For Dynamic VPN clients to be able to connect, two access profiles need to be configured; one under the 'security dynamic-vpn' stanza and another under 'security ike gateway'. If two different access profiles are configured, for example one for local authentication and the other for RADIUS authentication, then some confusion may arise with the user about when to use which credentials. This may lead to the 'Authentication failure: Incorrect credentials' error message, when the user logs on to Dynamic VPN. For this reason, it is strongly recommended to use the same access profile for both authentications.
Symptoms:
When setting up the Dynamic VPN connection for the first time, the user needs to login twice. The double login is only needed the first time that a Dynamic VPN connection is made, after installing the VPN client. From the second connection onwards, the user will only be prompted for the second authentication. The reason for this is that the first time that a VPN connection is made, the VPN client configuration parameters, including a unique token, will be downloaded from the SRX device. From the second connection onwards the token will be used instead of the first authentication. This means that the user is then only requested to provide credentials once, using the credentials from the access profile configured under security ike gateway . To avoid any confusion about which credentials to use and when to use them, it is strongly recommended to use the same access profile (using Radius or local authentication) in both locations of the configuration. Here is a summary about when and which credentials to use. The access profile configured under security dynamic-vpn is used for:
For information on how to configure Dynamic VPN, refer to KB14318 - SRX Getting Started - Configure Dynamic VPN (VPN Client) [juniper.net] .