Description

Is it possible to create IPSEC VPN tunnels on an SRX cluster in MIST or do we need the Juniper Security Director Cloud to be able to do that?

Symptoms

Secure Edge Connector instances with SASE providers, Juniper Security Director, Zscaler alike vendors or custom defined options within Mist Integration.

Solution

You can build up the tunnel template pushed by Mist or sync with Security Director or Zscaler alike vendors as shown on documentation.
As shown below you will need to go to Organization > WAN Edge Templates > Secure Edge Connections 

For Local ID value you can define <custom-name>@juniper.net, we setup h1 and h2 respectively in order to identify each Hub.

Custom values: PSK, Hostname {SRX IP, IKE & IPSEC proposals}.

We can left Probe IP space in blank or in case you want to setup RPM probes for Peer/ISP link we can fill them.

Note: For further info on Probe please refer to the following KB: 
[J/SRX] Example – Configuring a primary and backup VPN with route failover using ip-monitoring



Custom MistUI VPN

For Security Director or Zscaler refer to the top of the doc, else go to the bottom you will find MistUI setup:
https://www.mist.com/documentation/secure-edge-connector/

Advise the customer if this is a new implementation to reach Juniper/Mist SE from Account Team for accuracy.

Modification History

1/2/2024 - Preview edit {No info added nor removed}

10/5/2024 : KB Published Externally