My company purcahesd MAG6611 and ask me to configure it, i am working well with Juniper SRX Series but i have no idea how to start emplement MAG6611, can any body guide me how to start emplement it step by step?
since you are posting in the "Connect Secure" forum I assume you will be using SSL VPN. If you are looking to deploy this as a NAC solution the "Policy Secure" is the forum to use. The type of appliance you have is dictated by your license and the installed softeware.
I would recommend the following basic steps.
1-Get up to date. Register and link an account to your contract on the support site and upgrade to the current version on the appliance. This might take a support ticket to get older versions of the code depending on where your appliance currently is. Note there are specific version support for upgrades when back multiple versions as seen in the release notes.
2-Decide on dual DMZ or single DMZ design. Most go with a single ethernet interface in the DMZ. This will both terminate the outside session and generate the internal network session from the same port. There is also an option to use two ports on the device where one is in your external DMZ for the inbound connection and the inside port is used for reaching the resources. Once you pick the single or dual interfaces you can assign the necessary ip addresses and design your needed firewall port forwarding and internal access rules.
You also need to choose if the appliance will provide a pool of ip addresses for the client connections or if you will use dhcp forwarding to your internal dhcp server.
Also note if you need internal DNS for connected clients and be ready for those inputs and selections to override the connecting client DNS servers.
Now you can configure the interfaces and connect to the network for basic setups. And setup firewall rules.
3-Setup remote access:
You will need to configure authentication to your internal AD or use local auth on the applicance.
Once auth is setup, you then have to have resources and group mappings that can use the resources. This can get complicated as it is very flexible in restrictions. The admin guide has all the gory details. Read the first two chapters to get the overview of all the options. For simple layer3 connection setups go right to chapter 30 - VPN Tunneling.