set interfaces st0 unit 6 family inet address 10.79.185.
94/30
set security ike proposal IKE-PROPOSAL-NGDTLNTDC2 authentication-method pre-shared-
keys set security ike proposal IKE-PROPOSAL-NGDTLNTDC2 dh-group group5 set security ike proposal IKE-PROPOSAL-NGDTLNTDC2 authentication-algorithm sha1 set security ike proposal IKE-PROPOSAL-NGDTLNTDC2 encryption-algorithm aes-256-cbc set security ike proposal IKE-PROPOSAL-NGDTLNTDC2 lifetime-seconds 28800
set security ike policy IKE-POLICY-NGDTLNTDC2 mode main
set security ike policy IKE-POLICY-NGDTLNTDC2 proposals IKE-PROPOSAL-NGDTLNTDC2 set security ike policy IKE-POLICY-NGDTLNTDC2 pre-shared-key ascii-text 12345
set security ike gateway NGDTLNTDC2-GW-Nagad ike-policy IKE-POLICY-NGDTLNTDC2
set security ike gateway NGDTLNTDC2-GW-Nagad address 10.2.52.90 set security ike gateway NGDTLNTDC2-GW-Nagad local-identity inet 10.2.52.38 set security ike gateway NGDTLNTDC2-GW-Nagad external-interface ge-0/0/0.0
set security ipsec proposal IPSEC-PROPTLNTDC2-NGD protocol esp
set security ipsec proposal IPSEC-PROPTLNTDC2-NGD authentication-algorithm hmac- sha1-96 set security ipsec proposal IPSEC-PROPTLNTDC2-NGD encryption-algorithm aes-256-cbc set security ipsec proposal IPSEC-PROPTLNTDC2-NGD lifetime-seconds 86400
set security ipsec policy IPSEC-PLCY-TLNTDC2NGD proposals IPSEC-PROPTLNTDC2-NGD
set security ipsec vpn VPN-NGD-TLNTDC2 bind-interface st0.6
set security ipsec vpn VPN-NGD-TLNTDC2 ike gateway NGDTLNTDC2-GW-Nagad set security ipsec vpn VPN-NGD-TLNTDC2 ike proxy-identity service junos-gre set security ipsec vpn VPN-NGD-TLNTDC2 ike ipsec-policy IPSEC-PLCY-TLNTDC2NGD set security ipsec vpn VPN-NGD-TLNTDC2 establish-tunnels immediately
set security zones security-zone untrust interfaces st0.6 host-inbound-traffic
system-services all set security zones security-zone untrust interfaces st0.6 host-inbound-traffic protocols all set security zones security-zone VPN-NGD-TLNTDC2 host-inbound-traffic system- services all set security zones security-zone VPN-NGD-TLNTDC2 host-inbound-traffic protocols all
set routing-options static route 10.79.185.93/32 next-hop st0.6
set security zones security-zone signaling host-inbound-traffic system-services ike
set security flow tcp-mss ipsec-vpn mss 1350 set security zones security-zone untrust host-inbound-traffic system-services ike set security zones security-zone untrust host-inbound-traffic protocols all