Description

This article describes how to set up the Network Control Protocol (NCP) Exclusive Remote Access Client for connecting to SRX devices, with an example.

Note: In this example, a Pre-Shared Key (PSK) in Aggressive mode has been used. Depending on the VPN setup required, various Internet Key Exchange (IKE) and IP Security (IPsec) parameters can be selected.

 

Solution

To set up the NCP Exclusive Remote Access Client, perform the following steps:

  1. Click Configuration to set up a new connection profile:

  1. Select Profiles from the drop-down list:

  1. Click Add to set up the new profile:

  1. Enter a name for the new connection profile:

  1. Select a Communication Medium:

  1. Enter the IP address of the VPN Gateway:

  1. Enter the VPN User ID and Password for XAUTH:

  1. Select the IKE ID Type and enter the IKE ID:

  1. Verify the profile configuration and click OK:

  1. Select the IPsec option from the left menu and click Policy Editor under IKE Policy to set up a new IKE policy:

  1. Enter the IKE Policy name and select the IKE parameters:

  1. Click the Policy Editor button under IPSec Policy to create a new IPsec policy:

  1. Enter the IPsec Policy name and select the IPsec parameters:

  1. Select the new IKE and IPsec policies and set the remaining IKE and IPsec parameters:

  1. Click OK to save the new connection profile:

  1. Select the new connection profile from the Connection Profile drop-down menu and click Connect to initiate the VPN connection:

 

To know how an SRX device can be configured to support an NCP Client connection where a Pre-Shared Key is used for IKE authentication, refer to KB32418 - [SRX] Example - Configuring Dynamic VPN on SRX while using NCP client (CLI instructions) [juniper.net] .