Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Navigation
Guide That Contains This Content
[+] Expand All
[-] Collapse All

Dynamic VPN Overview

Virtual private network (VPN) tunnels enable users to securely access assets such as e-mail servers and application servers that reside behind a firewall. End-to-site VPN tunnels are particularly helpful to remote users such as telecommuters because a single tunnel enables access to all of the resources on a network—the users do not need to configure individual access settings to each application and server. See Figure 1.

Figure 1: Using a VPN Tunnel to Enable Remote Access to a Corporate Network

Using a VPN Tunnel
to Enable Remote Access to a Corporate Network

The dynamic VPN feature (also known as remote access VPN or IPsec VPN client) further simplifies remote access by enabling users to establish Internet Protocol Security (IPsec) VPN tunnels without having to manually configure VPN settings on their PCs or laptops. Instead, authenticated users can simply download the VPN client software to their computers. This Layer 3 remote access client uses client-side configuration settings that it receives from the server to create and manage a secure end-to-site VPN tunnel to the server.

The dynamic VPN server must be a standalone branch SRX Series device. The dynamic VPN feature is not supported on high-end SRX Series devices or on branch SRX Series devices in a chassis cluster.

Note: If more than two simultaneous user connections are required, a dynamic VPN license must be installed on the SRX Series device. The dynamic VPN feature is disabled by default on the device. To enable dynamic VPN, you must configure the feature using the dynamic-vpn configuration statement at the [edit security] hierarchy level. See the Installation and Upgrade Guide for Security Devices for information about installing and managing licenses.

Modified: 2016-07-07