Quantcast
Channel: All SRX Services Gateway posts
Viewing all 17645 articles
Browse latest View live

Re: Can SRX series work with Shrew Soft VPN client?

$
0
0

SRX comes with two DynVPN user licenses. You have to purchase more to support more users. Why dont you enable traceoptiosn and see if it gets you some information?


[SRX220] Is fan speed control possible?

$
0
0

Hello all,

Recently I have replaced both fans on SRX220 to a slightly more powerful ones (and more quiet) and now I would like to lower the fan speed when there is no need for such efficency.

Putting aside any safety and support aspects:

Is it possible to change the fan speed under 'normal' temperature threshold on SRX220? Any hidden CLI commands, anything?

 

 

 

Re: [SRX220] Is fan speed control possible?

With vSRX , HTTP client sending TCP RSTs after initial SYN and SYN-ACK.

$
0
0

We are observing HTTP client sending RSTs after initial TCP SYN from client and SYN ACK from server , when vSRX is deployed between webserver in private subnet (Trust zone) and  HTTP client in public subnet (UnTrust zone). When vSRX is removed, same server and client face no issues.

 

Any specific reasons, why HTTP client is sending the RSTs? Please note few points, just FYI.

 

  • Destination NAT is configured for public IP Address and is working fine.
  • No routing issues since we can observe the TCP SYN from client to server and SYN ACK from server to client at client or server.
  • No other configurations (Screens, IDP, UTM etc), except NAT and static route at vSRX to simplify things in debugging.
  • Surprisingly, everything is normal if VSRX is not there in between.

 

Please suggest any reasons for this issue.

 

Thanks,

Shirish.

Re: With vSRX , HTTP client sending TCP RSTs after initial SYN and SYN-ACK.

$
0
0

Can you do a pcap on client machine and see if the client is sending RST or its the VSRX sending RST (while proxying)? You may take pcap simultaneously on CLient and vSRX and confirm the behavior

Re: Using SNMP to monitor SPU; what are MIBS

Re: RTPERF_CPU_THRESHOLD_EXCEEDED when 40 Mbps passed to st0.1

$
0
0

Can you collect the below counters in scenario 1 and 2 .

 

 

show security flow statistics

 

use "clear security flow statistics" before start of test.

 

 

Re: With vSRX , HTTP client sending TCP RSTs after initial SYN and SYN-ACK.

$
0
0

vSRX is not sending any RSTs, its the HTTP client sending the RSTs.

 


Re: With vSRX , HTTP client sending TCP RSTs after initial SYN and SYN-ACK.

$
0
0

BTW, Could this be the cause of the issue ?

 

1.) HTTP client at 172.31.81.76  sends TCP SYN for HTTP connection to SRX Untrust interface say  172.31.94.254.

    So at HTTP Client , Source IP = 172.31.81.76

                                     Destination IP = 172.31.94.254.

2.) vSRX successfully performs the destination NAT on (Dest IP for Server IP) and forwards the request/SYN to

     server at IP 172.31.51.86.So at HTTP server,

      Source IP = 172.31.81.76 and

      Destination IP = 172.31.51.86

 

3.) HTTP Server replies the TCP ACK with source IP = 172.31.51.86 and dest IP = 172.31.81.76.

 

4.) HTTP client receives the SYN ACK with source IP = 172.31.51.86 and dest IP = 172.31.81.76 , BUT the source

     IP now is not 172.31.94.254 where client made its initial connection. There is no socket thus open for this IP and it rejects

     by sending RST.

 

    Could this be the reason ?

 

Re: With vSRX , HTTP client sending TCP RSTs after initial SYN and SYN-ACK.

$
0
0

i dont think this will happen, destination NAT rule on SRX will take care of the reverse NAT.

Re: Lots of tunnels ok but ONE route-based VPN tunnel to Cisco ASA passes data but will drop every few minutes

$
0
0

rsuraj wrote:

We may see what packet/notification is coming during the issue using below command.

 

"monitor traffic interface ge-0/0/0.0 no-resolve matching udp detail"  ===replace ge-0/0/0.0 with your VPN external interface


The monitor command does not seem to show any info on this particular tunnel even after watching the traffic through the events.

Re: Lots of tunnels ok but ONE route-based VPN tunnel to Cisco ASA passes data but will drop every few minutes

$
0
0

rsuraj wrote:

We may see what packet/notification is coming during the issue using below command.

 

"monitor traffic interface ge-0/0/0.0 no-resolve matching udp detail"  ===replace ge-0/0/0.0 with your VPN external interface


I spoke too soon.  Was able to capture a short sequence

 

10:35:36.332380 In IP (tos 0x0, ttl 249, id 24912, offset 0, flags [none], proto: UDP (17), length: 184) 189.XXX-XXX-XXX.500 > 198.XXX-XXX-XXX.500: isakmp 1.0 msgid b5c766ba: phase 2/others ? oakley-quick[E]: [|hash]
10:35:36.351053 Out IP (tos 0x0, ttl 64, id 24605, offset 0, flags [none], proto: UDP (17), length: 184) 198.XXX-XXX-XXX.500 > 189.XXX-XXX-XXX.500: isakmp 1.0 msgid b5c766ba: phase 2/others ? oakley-quick[E]: [|hash]
10:35:36.383683 In IP (tos 0x0, ttl 249, id 21479, offset 0, flags [none], proto: UDP (17), length: 104) 189.XXX-XXX-XXX.500 > 198.XXX-XXX-XXX.500: isakmp 1.0 msgid b5c766ba: phase 2/others ? oakley-quick[E]: [|hash]
10:35:36.393107 Out IP (tos 0x0, ttl 64, id 24606, offset 0, flags [none], proto: UDP (17), length: 96) 198.XXX-XXX-XXX.500 > 189.XXX-XXX-XXX.500: isakmp 1.0 msgid a644afac: phase 2/others ? inf[E]: [|hash]
10:35:36.825417 In IP (tos 0x0, ttl 122, id 4624, offset 0, flags [none], proto: UDP (17), length: 124) 65.36.94.126.62885 > 198.XXX-XXX-XXX.4500: UDP, length 96
10:35:36.828233 Out IP (tos 0x0, ttl 64, id 24608, offset 0, flags [none], proto: UDP (17), length: 124) 198.XXX-XXX-XXX.4500 > 65.36.94.126.62885: UDP, length 96
10:35:37.477698 Out IP (tos 0x0, ttl 64, id 24609, offset 0, flags [none], proto: UDP (17), length: 29) 198.XXX-XXX-XXX.4500 > 76.185.93.13.60106: UDP, length 1
10:35:38.475174 In IP (tos 0x0, ttl 249, id 23593, offset 0, flags [none], proto: UDP (17), length: 184) 189.XXX-XXX-XXX.500 > 198.XXX-XXX-XXX.500: isakmp 1.0 msgid 53568c70: phase 2/others ? oakley-quick[E]: [|hash]
10:35:38.496892 Out IP (tos 0x0, ttl 64, id 24611, offset 0, flags [none], proto: UDP (17), length: 184) 198.XXX-XXX-XXX.500 > 189.XXX-XXX-XXX.500: isakmp 1.0 msgid 53568c70: phase 2/others ? oakley-quick[E]: [|hash]
10:35:38.529892 In IP (tos 0x0, ttl 249, id 24038, offset 0, flags [none], proto: UDP (17), length: 104) 189.XXX-XXX-XXX.500 > 198.XXX-XXX-XXX.500: isakmp 1.0 msgid 53568c70: phase 2/others ? oakley-quick[E]: [|hash]
10:35:38.540305 Out IP (tos 0x0, ttl 64, id 24612, offset 0, flags [none], proto: UDP (17), length: 96) 198.XXX-XXX-XXX.500 > 189.XXX-XXX-XXX.500: isakmp 1.0 msgid ca32943e: phase 2/others ? inf[E]: [|hash]

 

I cannot get any meaning from the above.  Anyone else?

QOS on ST0 interfaces?

$
0
0

how does one go about getting the QOS over ST interfaces? 

 

it is not an option right now in the CLI 

 

we have a RW rule on our MPLS interface the ST interface uses a seperate cable/dsl connection for a VPN backup

 

the issue is when on the VPN the QOS doesn't really work and the phones and critical bissness apps have issues 

 

do i need to move the RW to the vlan ? to the phsical insterface the tunnle is on >? (vlan seem like it could work but not the phsyical)

 

what is the best practice on this? I have googled around but there is not much info and even in this forum the newest thread was from 2012 

Re: QOS on ST0 interfaces?

Re: QOS on ST0 interfaces?

$
0
0
CoS/QoS on ST0 is supported from 15.1X49-D60 onwards.


Class of Service

* CoS support for the st0 interface for SRX300, SRX320, SRX340, SRX345, SRX550M devices and vSRX2.0 instances—Starting with Junos OS 15.1X49-D60, class of service (CoS) features such as classifier, policer, queuing, scheduling, shaping, rewriting markers, and virtual channels can now be configured on the secure tunnel interface (st0) for point-to-point VPNs. The st0 tunnel interface is an internal interface that can be used by route-based VPNs to route cleartext traffics to an IPsec VPN tunnel.

Ref: https://www.juniper.net/techpubs/en_US/junos15.1x49-d60/information-products/topic-collections/release-notes/15.1x49-d60/topic-108022.html#jd0e161

Re: Lots of tunnels ok but ONE route-based VPN tunnel to Cisco ASA passes data but will drop every few minutes

$
0
0

Hello,

 

Just to confirm:

 

Is VPN created on Cisco ASA with correct crypto map?

 

This can be confirmed using 'show crypto ipsec sa detail' command for specific peer.

 

I have seen cases where a configured crypto map (and sequence number) is not utilized due to positioning or overlapping subnet or because default map kicks in.

 

Regards,

 

Rushi

Re: Trouble with firewall filters

$
0
0

Hi 

defined the port to be allowed. Such as this:

 from all the 3 prefix list , Protocol udp and destination-port 161 

But I see this error in mesage log

snmpd[1464]: SNMPD_AUTH_FAILURE: nsa_log_community: unauthorized SNMP community from 5.210.62.144 to x.x.x.x (public).

will you help me.

Re: Trouble with firewall filters

$
0
0

i checked SRX interface with nmap and it shows open udp/161

 

Re: Trouble with firewall filters

Re: Site-to-Site VPN with Inline Transparent Web Filter

$
0
0

So on the datacenter side:

-Create a virtual-router "VPN"

-Add ge-0/0/5 with ip 10.28.0.2 (some unused port on the SRX) and st0.0 to the virtual router

-Make the 0.0.0.0/0 route on the VPN virtual router 10.28.0.1

-Connect ge-0/0/5 to the 4200

-Create a VLAN on the 4200 "VPN Traffic" 10.28.0.1/29 as the gateway. 

-Make port on 4200 an access port for VPN Traffic VLAN

-Add "VPN Traffic" VLAN to my 0.0.0.1 OSPF Area (10.29.0.0/29 is my 0.0.0.0 backbone)

-Voila?

 

That should in theory work correct? I'm guessing there wouldn't be an issue trunking the VLAN instead of using a physical port if I so choose.

 

 

Viewing all 17645 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>