Hi
- When you have one side dynamic vpn and the other is static you need to use "Aggressive Mode" instead of "Main mode" at both sides .
- As the SSG device has a Dynamic IP , we would be using FQDN (Fully qualified domain name)
- Take a look at this link which might be helpful:
http://gsraut.com.np/juniper/site-to-site-ipsec-vpn-in-juniper-ssg-with-one-side-dynamic-ip-part-1/
https://kb.juniper.net/kb/documents/public/resolution_path/J_FW_VPN_Config_or_Trblsh.htm
- When you have one side dynamic vpn and the other is static you need to use "Aggressive Mode" instead of "Main mode" at both sides .
- As the SSG device has a Dynamic IP , we would be using FQDN (Fully qualified domain name)
- Take a look at this link which might be helpful:
http://gsraut.com.np/juniper/site-to-site-ipsec-vpn-in-juniper-ssg-with-one-side-dynamic-ip-part-1/
https://kb.juniper.net/kb/documents/public/resolution_path/J_FW_VPN_Config_or_Trblsh.htm