Skip to content
Notifications
Clear all

Step-by-step: Configuring a secure VPN for remote contractors.

1 Posts
1 Users
0 Reactions
3 Views
(@brianl)
Estimable Member
Joined: 1 week ago
Posts: 113
Topic starter   [#15906]

Hello everyone. I’ve been reading through the discussions here for a few weeks as we evaluate replacing our current edge solution with a Juniper SRX series firewall. The depth of knowledge in this forum has been incredibly helpful already, so thank you.

My current project, and the reason for this post, involves setting up a secure VPN for a growing team of remote contractors. These contractors are in manufacturing and logistics roles, and they need reliable, audited access to our on-premise ERP system (NetSuite) and several internal inventory management platforms. The requirements are typical but stringent: role-based access, strong encryption, reliable uptime, and detailed connection logging for compliance. I’ve seen several mentions of IPsec and IKEv2 on the SRX, but I want to ensure I understand the entire workflow from configuration to ongoing management.

I am planning a phased approach, starting with a pilot group of 10 contractors. My current plan, based on the Juniper documentation and a few older threads here, is to use IKEv2 with certificate-based authentication for the user VPN, terminating on an SRX 345. I intend to place these users in a dedicated security zone with very restrictive policies, only allowing traffic to specific subnets hosting the required applications.

Where I’m hoping for some community insight is on the specific pitfalls in this process. For instance, are there particular configuration nuances in the `set security ike` or `set security ipsec` hierarchies that are easy to miss but critical for stability? I am especially interested in any experiences related to integrating with an internal CA for certificate deployment, as that is a new area for our team. Also, how manageable is the logging for these connections when you need to produce reports on who accessed what and when? Does the built-in reporting suffice, or does this typically require a log collector and external analysis tool?

Finally, from an operational perspective, are there any noticeable performance considerations or session limits I should be aware of when scaling this from 10 to potentially 50 or more concurrent VPN users? Any feedback on real-world stability, particularly during firmware upgrades, would also be greatly appreciated. I want to make sure the solution is not only secure but also maintainable for a small IT team that is more familiar with ERP systems than networking gear.



   
Quote