mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19181004&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;/div&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19181004&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Policy-traffic-shaping-netscreen-tp19027684p19181004.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19181515</id>
	<title>Re: Policy traffic shaping netscreen</title>
	<published>2008-08-27T06:24:44Z</published>
	<updated>2008-08-27T06:24:44Z</updated>
	<author>
		<name>Greg Conroy</name>
	</author>
	<content type="html">The Netscreen remote client version 9.0 works with 32bit Vista, but not 
&lt;br&gt;with 64bit Vista. &amp;nbsp;If you need a client for 64bit Vista (or 64 bit XP) 
&lt;br&gt;you can use the NCP Universal IPSec VPN Client. &amp;nbsp;That client also works 
&lt;br&gt;with XP 32/64 and Windows 2000 as well as CE. &amp;nbsp;I believe they also have 
&lt;br&gt;a Linux client as well.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.ncp-e.com/en/vpn-szenarien-produkte/vpn-produkte/secure-entry-client.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ncp-e.com/en/vpn-szenarien-produkte/vpn-produkte/secure-entry-client.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Greg
&lt;br&gt;&lt;br&gt;Kai Krebber wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.shrew.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.shrew.net/&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Didn’t try it yet, but supposed to work just fine.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cheers,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Kai
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; *Von:* &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19181515&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn-bounces@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19181515&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn-bounces@...&lt;/a&gt;] *Im 
&lt;br&gt;&amp;gt; Auftrag von *Praveen Sankar
&lt;br&gt;&amp;gt; *Gesendet:* Mittwoch, 27. August 2008 08:17
&lt;br&gt;&amp;gt; *An:* 'Juniper-Nsp'; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19181515&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&amp;gt; *Betreff:* Re: [nn] Policy traffic shaping netscreen
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hi All,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I m looking for vpn_client_juniper software which is suitable for 
&lt;br&gt;&amp;gt; Windows Vista.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I m having the software which is suitable for XP , and it is working 
&lt;br&gt;&amp;gt; well too.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; In coming week, I need to configure VPN for vista user. I would be 
&lt;br&gt;&amp;gt; grateful if anyone can provide me the link where I can get the 
&lt;br&gt;&amp;gt; software. &amp;nbsp; 
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Looking forward to hearing from you.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks and regards,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Praveen. &amp;nbsp;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; nn mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19181515&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19181515&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Policy-traffic-shaping-netscreen-tp19027684p19181515.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19175971</id>
	<title>Re: Policy traffic shaping netscreen</title>
	<published>2008-08-26T23:54:53Z</published>
	<updated>2008-08-26T23:54:53Z</updated>
	<author>
		<name>Stefan Bauer-5</name>
	</author>
	<content type="html">* Kai Krebber &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19175971&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Kai.Krebber@...&lt;/a&gt;&amp;gt; [27.08.2008 08:40]:
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.shrew.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.shrew.net/&lt;/a&gt;&amp;nbsp;&amp;lt;&lt;a href=&quot;http://www.shrew.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.shrew.net/&lt;/a&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Didn't try it yet, but supposed to work just fine.
&lt;br&gt;&lt;br&gt;works fine in my case with a 5XT and GT.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19175971&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stefan.bauer@...&lt;/a&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Linux Professional
&lt;br&gt;Phone &amp;nbsp;+49 89 26 216 964 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Debian GNU/Linux
&lt;br&gt;Mobile +49 179 11 94 767 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Josef-Führer-Str. 30
&lt;br&gt;&lt;a href=&quot;http://www.plzk.de&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.plzk.de&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;80997 München
&lt;br&gt;&lt;br&gt;Bitte senden Sie mir keine Word- oder PowerPoint-Anhänge.
&lt;br&gt;Siehe &lt;a href=&quot;http://www.gnu.org/philosophy/no-word-attachments.de.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.gnu.org/philosophy/no-word-attachments.de.html&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19175971&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Policy-traffic-shaping-netscreen-tp19027684p19175971.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19175506</id>
	<title>Re: Policy traffic shaping netscreen</title>
	<published>2008-08-26T23:25:29Z</published>
	<updated>2008-08-26T23:25:29Z</updated>
	<author>
		<name>Kai Krebber</name>
	</author>
	<content type="html">&lt;html xmlns:v=&quot;urn:schemas-microsoft-com:vml&quot; xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns:x=&quot;urn:schemas-microsoft-com:office:excel&quot; xmlns:p=&quot;urn:schemas-microsoft-com:office:powerpoint&quot; xmlns:a=&quot;urn:schemas-microsoft-com:office:access&quot; xmlns:dt=&quot;uuid:C2F41010-65B3-11d1-A29F-00AA00C14882&quot; xmlns:s=&quot;uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882&quot; xmlns:rs=&quot;urn:schemas-microsoft-com:rowset&quot; xmlns:z=&quot;#RowsetSchema&quot; xmlns:b=&quot;urn:schemas-microsoft-com:office:publisher&quot; xmlns:ss=&quot;urn:schemas-microsoft-com:office:spreadsheet&quot; xmlns:c=&quot;urn:schemas-microsoft-com:office:component:spreadsheet&quot; xmlns:odc=&quot;urn:schemas-microsoft-com:office:odc&quot; xmlns:oa=&quot;urn:schemas-microsoft-com:office:activation&quot; xmlns:html=&quot;http://www.w3.org/TR/REC-html40&quot; xmlns:q=&quot;http://schemas.xmlsoap.org/soap/envelope/&quot; xmlns:D=&quot;DAV:&quot; xmlns:x2=&quot;http://schemas.microsoft.com/office/excel/2003/xml&quot; xmlns:ois=&quot;http://schemas.microsoft.com/sharepoint/soap/ois/&quot; xmlns:dir=&quot;http://schemas.microsoft.com/sharepoint/soap/directory/&quot; xmlns:ds=&quot;http://www.w3.org/2000/09/xmldsig#&quot; xmlns:dsp=&quot;http://schemas.microsoft.com/sharepoint/dsp&quot; xmlns:udc=&quot;http://schemas.microsoft.com/data/udc&quot; xmlns:xsd=&quot;http://www.w3.org/2001/XMLSchema&quot; xmlns:sub=&quot;http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/&quot; xmlns:ec=&quot;http://www.w3.org/2001/04/xmlenc#&quot; xmlns:sp=&quot;http://schemas.microsoft.com/sharepoint/&quot; xmlns:sps=&quot;http://schemas.microsoft.com/sharepoint/soap/&quot; xmlns:xsi=&quot;http://www.w3.org/2001/XMLSchema-instance&quot; xmlns:udcxf=&quot;http://schemas.microsoft.com/data/udc/xmlfile&quot; xmlns:st=&quot;&amp;#1;&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot; xmlns:ns0=&quot;http://schemas.microsoft.com/sharepoint/soap/workflow/&quot; xmlns:ns1=&quot;http://schemas.openxmlformats.org/markup-compatibility/2006&quot; xmlns:ns2=&quot;http://schemas.microsoft.com/office/2004/12/omml&quot; xmlns:ns3=&quot;http://schemas.openxmlformats.org/package/2006/relationships&quot; xmlns:ns4=&quot;http://schemas.microsoft.com/exchange/services/2006/types&quot; xmlns:ns5=&quot;http://schemas.microsoft.com/exchange/services/2006/messages&quot; xmlns:ns6=&quot;urn:schemas-microsoft-com:&quot;&gt;

&lt;head&gt;
&lt;META HTTP-EQUIV=&quot;Content-Type&quot; CONTENT=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 11 (filtered medium)&quot;&gt;
&lt;!--[if !mso]&gt;
&lt;style&gt;
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body lang=DE link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;&lt;a href=&quot;http://www.shrew.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;&lt;span lang=EN-GB&gt;http://www.shrew.net/&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:
Arial;color:navy'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;Didn&amp;#8217;t try it yet,
but supposed to work just fine.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;Cheers,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;Kai&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span lang=EN-GB style='font-size:10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;div&gt;

&lt;div class=MsoNormal align=center style='text-align:center'&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:12.0pt'&gt;

&lt;hr size=2 width=&quot;100%&quot; align=center tabindex=-1&gt;

&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 face=Tahoma&gt;&lt;span style='font-size:10.0pt;
font-family:Tahoma;font-weight:bold'&gt;Von:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 face=Tahoma&gt;&lt;span style='font-size:10.0pt;font-family:Tahoma'&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19175506&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn-bounces@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19175506&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn-bounces@...&lt;/a&gt;] &lt;b&gt;&lt;span style='font-weight:bold'&gt;Im Auftrag von &lt;/span&gt;&lt;/b&gt;Praveen Sankar&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Gesendet:&lt;/span&gt;&lt;/b&gt; Mittwoch, 27. August
2008 08:17&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;An:&lt;/span&gt;&lt;/b&gt; 'Juniper-Nsp'; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19175506&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Betreff:&lt;/span&gt;&lt;/b&gt; Re: [nn] Policy traffic
shaping netscreen&lt;/span&gt;&lt;/font&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Hi All, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;I m looking for
vpn_client_juniper software which is suitable for Windows Vista. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;I m having the
software which is suitable for XP , and it is working well too. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;In coming week, I
need to configure VPN for vista user. I would be grateful if anyone can provide
me the link where I can get the software. &amp;nbsp;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Looking forward to
hearing from you.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Thanks and regards,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#1f497d&quot; face=Calibri&gt;&lt;span lang=EN-US style='font-size:11.0pt;font-family:Calibri;color:#1F497D'&gt;Praveen. &amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19175506&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Policy-traffic-shaping-netscreen-tp19027684p19175506.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19175266</id>
	<title>Re: Policy traffic shaping netscreen</title>
	<published>2008-08-26T23:15:47Z</published>
	<updated>2008-08-26T23:15:47Z</updated>
	<author>
		<name>Praveen Sankar</name>
	</author>
	<content type="html">&lt;html xmlns:v=&quot;urn:schemas-microsoft-com:vml&quot; xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns:x=&quot;urn:schemas-microsoft-com:office:excel&quot; xmlns:p=&quot;urn:schemas-microsoft-com:office:powerpoint&quot; xmlns:a=&quot;urn:schemas-microsoft-com:office:access&quot; xmlns:dt=&quot;uuid:C2F41010-65B3-11d1-A29F-00AA00C14882&quot; xmlns:s=&quot;uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882&quot; xmlns:rs=&quot;urn:schemas-microsoft-com:rowset&quot; xmlns:Z=&quot;urn:schemas-microsoft-com:&quot; xmlns:b=&quot;urn:schemas-microsoft-com:office:publisher&quot; xmlns:ss=&quot;urn:schemas-microsoft-com:office:spreadsheet&quot; xmlns:c=&quot;urn:schemas-microsoft-com:office:component:spreadsheet&quot; xmlns:odc=&quot;urn:schemas-microsoft-com:office:odc&quot; xmlns:oa=&quot;urn:schemas-microsoft-com:office:activation&quot; xmlns:html=&quot;http://www.w3.org/TR/REC-html40&quot; xmlns:q=&quot;http://schemas.xmlsoap.org/soap/envelope/&quot; xmlns:D=&quot;DAV:&quot; xmlns:x2=&quot;http://schemas.microsoft.com/office/excel/2003/xml&quot; xmlns:ois=&quot;http://schemas.microsoft.com/sharepoint/soap/ois/&quot; xmlns:dir=&quot;http://schemas.microsoft.com/sharepoint/soap/directory/&quot; xmlns:ds=&quot;http://www.w3.org/2000/09/xmldsig#&quot; xmlns:dsp=&quot;http://schemas.microsoft.com/sharepoint/dsp&quot; xmlns:udc=&quot;http://schemas.microsoft.com/data/udc&quot; xmlns:xsd=&quot;http://www.w3.org/2001/XMLSchema&quot; xmlns:sub=&quot;http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/&quot; xmlns:ec=&quot;http://www.w3.org/2001/04/xmlenc#&quot; xmlns:sp=&quot;http://schemas.microsoft.com/sharepoint/&quot; xmlns:sps=&quot;http://schemas.microsoft.com/sharepoint/soap/&quot; xmlns:xsi=&quot;http://www.w3.org/2001/XMLSchema-instance&quot; xmlns:udcxf=&quot;http://schemas.microsoft.com/data/udc/xmlfile&quot; xmlns:wf=&quot;http://schemas.microsoft.com/sharepoint/soap/workflow/&quot; xmlns:mver=&quot;http://schemas.openxmlformats.org/markup-compatibility/2006&quot; xmlns:m=&quot;http://schemas.microsoft.com/office/2004/12/omml&quot; xmlns:mrels=&quot;http://schemas.openxmlformats.org/package/2006/relationships&quot; xmlns:ex12t=&quot;http://schemas.microsoft.com/exchange/services/2006/types&quot; xmlns:ex12m=&quot;http://schemas.microsoft.com/exchange/services/2006/messages&quot; xmlns:st=&quot;&amp;#1;&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;META HTTP-EQUIV=&quot;Content-Type&quot; CONTENT=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 12 (filtered medium)&quot;&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Hi All, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;I m looking for vpn_client_juniper software which is suitable
for Windows Vista. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;I m having the software which is suitable for XP , and it is
working well too. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;In coming week, I need to configure VPN for vista user. I would
be grateful if anyone can provide me the link where I can get the software. &amp;nbsp;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Looking forward to hearing from you.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Thanks and regards,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Praveen. &amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19175266&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Policy-traffic-shaping-netscreen-tp19027684p19175266.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19132183</id>
	<title>Re: VPN Tunnel Woes - Again</title>
	<published>2008-08-24T09:44:07Z</published>
	<updated>2008-08-24T09:44:07Z</updated>
	<author>
		<name>Marc Haber-6</name>
	</author>
	<content type="html">On Sun, Aug 24, 2008 at 06:20:53PM +0530, Naveen Dhar wrote:
&lt;br&gt;&amp;gt; This would be counted as using 2 vpn's bcos 2 tunnel interfaces are being
&lt;br&gt;&amp;gt; used between the same two gateways whereas in policy based VPN, it would be
&lt;br&gt;&amp;gt; seen as 1 VPN tunnel being used with any number of vpn policies assigned to
&lt;br&gt;&amp;gt; it.
&lt;br&gt;&lt;br&gt;Policy Based VPN is not an option because of the network structure
&lt;br&gt;involved.
&lt;br&gt;&lt;br&gt;&amp;gt; So if you now have about 25 different small subnets to be going through vpn
&lt;br&gt;&amp;gt; in future, you may end up using 25 vpn license.
&lt;br&gt;&lt;br&gt;This is still cheaper than re-working the network and living with the
&lt;br&gt;complexity of having the netscreen connected with two interfaces.
&lt;br&gt;&lt;br&gt;Greetings
&lt;br&gt;Marc
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;-----------------------------------------------------------------------------
&lt;br&gt;Marc Haber &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;I don't trust Computers. They | Mailadresse im Header
&lt;br&gt;Mannheim, Germany &amp;nbsp;| &amp;nbsp;lose things.&amp;quot; &amp;nbsp; &amp;nbsp;Winona Ryder | Fon: *49 621 72739834
&lt;br&gt;Nordisch by Nature | &amp;nbsp;How to make an American Quilt | Fax: *49 3221 2323190
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19132183&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/VPN-Tunnel-Woes---Again-tp19023612p19132183.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19130356</id>
	<title>Re: VPN Tunnel Woes - Again</title>
	<published>2008-08-24T05:50:53Z</published>
	<updated>2008-08-24T05:50:53Z</updated>
	<author>
		<name>Naveen Dhar</name>
	</author>
	<content type="html">&lt;div dir=&quot;ltr&quot;&gt;Great find mate but just a quickie.. i believe if you have a small netscreen device like 10 vpn allowed.&lt;br&gt;&lt;br&gt;This would be counted as using 2 vpn&amp;#39;s bcos 2 tunnel interfaces are being used between the same two gateways whereas in policy based VPN, it would be seen as 1 VPN tunnel being used with any number of vpn policies assigned to it.&lt;br&gt;
&lt;br&gt;So if you now have about 25 different small subnets to be going through vpn in future, you may end up using 25 vpn license.&lt;br&gt;&lt;br&gt;Cheers. &lt;br&gt;&lt;br&gt;:-)&lt;br&gt;&lt;br&gt;-- &lt;br&gt;Thanks &amp;amp; Regards,&lt;br&gt;Naveen Dhar&lt;br&gt;Lead Consultant &amp;amp; Subject Matter Expert - Network Security&lt;br&gt;
CCNA,CCSA,CCSE,JNCIA,JNCIS&lt;br&gt;Computer Sciences Corporation Pvt. Ltd.&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;2008/8/24 Marc Haber &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19130356&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mh%2Bqorbit-nn@...&lt;/a&gt;&amp;gt;&lt;/span&gt;&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;The issue is solved now.&lt;br&gt;
&lt;div class=&quot;Ih2E3d&quot;&gt;&lt;br&gt;
On Sun, Aug 17, 2008 at 11:09:38PM +0200, Marc Haber wrote:&lt;br&gt;
&amp;gt; set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; gateway &amp;quot;myvpn-172-16-251-112&amp;quot; no-replay tunnel idletime 0 proposal &amp;quot;g2-aes256-sha1&amp;quot;&lt;br&gt;
&amp;gt; set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; id 22 bind interface tunnel.5&lt;br&gt;
&amp;gt; set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; proxy-id local-ip &lt;a href=&quot;http://10.1.2.0/28&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.1.2.0/28&lt;/a&gt; remote-ip &lt;a href=&quot;http://10.101.139.64/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.64/30&lt;/a&gt; &amp;quot;ANY&amp;quot;&lt;br&gt;

&amp;gt; set route &lt;a href=&quot;http://10.101.139.64/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.64/30&lt;/a&gt; interface tunnel.5 preference 20&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; set interface &amp;quot;tunnel.5&amp;quot; zone &amp;quot;Untrust&amp;quot;&lt;br&gt;
&amp;gt; set interface tunnel.5 ip unnumbered interface untrust&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; set ike gateway &amp;quot;myvpn-172-16-251-112&amp;quot; address &lt;a href=&quot;http://172.16.251.112&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;172.16.251.112&lt;/a&gt; Main outgoing-interface &amp;quot;untrust&amp;quot; preshare &amp;quot;&amp;lt;snip&amp;gt;&amp;quot; proposal &amp;quot;pre-g2-aes256-sha1&amp;quot;&lt;br&gt;

&amp;gt; set ike gateway &amp;quot;myvpn-172-16-251-112&amp;quot; cert peer-ca all&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; set policy id 1 from &amp;quot;Untrust&amp;quot; to &amp;quot;Untrust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;ANY&amp;quot; permit log&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; This works just fine. I now need to add a second tunnel which has&lt;br&gt;
&amp;gt; &lt;a href=&quot;http://10.101.139.100/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.100/30&lt;/a&gt; as the remote side. As soon as I add the canonical&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; gateway &amp;quot;myvpn-172-16-251-112&amp;quot; no-replay tunnel idletime 0 proposal &amp;quot;g2-aes256-sha1&amp;quot;&lt;br&gt;
&amp;gt; set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; id 22 bind interface tunnel.5&lt;br&gt;
&amp;gt; set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; proxy-id local-ip &lt;a href=&quot;http://10.1.2.0/28&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.1.2.0/28&lt;/a&gt; remote-ip &lt;a href=&quot;http://10.101.139.100/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.100/30&lt;/a&gt; &amp;quot;ANY&amp;quot;&lt;br&gt;

&amp;gt; set route &lt;a href=&quot;http://10.101.139.100/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.100/30&lt;/a&gt; interface tunnel.5 preference 20&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;Two problems with this configuration:&lt;br&gt;
- need a dedicated tunnel interface for each tunnel&lt;br&gt;
- must not re-use the id in the bind interface tunnel line.&lt;br&gt;
&lt;br&gt;
Working configuration:&lt;br&gt;
set interface &amp;quot;tunnel.2&amp;quot; zone &amp;quot;Untrust&amp;quot;&lt;br&gt;
set interface &amp;quot;tunnel.3&amp;quot; zone &amp;quot;Untrust&amp;quot;&lt;br&gt;
set interface tunnel.2 ip unnumbered interface untrust&lt;br&gt;
set interface tunnel.3 ip unnumbered interface untrust&lt;br&gt;
set ike gateway &amp;quot;myvpn-10-101-251-112&amp;quot; address &lt;a href=&quot;http://10.101.251.112&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.251.112&lt;/a&gt; Main outgoing-interface &amp;quot;untrust&amp;quot; preshare &amp;quot;&amp;lt;snip&amp;gt;&amp;quot;&lt;br&gt;
set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; gateway &amp;quot;myvpn-10-101-251-112&amp;quot; no-replay tunnel idletime 0 proposal &amp;quot;g2-aes256-sha1&amp;quot;&lt;br&gt;
set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; id 30 bind interface tunnel.2&lt;br&gt;
set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; gateway &amp;quot;myvpn-10-101-251-112&amp;quot; no-replay tunnel idletime 0 proposal &amp;quot;g2-aes256-sha1&amp;quot;&lt;br&gt;
set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; id 31 bind interface tunnel.3&lt;br&gt;
set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; proxy-id local-ip &lt;a href=&quot;http://10.1.2.0/24&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.1.2.0/24&lt;/a&gt; remote-ip &lt;a href=&quot;http://10.101.139.64/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.64/30&lt;/a&gt; &amp;quot;ANY&amp;quot;&lt;br&gt;

set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; proxy-id local-ip &lt;a href=&quot;http://10.1.2.0/24&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.1.2.0/24&lt;/a&gt; remote-ip &lt;a href=&quot;http://10.101.139.100/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.100/30&lt;/a&gt; &amp;quot;ANY&amp;quot;&lt;br&gt;

&lt;br&gt;
&lt;br&gt;
Conslusion: Multiple proxy-IDs with the same remote side work fine&lt;br&gt;
even with route-based tunnels, if one does it right.&lt;br&gt;
&lt;br&gt;
Thanks to a lot of help I received on IRC.&lt;br&gt;
&lt;div class=&quot;Ih2E3d&quot;&gt;&lt;br&gt;
Greetings&lt;br&gt;
Marc&lt;br&gt;
&lt;br&gt;
--&lt;br&gt;
-----------------------------------------------------------------------------&lt;br&gt;
Marc Haber &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;I don&amp;#39;t trust Computers. They | Mailadresse im Header&lt;br&gt;
Mannheim, Germany &amp;nbsp;| &amp;nbsp;lose things.&amp;quot; &amp;nbsp; &amp;nbsp;Winona Ryder | Fon: *49 621 72739834&lt;br&gt;
Nordisch by Nature | &amp;nbsp;How to make an American Quilt | Fax: *49 3221 2323190&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;Bitte beachten Sie, daß dem [m.E. grundgesetzwidrigen] Gesetz zur&lt;br&gt;
Vorratsdatenspeicherung zufolge, seit dem 1. Januar 2008 jeglicher&lt;br&gt;
elektronische Kontakt (E-Mail, Telefongespräche, SMS, Internet-&lt;br&gt;
Telefonie, Mobilfunk, Fax) mit mir oder anderen Nutzern verdachts-&lt;br&gt;
unabhängig für den automatisierten geheimen Zugriff durch Strafver-&lt;br&gt;
folgungs- u. Polizeivollzugsbehörden, die Bundesanstalt für Finanz-&lt;br&gt;
dienstleistungsaufsicht, Zollkriminal- und Zollfahndungsämter,die&lt;br&gt;
Zollverwaltung zur Schwarzarbeitsbekämpfung, Notrufabfragestellen,&lt;br&gt;
Verfassungsschutzbehörden, den Militärischen Abschirmdienst, Bundes-&lt;br&gt;
nachrichtendienst sowie 52 Staaten wie beispielsweise Aserbeidschan&lt;br&gt;
oder die USA sechs Monate lang gespeichert wird, einschließlich der&lt;br&gt;
Kommunikation mit Berufsgeheimnisträgern wie Ärzten, Journalisten und&lt;br&gt;
Anwälten. Mehr Infos zur totalen Protokollierung Ihrer Kommunikations-&lt;br&gt;
daten auf &lt;a href=&quot;http://www.vorratsdatenspeicherung.de&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;www.vorratsdatenspeicherung.de&lt;/a&gt;. (leicht verändert übernommen&lt;br&gt;
kopiert von &lt;a href=&quot;http://www.lawblog.de&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;www.lawblog.de&lt;/a&gt;)&lt;br&gt;
&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class=&quot;Wj3C7c&quot;&gt;_______________________________________________&lt;br&gt;
nn mailing list&lt;br&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19130356&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;&lt;br&gt;
&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19130356&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/VPN-Tunnel-Woes---Again-tp19023612p19130356.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19129296</id>
	<title>Re: VPN Tunnel Woes - Again</title>
	<published>2008-08-24T03:09:48Z</published>
	<updated>2008-08-24T03:09:48Z</updated>
	<author>
		<name>Marc Haber-6</name>
	</author>
	<content type="html">The issue is solved now.
&lt;br&gt;&lt;br&gt;On Sun, Aug 17, 2008 at 11:09:38PM +0200, Marc Haber wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; gateway &amp;quot;myvpn-172-16-251-112&amp;quot; no-replay tunnel idletime 0 proposal &amp;quot;g2-aes256-sha1&amp;quot;
&lt;br&gt;&amp;gt; set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; id 22 bind interface tunnel.5
&lt;br&gt;&amp;gt; set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; proxy-id local-ip 10.1.2.0/28 remote-ip 10.101.139.64/30 &amp;quot;ANY&amp;quot;
&lt;br&gt;&amp;gt; set route 10.101.139.64/30 interface tunnel.5 preference 20
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; set interface &amp;quot;tunnel.5&amp;quot; zone &amp;quot;Untrust&amp;quot;
&lt;br&gt;&amp;gt; set interface tunnel.5 ip unnumbered interface untrust
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; set ike gateway &amp;quot;myvpn-172-16-251-112&amp;quot; address 172.16.251.112 Main outgoing-interface &amp;quot;untrust&amp;quot; preshare &amp;quot;&amp;lt;snip&amp;gt;&amp;quot; proposal &amp;quot;pre-g2-aes256-sha1&amp;quot;
&lt;br&gt;&amp;gt; set ike gateway &amp;quot;myvpn-172-16-251-112&amp;quot; cert peer-ca all
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; set policy id 1 from &amp;quot;Untrust&amp;quot; to &amp;quot;Untrust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;ANY&amp;quot; permit log
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; This works just fine. I now need to add a second tunnel which has
&lt;br&gt;&amp;gt; 10.101.139.100/30 as the remote side. As soon as I add the canonical
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; gateway &amp;quot;myvpn-172-16-251-112&amp;quot; no-replay tunnel idletime 0 proposal &amp;quot;g2-aes256-sha1&amp;quot;
&lt;br&gt;&amp;gt; set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; id 22 bind interface tunnel.5
&lt;br&gt;&amp;gt; set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; proxy-id local-ip 10.1.2.0/28 remote-ip 10.101.139.100/30 &amp;quot;ANY&amp;quot;
&lt;br&gt;&amp;gt; set route 10.101.139.100/30 interface tunnel.5 preference 20
&lt;/div&gt;&lt;br&gt;Two problems with this configuration:
&lt;br&gt;- need a dedicated tunnel interface for each tunnel
&lt;br&gt;- must not re-use the id in the bind interface tunnel line.
&lt;br&gt;&lt;br&gt;Working configuration:
&lt;br&gt;set interface &amp;quot;tunnel.2&amp;quot; zone &amp;quot;Untrust&amp;quot;
&lt;br&gt;set interface &amp;quot;tunnel.3&amp;quot; zone &amp;quot;Untrust&amp;quot;
&lt;br&gt;set interface tunnel.2 ip unnumbered interface untrust
&lt;br&gt;set interface tunnel.3 ip unnumbered interface untrust
&lt;br&gt;set ike gateway &amp;quot;myvpn-10-101-251-112&amp;quot; address 10.101.251.112 Main outgoing-interface &amp;quot;untrust&amp;quot; preshare &amp;quot;&amp;lt;snip&amp;gt;&amp;quot;
&lt;br&gt;set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; gateway &amp;quot;myvpn-10-101-251-112&amp;quot; no-replay tunnel idletime 0 proposal &amp;quot;g2-aes256-sha1&amp;quot;
&lt;br&gt;set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; id 30 bind interface tunnel.2
&lt;br&gt;set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; gateway &amp;quot;myvpn-10-101-251-112&amp;quot; no-replay tunnel idletime 0 proposal &amp;quot;g2-aes256-sha1&amp;quot;
&lt;br&gt;set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; id 31 bind interface tunnel.3
&lt;br&gt;set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; proxy-id local-ip 10.1.2.0/24 remote-ip 10.101.139.64/30 &amp;quot;ANY&amp;quot;
&lt;br&gt;set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; proxy-id local-ip 10.1.2.0/24 remote-ip 10.101.139.100/30 &amp;quot;ANY&amp;quot;
&lt;br&gt;&lt;br&gt;&lt;br&gt;Conslusion: Multiple proxy-IDs with the same remote side work fine
&lt;br&gt;even with route-based tunnels, if one does it right.
&lt;br&gt;&lt;br&gt;Thanks to a lot of help I received on IRC.
&lt;br&gt;&lt;br&gt;Greetings
&lt;br&gt;Marc
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;-----------------------------------------------------------------------------
&lt;br&gt;Marc Haber &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;I don't trust Computers. They | Mailadresse im Header
&lt;br&gt;Mannheim, Germany &amp;nbsp;| &amp;nbsp;lose things.&amp;quot; &amp;nbsp; &amp;nbsp;Winona Ryder | Fon: *49 621 72739834
&lt;br&gt;Nordisch by Nature | &amp;nbsp;How to make an American Quilt | Fax: *49 3221 2323190
&lt;br&gt;&lt;br&gt;Bitte beachten Sie, daß dem [m.E. grundgesetzwidrigen] Gesetz zur
&lt;br&gt;Vorratsdatenspeicherung zufolge, seit dem 1. Januar 2008 jeglicher
&lt;br&gt;elektronische Kontakt (E-Mail, Telefongespräche, SMS, Internet-
&lt;br&gt;Telefonie, Mobilfunk, Fax) mit mir oder anderen Nutzern verdachts-
&lt;br&gt;unabhängig für den automatisierten geheimen Zugriff durch Strafver-
&lt;br&gt;folgungs- u. Polizeivollzugsbehörden, die Bundesanstalt für Finanz-
&lt;br&gt;dienstleistungsaufsicht, Zollkriminal- und Zollfahndungsämter,die
&lt;br&gt;Zollverwaltung zur Schwarzarbeitsbekämpfung, Notrufabfragestellen,
&lt;br&gt;Verfassungsschutzbehörden, den Militärischen Abschirmdienst, Bundes-
&lt;br&gt;nachrichtendienst sowie 52 Staaten wie beispielsweise Aserbeidschan
&lt;br&gt;oder die USA sechs Monate lang gespeichert wird, einschließlich der
&lt;br&gt;Kommunikation mit Berufsgeheimnisträgern wie Ärzten, Journalisten und
&lt;br&gt;Anwälten. Mehr Infos zur totalen Protokollierung Ihrer Kommunikations-
&lt;br&gt;daten auf www.vorratsdatenspeicherung.de. (leicht verändert übernommen
&lt;br&gt;kopiert von www.lawblog.de)
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19129296&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/VPN-Tunnel-Woes---Again-tp19023612p19129296.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19128772</id>
	<title>Multiple Proxy-IDs per tunnel on a route-based VPN (was: VPN Tunnel Woes - Again)</title>
	<published>2008-08-24T01:53:23Z</published>
	<updated>2008-08-24T01:53:23Z</updated>
	<author>
		<name>Marc Haber-6</name>
	</author>
	<content type="html">On Tue, Aug 19, 2008 at 12:07:07AM +0200, Marc Haber wrote:
&lt;br&gt;&amp;gt; On Mon, Aug 18, 2008 at 01:16:09PM +0530, Naveen Dhar wrote:
&lt;br&gt;&amp;gt; &amp;gt; Policy based VPN allow multiple proxy id's to be generated per vpn policy
&lt;br&gt;&amp;gt; &amp;gt; inside the same tunnel.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Ok, I'll try converting to policy based VPNs in the next few days.
&lt;br&gt;&lt;br&gt;Now I remember why I used a route-based VPN in the first place. My
&lt;br&gt;netscreen device is not the actual firewall being used, it is only
&lt;br&gt;being used as a VPN gateway, only connected with a single Interface:
&lt;br&gt;&lt;br&gt;-------------------- &amp;nbsp; ---------------------
&lt;br&gt;| 10.101.139.64/30 | &amp;nbsp; | 10.101.139.100/30 |
&lt;br&gt;-------------------- &amp;nbsp; ---------------------
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;---------------------------
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp;Cisco Concentrator &amp;nbsp; |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;---------------------------
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;| 172.16.251.112
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;untrust
&lt;br&gt;-------------- &amp;nbsp; &amp;nbsp; &amp;nbsp;172.17.0.1 &amp;nbsp;-------------
&lt;br&gt;| Router &amp;nbsp; &amp;nbsp; |------------------| Netscreen |
&lt;br&gt;-------------- &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-------------
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|
&lt;br&gt;--------------
&lt;br&gt;| 10.1.2.7 &amp;nbsp; |
&lt;br&gt;--------------
&lt;br&gt;&lt;br&gt;The netscreen's untrust interface is the only interface connected.
&lt;br&gt;&lt;br&gt;With a policy-based VPN, i'd need the VPN policy to go from &amp;quot;untrust&amp;quot;
&lt;br&gt;to &amp;quot;untrust&amp;quot;, and untrust-to-untrust policies don't allow a VPN tunnel
&lt;br&gt;to be specified.
&lt;br&gt;&lt;br&gt;Is there and workaround to specify a VPN policy from untrust to
&lt;br&gt;untrust? I don't want to waste a second switch port on the Netscreen's
&lt;br&gt;trust interface and would really like to avoid the complexity of a
&lt;br&gt;second VLAN for the netscreen's trust interface.
&lt;br&gt;&lt;br&gt;Any ideas?
&lt;br&gt;&lt;br&gt;Greetings
&lt;br&gt;Marc
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;-----------------------------------------------------------------------------
&lt;br&gt;Marc Haber &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;I don't trust Computers. They | Mailadresse im Header
&lt;br&gt;Mannheim, Germany &amp;nbsp;| &amp;nbsp;lose things.&amp;quot; &amp;nbsp; &amp;nbsp;Winona Ryder | Fon: *49 621 72739834
&lt;br&gt;Nordisch by Nature | &amp;nbsp;How to make an American Quilt | Fax: *49 3221 2323190
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19128772&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/VPN-Tunnel-Woes---Again-tp19023612p19128772.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19040997</id>
	<title>Re: VPN Tunnel Woes - Again</title>
	<published>2008-08-18T15:07:07Z</published>
	<updated>2008-08-18T15:07:07Z</updated>
	<author>
		<name>Marc Haber-6</name>
	</author>
	<content type="html">On Mon, Aug 18, 2008 at 01:16:09PM +0530, Naveen Dhar wrote:
&lt;br&gt;&amp;gt; You can use one route based vpn tunnel with vpn proxy id as local *
&lt;br&gt;&amp;gt; 10.101.139.64/26* containing 10.101.139.64/30 &amp;nbsp;&amp; &amp;nbsp;10.101.139.100/30 &amp;nbsp;both
&lt;br&gt;&amp;gt; and then filter vpn traffic through vpn policies but you have to change the
&lt;br&gt;&amp;gt; encryption domain @ Cisco device as well to say remote party netscreen
&lt;br&gt;&amp;gt; subnet is *10.101.139.64/26* and not 10.101.139.64/30 &amp;nbsp;&amp; &amp;nbsp;10.101.139.100/30
&lt;br&gt;&lt;br&gt;I don't like that idea too much since there is already a request for a
&lt;br&gt;third tunnel whose remote side is not even in the same /8 network.
&lt;br&gt;&lt;br&gt;&amp;gt; Policy based VPN allow multiple proxy id's to be generated per vpn policy
&lt;br&gt;&amp;gt; inside the same tunnel.
&lt;br&gt;&lt;br&gt;Ok, I'll try converting to policy based VPNs in the next few days.
&lt;br&gt;&lt;br&gt;Does the config file pulled from the WebUI contain complete
&lt;br&gt;configuration, including all certificates, keys etc so that I can make
&lt;br&gt;a backup (and restore it!) before doing so?
&lt;br&gt;&lt;br&gt;Greetings
&lt;br&gt;Ma &amp;quot;nobody wants backup, everybody wants restore&amp;quot; rc
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;-----------------------------------------------------------------------------
&lt;br&gt;Marc Haber &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;I don't trust Computers. They | Mailadresse im Header
&lt;br&gt;Mannheim, Germany &amp;nbsp;| &amp;nbsp;lose things.&amp;quot; &amp;nbsp; &amp;nbsp;Winona Ryder | Fon: *49 621 72739834
&lt;br&gt;Nordisch by Nature | &amp;nbsp;How to make an American Quilt | Fax: *49 3221 2323190
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19040997&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/VPN-Tunnel-Woes---Again-tp19023612p19040997.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19027684</id>
	<title>Policy traffic shaping netscreen</title>
	<published>2008-08-18T01:36:33Z</published>
	<updated>2008-08-18T01:36:33Z</updated>
	<author>
		<name>sunnyday-2</name>
	</author>
	<content type="html">&lt;html xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;META HTTP-EQUIV=&quot;Content-Type&quot; CONTENT=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 11 (filtered medium)&quot;&gt;


&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=&quot;Lucida Sans Unicode&quot;&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Lucida Sans Unicode&quot;'&gt;Hello I have an SSG
140 with &amp;nbsp;screenOS &lt;/span&gt;&lt;/font&gt;&amp;nbsp;6.1.0r2.0&lt;font size=2 face=&quot;Lucida Sans Unicode&quot;&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Lucida Sans Unicode&quot;'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;And I have a problem with policy traffic shaping which does no seem to
work proper.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;When I configure a policy with guaranteed bw and maximum bw traffic seems
to be matched &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;at another policy with another source address than the one &amp;nbsp;configured.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;e.g 192.168.40.10 is matched at a policy with source 192.168.40.19&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;any ideas what causes this kind of behavior? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;Thank you &lt;br&gt;
&lt;br&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19027684&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Policy-traffic-shaping-netscreen-tp19027684p19027684.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19027233</id>
	<title>Re: VPN Tunnel Woes - Again</title>
	<published>2008-08-18T00:46:09Z</published>
	<updated>2008-08-18T00:46:09Z</updated>
	<author>
		<name>Naveen Dhar</name>
	</author>
	<content type="html">&lt;div dir=&quot;ltr&quot;&gt;&lt;div&gt;Marc,&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;You can use one route based vpn tunnel with vpn proxy id as local &lt;strong&gt;&lt;a href=&quot;http://10.101.139.64/26&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;10.101.139.64/26&lt;/a&gt;&lt;/strong&gt; containing &lt;a href=&quot;http://10.101.139.64/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.64/30&lt;/a&gt; &amp;nbsp;&amp;amp; &amp;nbsp;&lt;a href=&quot;http://10.101.139.100/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.100/30&lt;/a&gt;&amp;nbsp; both and then filter vpn traffic through vpn policies but you have to change the encryption domain @ Cisco device as well to say remote party netscreen subnet is &lt;strong&gt;&lt;a href=&quot;http://10.101.139.64/26&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;10.101.139.64/26&lt;/a&gt;&lt;/strong&gt; and not &lt;a href=&quot;http://10.101.139.64/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.64/30&lt;/a&gt; &amp;nbsp;&amp;amp; &amp;nbsp;&lt;a href=&quot;http://10.101.139.100/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.100/30&lt;/a&gt;&amp;nbsp;.&lt;/div&gt;

&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;With route based tunnels you can&amp;#39;t use multiple subnets as proxy id&amp;#39;s, so you have&amp;nbsp;to use supernet to cover both inidividual small subnets. Also if you have multiple subnets from Cisco LAN side as well then you need to use supernet for them as well or only other option is create policy based vpn.&lt;/div&gt;

&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Policy based VPN allow multiple proxy id&amp;#39;s to be generated per vpn policy inside the same tunnel.&lt;br&gt;&lt;/div&gt;
&lt;div&gt;&lt;br&gt;-- &lt;br&gt;Thanks &amp;amp; Regards,&lt;br&gt;Naveen Dhar&lt;br&gt;Lead Consultant &amp;amp; Subject Matter Expert - Network Security&lt;br&gt;CCNA,CCSA,CCSE,JNCIA,JNCIS&lt;br&gt;Computer Sciences Corporation Pvt. Ltd.&lt;br&gt;&lt;/div&gt;
&lt;div class=&quot;gmail_quote&quot;&gt;On Mon, Aug 18, 2008 at 11:48 AM, Marc Haber &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19027233&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mh%2Bqorbit-nn@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid&quot;&gt;
&lt;div class=&quot;Ih2E3d&quot;&gt;On Mon, Aug 18, 2008 at 10:52:14AM +0530, Naveen Dhar wrote:&lt;br&gt;&amp;gt; If you want multiple subnets to be accessed via VPN tunnel between NetScreen&lt;br&gt;&amp;gt; and Cisco then create Policy Based Tunnel on NetScreen device and all would&lt;br&gt;
&amp;gt; work. i have a few of them already working.&lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt; Route based tunnel should be used when you can use a supernet in vpn proxy&lt;br&gt;&amp;gt; id for netscreen vpn which covers both of those subnets inside it and both&lt;br&gt;
&amp;gt; subnets &lt;a href=&quot;http://10.101.139.64/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.64/30&lt;/a&gt; &amp;nbsp;&amp;amp; &amp;nbsp;&lt;a href=&quot;http://10.101.139.100/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.100/30&lt;/a&gt; &amp;nbsp;would work via the same one&lt;br&gt;&amp;gt; vpn tunnel via single tunnel interface.&lt;br&gt;
&lt;br&gt;&lt;/div&gt;I have always used route-based VPNs for years. Do I really have to&lt;br&gt;learn how to use policy-based VPNs as what I want cannot be&lt;br&gt;accomplished with route-based VPNs?&lt;br&gt;
&lt;div&gt;
&lt;div&gt;&lt;/div&gt;
&lt;div class=&quot;Wj3C7c&quot;&gt;&lt;br&gt;Greetings&lt;br&gt;Marc&lt;br&gt;&lt;br&gt;--&lt;br&gt;-----------------------------------------------------------------------------&lt;br&gt;Marc Haber &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;I don&amp;#39;t trust Computers. They | Mailadresse im Header&lt;br&gt;
Mannheim, Germany &amp;nbsp;| &amp;nbsp;lose things.&amp;quot; &amp;nbsp; &amp;nbsp;Winona Ryder | Fon: *49 621 72739834&lt;br&gt;Nordisch by Nature | &amp;nbsp;How to make an American Quilt | Fax: *49 3221 2323190&lt;br&gt;_______________________________________________&lt;br&gt;nn mailing list&lt;br&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19027233&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;&lt;/div&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19027233&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/VPN-Tunnel-Woes---Again-tp19023612p19027233.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19026474</id>
	<title>Re: VPN Tunnel Woes - Again</title>
	<published>2008-08-17T23:18:48Z</published>
	<updated>2008-08-17T23:18:48Z</updated>
	<author>
		<name>Marc Haber-6</name>
	</author>
	<content type="html">On Mon, Aug 18, 2008 at 10:52:14AM +0530, Naveen Dhar wrote:
&lt;br&gt;&amp;gt; If you want multiple subnets to be accessed via VPN tunnel between NetScreen
&lt;br&gt;&amp;gt; and Cisco then create Policy Based Tunnel on NetScreen device and all would
&lt;br&gt;&amp;gt; work. i have a few of them already working.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Route based tunnel should be used when you can use a supernet in vpn proxy
&lt;br&gt;&amp;gt; id for netscreen vpn which covers both of those subnets inside it and both
&lt;br&gt;&amp;gt; subnets 10.101.139.64/30 &amp;nbsp;&amp; &amp;nbsp;10.101.139.100/30 &amp;nbsp;would work via the same one
&lt;br&gt;&amp;gt; vpn tunnel via single tunnel interface.
&lt;br&gt;&lt;br&gt;I have always used route-based VPNs for years. Do I really have to
&lt;br&gt;learn how to use policy-based VPNs as what I want cannot be
&lt;br&gt;accomplished with route-based VPNs?
&lt;br&gt;&lt;br&gt;Greetings
&lt;br&gt;Marc
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;-----------------------------------------------------------------------------
&lt;br&gt;Marc Haber &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;I don't trust Computers. They | Mailadresse im Header
&lt;br&gt;Mannheim, Germany &amp;nbsp;| &amp;nbsp;lose things.&amp;quot; &amp;nbsp; &amp;nbsp;Winona Ryder | Fon: *49 621 72739834
&lt;br&gt;Nordisch by Nature | &amp;nbsp;How to make an American Quilt | Fax: *49 3221 2323190
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19026474&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/VPN-Tunnel-Woes---Again-tp19023612p19026474.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19026136</id>
	<title>Re: VPN Tunnel Woes - Again</title>
	<published>2008-08-17T22:22:14Z</published>
	<updated>2008-08-17T22:22:14Z</updated>
	<author>
		<name>Naveen Dhar</name>
	</author>
	<content type="html">&lt;div dir=&quot;ltr&quot;&gt;Hi Marc,&lt;br&gt;
&lt;br&gt;
If you want multiple subnets to be accessed via VPN tunnel between
NetScreen and Cisco then create Policy Based Tunnel on NetScreen device
and all would work. i have a few of them already working.&lt;br&gt;
&lt;br&gt;
Route based tunnel should be used when you can use a supernet in vpn
proxy id for netscreen vpn which covers both of those subnets inside it
and both subnets &lt;a href=&quot;http://10.101.139.64/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.64/30&lt;/a&gt;&amp;nbsp; &amp;amp;&amp;nbsp; &lt;a href=&quot;http://10.101.139.100/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.100/30&lt;/a&gt;&amp;nbsp; would work via the same one vpn tunnel via single tunnel interface.&lt;br&gt;

&lt;br&gt;
-- &lt;br&gt;
Thanks &amp;amp; Regards,&lt;br&gt;
Naveen Dhar&lt;br&gt;
Lead Consultant &amp;amp; Subject Matter Expert - Network Security&lt;br&gt;
CCNA,CCSA,CCSE,JNCIA,JNCIS&lt;br&gt;
Computer Sciences Corporation Pvt. Ltd.&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Mon, Aug 18, 2008 at 2:39 AM, Marc Haber &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19026136&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mh%2Bqorbit-nn@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;Hi,&lt;br&gt;
&lt;br&gt;
I had this issue in last december and addressed in on this list.&lt;br&gt;
Unfortunately, I failed to properly followup with the replies I&lt;br&gt;
received since I never fully understood what was going on. I apologize.&lt;br&gt;
&lt;br&gt;
I am having trouble - again - with a IPSEC tunnel to another company&lt;br&gt;
running a Cisco VPN Concentrator. I do not do netscreen VPN very much&lt;br&gt;
and am therefore at a loss how to debug.&lt;br&gt;
&lt;br&gt;
This is how things look:&lt;br&gt;
&lt;br&gt;
Network &amp;quot;plan&amp;quot;:&lt;br&gt;
-------------------- &amp;nbsp; ---------------------&lt;br&gt;
| &lt;a href=&quot;http://10.101.139.64/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.64/30&lt;/a&gt; | &amp;nbsp; | &lt;a href=&quot;http://10.101.139.100/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.100/30&lt;/a&gt; |&lt;br&gt;
-------------------- &amp;nbsp; ---------------------&lt;br&gt;
 &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;br&gt;
 &amp;nbsp; &amp;nbsp; ---------------------------&lt;br&gt;
 &amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp;Cisco Concentrator &amp;nbsp; |&lt;br&gt;
 &amp;nbsp; &amp;nbsp; ---------------------------&lt;br&gt;
 &amp;nbsp; &amp;nbsp; &amp;nbsp; | &lt;a href=&quot;http://172.16.251.112&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;172.16.251.112&lt;/a&gt;&lt;br&gt;
 &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;untrust&lt;br&gt;
-------------- &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://172.17.0.1&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;172.17.0.1&lt;/a&gt; &amp;nbsp;-------------&lt;br&gt;
| Router &amp;nbsp; &amp;nbsp; |------------------| Netscreen |&lt;br&gt;
-------------- &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-------------&lt;br&gt;
 &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;br&gt;
 &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;br&gt;
--------------&lt;br&gt;
| &lt;a href=&quot;http://10.1.2.7&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.1.2.7&lt;/a&gt; &amp;nbsp; |&lt;br&gt;
--------------&lt;br&gt;
&lt;br&gt;
I have a currenly existing and working tunnel between &lt;a href=&quot;http://10.1.2.0/28&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.1.2.0/28&lt;/a&gt; and&lt;br&gt;
&lt;a href=&quot;http://10.1.139.64/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.1.139.64/30&lt;/a&gt; via the Netscreen and the Cisco concentrator.&lt;br&gt;
&lt;br&gt;
Netscreen config excerpts:&lt;br&gt;
-&amp;gt; get system&lt;br&gt;
Product Name: NetScreen-NS5GT&lt;br&gt;
Hardware Version: 1010(0)-(00), FPGA checksum: 00000000, VLAN1 IP (&lt;a href=&quot;http://0.0.0.0&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;0.0.0.0&lt;/a&gt;)&lt;br&gt;
Software Version: 5.4.0r3a.0, Type: Firewall+VPN&lt;br&gt;
Feature: AV-K&lt;br&gt;
Compiled by build_master at: Wed Feb 7 19:00:24 PST 2007&lt;br&gt;
Base Mac: 0010.db73.5a50&lt;br&gt;
File Name: screenos_image, Checksum: 51863a99&lt;br&gt;
Box in trust-untrust mode&lt;br&gt;
System in NAT/route mode.&lt;br&gt;
&lt;br&gt;
set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; gateway &amp;quot;myvpn-172-16-251-112&amp;quot; no-replay tunnel idletime 0 proposal &amp;quot;g2-aes256-sha1&amp;quot;&lt;br&gt;
set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; id 22 bind interface tunnel.5&lt;br&gt;
set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; proxy-id local-ip &lt;a href=&quot;http://10.1.2.0/28&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.1.2.0/28&lt;/a&gt; remote-ip &lt;a href=&quot;http://10.101.139.64/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.64/30&lt;/a&gt; &amp;quot;ANY&amp;quot;&lt;br&gt;

set route &lt;a href=&quot;http://10.101.139.64/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.64/30&lt;/a&gt; interface tunnel.5 preference 20&lt;br&gt;
&lt;br&gt;
set interface &amp;quot;tunnel.5&amp;quot; zone &amp;quot;Untrust&amp;quot;&lt;br&gt;
set interface tunnel.5 ip unnumbered interface untrust&lt;br&gt;
&lt;br&gt;
set ike gateway &amp;quot;myvpn-172-16-251-112&amp;quot; address &lt;a href=&quot;http://172.16.251.112&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;172.16.251.112&lt;/a&gt; Main outgoing-interface &amp;quot;untrust&amp;quot; preshare &amp;quot;&amp;lt;snip&amp;gt;&amp;quot; proposal &amp;quot;pre-g2-aes256-sha1&amp;quot;&lt;br&gt;

set ike gateway &amp;quot;myvpn-172-16-251-112&amp;quot; cert peer-ca all&lt;br&gt;
&lt;br&gt;
set policy id 1 from &amp;quot;Untrust&amp;quot; to &amp;quot;Untrust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;ANY&amp;quot; permit log&lt;br&gt;
&lt;br&gt;
This works just fine. I now need to add a second tunnel which has&lt;br&gt;
&lt;a href=&quot;http://10.101.139.100/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.100/30&lt;/a&gt; as the remote side. As soon as I add the canonical&lt;br&gt;
&lt;br&gt;
set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; gateway &amp;quot;myvpn-172-16-251-112&amp;quot; no-replay tunnel idletime 0 proposal &amp;quot;g2-aes256-sha1&amp;quot;&lt;br&gt;
set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; id 22 bind interface tunnel.5&lt;br&gt;
set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; proxy-id local-ip &lt;a href=&quot;http://10.1.2.0/28&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.1.2.0/28&lt;/a&gt; remote-ip &lt;a href=&quot;http://10.101.139.100/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.100/30&lt;/a&gt; &amp;quot;ANY&amp;quot;&lt;br&gt;

set route &lt;a href=&quot;http://10.101.139.100/30&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.100/30&lt;/a&gt; interface tunnel.5 preference 20&lt;br&gt;
&lt;br&gt;
I lose the connectivity of the first tunnel, and the second does not&lt;br&gt;
seem to come up. This is also the case when I replace tunnel.5 with&lt;br&gt;
tunnel.6 in the second tunnel definition.&lt;br&gt;
&lt;br&gt;
Debug info looks like december last year, something along like:&lt;br&gt;
&lt;br&gt;
 &amp;nbsp;untrust:&lt;a href=&quot;http://10.1.2.7/36462-&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.1.2.7/36462-&lt;/a&gt;&amp;gt;&lt;a href=&quot;http://10.101.139.65/1024,1%288/0%29&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.65/1024,1(8/0)&lt;/a&gt;&amp;lt;Root&amp;gt;&lt;br&gt;
 &amp;nbsp;no session found&lt;br&gt;
 &amp;nbsp;flow_first_sanity_check: in &amp;lt;untrust&amp;gt;, out &amp;lt;N/A&amp;gt;&lt;br&gt;
 &amp;nbsp;chose interface untrust as incoming nat if.&lt;br&gt;
 &amp;nbsp;flow_first_routing: in &amp;lt;untrust&amp;gt;, out &amp;lt;N/A&amp;gt;&lt;br&gt;
 &amp;nbsp;search route to (untrust, 10.1.2.7-&amp;gt;&lt;a href=&quot;http://10.101.139.65&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.65&lt;/a&gt;) in vr trust-vr for vsd-0/flag-0/ifp-null&lt;br&gt;
 &amp;nbsp;[ Dest] 7.route 10.101.139.65-&amp;gt;&lt;a href=&quot;http://10.101.139.65&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.65&lt;/a&gt;, to tunnel.5&lt;br&gt;
 &amp;nbsp;routed (x_dst_ip &lt;a href=&quot;http://10.101.139.65&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.65&lt;/a&gt;) from untrust (untrust in 0) to tunnel.5&lt;br&gt;
 &amp;nbsp;policy search from zone 1-&amp;gt; zone 1&lt;br&gt;
&amp;nbsp;policy_flow_search &amp;nbsp;policy search nat_crt from zone 1-&amp;gt; zone 1&lt;br&gt;
 &amp;nbsp;RPC Mapping Table search returned 0 matched service(s) for (vsys Root, ip &lt;a href=&quot;http://10.101.139.65&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.65&lt;/a&gt;, port 47853, proto 1)&lt;br&gt;
 &amp;nbsp;No SW RPC rule match, search HW rule&lt;br&gt;
 &amp;nbsp;Permitted by policy 1&lt;br&gt;
 &amp;nbsp;No src xlate ## 2007-12-05 14:58:40 : NHTB entry search no found: vpn none tif tunnel.5 nexthop &lt;a href=&quot;http://10.101.139.65&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.101.139.65&lt;/a&gt;&lt;br&gt;
 &amp;nbsp;packet dropped, no way(tunnel) out&lt;br&gt;
&lt;br&gt;
(this is not copied verbatim from the dbuf as it has scrolled out)&lt;br&gt;
&lt;br&gt;
Can anybody say what&amp;#39;s going wrong with my tunnels? Any hints will be&lt;br&gt;
appreciated. If there is any information missing, I&amp;#39;ll happily deliver&lt;br&gt;
what you need to properly diagnose things.&lt;br&gt;
&lt;br&gt;
Greetings&lt;br&gt;
Marc&lt;br&gt;
&lt;br&gt;
--&lt;br&gt;
-----------------------------------------------------------------------------&lt;br&gt;
&lt;font color=&quot;#888888&quot;&gt;Marc Haber &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;I don&amp;#39;t trust Computers. They | Mailadresse im Header&lt;br&gt;
Mannheim, Germany &amp;nbsp;| &amp;nbsp;lose things.&amp;quot; &amp;nbsp; &amp;nbsp;Winona Ryder | Fon: *49 621 72739834&lt;br&gt;
Nordisch by Nature | &amp;nbsp;How to make an American Quilt | Fax: *49 3221 2323190&lt;br&gt;
_______________________________________________&lt;br&gt;
nn mailing list&lt;br&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19026136&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;
&lt;/font&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br&gt;
&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19026136&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/VPN-Tunnel-Woes---Again-tp19023612p19026136.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19023612</id>
	<title>VPN Tunnel Woes - Again</title>
	<published>2008-08-17T14:09:38Z</published>
	<updated>2008-08-17T14:09:38Z</updated>
	<author>
		<name>Marc Haber-6</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;I had this issue in last december and addressed in on this list.
&lt;br&gt;Unfortunately, I failed to properly followup with the replies I
&lt;br&gt;received since I never fully understood what was going on. I apologize.
&lt;br&gt;&lt;br&gt;I am having trouble - again - with a IPSEC tunnel to another company
&lt;br&gt;running a Cisco VPN Concentrator. I do not do netscreen VPN very much
&lt;br&gt;and am therefore at a loss how to debug.
&lt;br&gt;&lt;br&gt;This is how things look:
&lt;br&gt;&lt;br&gt;Network &amp;quot;plan&amp;quot;:
&lt;br&gt;-------------------- &amp;nbsp; ---------------------
&lt;br&gt;| 10.101.139.64/30 | &amp;nbsp; | 10.101.139.100/30 |
&lt;br&gt;-------------------- &amp;nbsp; ---------------------
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;---------------------------
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp;Cisco Concentrator &amp;nbsp; |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;---------------------------
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;| 172.16.251.112
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;untrust
&lt;br&gt;-------------- &amp;nbsp; &amp;nbsp; &amp;nbsp;172.17.0.1 &amp;nbsp;-------------
&lt;br&gt;| Router &amp;nbsp; &amp;nbsp; |------------------| Netscreen |
&lt;br&gt;-------------- &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-------------
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|
&lt;br&gt;--------------
&lt;br&gt;| 10.1.2.7 &amp;nbsp; |
&lt;br&gt;--------------
&lt;br&gt;&lt;br&gt;I have a currenly existing and working tunnel between 10.1.2.0/28 and
&lt;br&gt;10.1.139.64/30 via the Netscreen and the Cisco concentrator.
&lt;br&gt;&lt;br&gt;Netscreen config excerpts:
&lt;br&gt;-&amp;gt; get system
&lt;br&gt;Product Name: NetScreen-NS5GT
&lt;br&gt;Hardware Version: 1010(0)-(00), FPGA checksum: 00000000, VLAN1 IP (0.0.0.0)
&lt;br&gt;Software Version: 5.4.0r3a.0, Type: Firewall+VPN
&lt;br&gt;Feature: AV-K
&lt;br&gt;Compiled by build_master at: Wed Feb 7 19:00:24 PST 2007
&lt;br&gt;Base Mac: 0010.db73.5a50
&lt;br&gt;File Name: screenos_image, Checksum: 51863a99
&lt;br&gt;Box in trust-untrust mode
&lt;br&gt;System in NAT/route mode.
&lt;br&gt;&lt;br&gt;set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; gateway &amp;quot;myvpn-172-16-251-112&amp;quot; no-replay tunnel idletime 0 proposal &amp;quot;g2-aes256-sha1&amp;quot;
&lt;br&gt;set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; id 22 bind interface tunnel.5
&lt;br&gt;set vpn &amp;quot;myvpn-10-101-139-64-off&amp;quot; proxy-id local-ip 10.1.2.0/28 remote-ip 10.101.139.64/30 &amp;quot;ANY&amp;quot;
&lt;br&gt;set route 10.101.139.64/30 interface tunnel.5 preference 20
&lt;br&gt;&lt;br&gt;set interface &amp;quot;tunnel.5&amp;quot; zone &amp;quot;Untrust&amp;quot;
&lt;br&gt;set interface tunnel.5 ip unnumbered interface untrust
&lt;br&gt;&lt;br&gt;set ike gateway &amp;quot;myvpn-172-16-251-112&amp;quot; address 172.16.251.112 Main outgoing-interface &amp;quot;untrust&amp;quot; preshare &amp;quot;&amp;lt;snip&amp;gt;&amp;quot; proposal &amp;quot;pre-g2-aes256-sha1&amp;quot;
&lt;br&gt;set ike gateway &amp;quot;myvpn-172-16-251-112&amp;quot; cert peer-ca all
&lt;br&gt;&lt;br&gt;set policy id 1 from &amp;quot;Untrust&amp;quot; to &amp;quot;Untrust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;ANY&amp;quot; permit log
&lt;br&gt;&lt;br&gt;This works just fine. I now need to add a second tunnel which has
&lt;br&gt;10.101.139.100/30 as the remote side. As soon as I add the canonical
&lt;br&gt;&lt;br&gt;set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; gateway &amp;quot;myvpn-172-16-251-112&amp;quot; no-replay tunnel idletime 0 proposal &amp;quot;g2-aes256-sha1&amp;quot;
&lt;br&gt;set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; id 22 bind interface tunnel.5
&lt;br&gt;set vpn &amp;quot;myvpn-10-101-139-100-off&amp;quot; proxy-id local-ip 10.1.2.0/28 remote-ip 10.101.139.100/30 &amp;quot;ANY&amp;quot;
&lt;br&gt;set route 10.101.139.100/30 interface tunnel.5 preference 20
&lt;br&gt;&lt;br&gt;I lose the connectivity of the first tunnel, and the second does not
&lt;br&gt;seem to come up. This is also the case when I replace tunnel.5 with
&lt;br&gt;tunnel.6 in the second tunnel definition.
&lt;br&gt;&lt;br&gt;Debug info looks like december last year, something along like:
&lt;br&gt;&lt;br&gt;&amp;nbsp; untrust:10.1.2.7