cancel
Showing results for 
Search instead for 
Did you mean: 

Junos Pulse and client certificate authentication VPN

Highlighted
Not applicable

Junos Pulse and client certificate authentication VPN

I have got the client certificate part running, when i access the url from a browser, it asks me for my client certificate, and i am able to sign in...

I created a profile with the iphone configuration utility, including the certificate, the certificate CA and the vpn connection settings for the ssl vpn box.

when trying to connect junos pulse (on ipad) it gives me a connection error.

I am able to connect to the url using the browser on the ipad, and i am signed in based on the certificate i used in the icu profile.

Any ideas ?

4 REPLIES 4
Highlighted
Frequent Contributor

Re: Junos Pulse and client certificate authentication VPN

I've had a ticket opened up on this very issue for a few weeks now. It seems as if JTAC has no idea.

Not to mention I get one communication per day and it's usually try this and see if it works then I respond and it takes another day until JTAC contacts us again. And yes, I have emailed and called.

Curious, what version of SA / MAG and what version of Pulse?

Highlighted
Regular Contributor

Re: Junos Pulse and client certificate authentication VPN

Couple of queries on the setup

What is the version SA is running?

What is the pulse client version?

On the Ipad under pulse do you see the certificate ?

to verify Launch pulse edit the configuration click on the certificate

Highlighted
Frequent Contributor

Re: Junos Pulse and client certificate authentication VPN

In the role you map the ipad's communication to, do you have Junos Pulse or Network Connect defined in the role options? As odd as it may sound, the Junos Pulse mobile clients need to connect to a role defining Network Connect.

Highlighted
Respected Contributor

Re: Junos Pulse and client certificate authentication VPN

What does your user access log show at time of failure? Policy trace?

Please note that in order to use the Junos Pulse client on iOS devices, Network Connect _must_ be configured for the role; there is no option for web-only with Pulse on iOS. If you only want to provide web access, Safari should be used.