Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
EdwinSoh
New Contributor

Site to site with juniper ssg

Hi, I' m supposed to connect to a juniper ssg through a site to site VPN tunnel. For phase 2 proposal, it' s given as g2-esp-aes128-sha. I could not find anywhere in the web based UI to set ESP protocol. Do I need to set it in CLI, and if so, could someone let me know the command?
Edwinsoh
Edwinsoh
3 REPLIES 3
rwpatterson
Valued Contributor III

ORIGINAL: EdwinSoh For phase 2 proposal, it' s given as g2-esp-aes128-sha.
Perhaps it means DH Group2 (g2), AES128, SHA1? For what you' re doing, ESP is phase 2, more or less.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
EdwinSoh
New Contributor

Thanks for the info
Edwinsoh
Edwinsoh
emnoc
Esteemed Contributor III

You can set this up in the cli quite easy and then define the proposal under your vpn gateway e.g set ike p2-proposal " myvpn1" group2 esp aes128 sha second 3600 than set vpn " fortigate-screen" gateway " whatever-gw-name-here" replay tunnel idletime 0 proposal " myvpn1" As with fgt, make sure to include the necessary fwpolicies

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors