Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: Replacing a SSG5 with SRX100H2 in branch office

$
0
0

Sorry about the PFS, you are correct I misread the proposal listings there.

 

As far as the proxy-id are concerned, these are explicitly configured on the SSG140 side so would need to remain on the SRX or be removed from both.

 

set vpn "Dallas_VPN" proxy-id local-ip 172.16.10.0/24 remote-ip 172.16.72.0/24 "ANY" 

The other configuration I notice on the SSG140 is enabling tunnel monitor with the default settings.  I have had issues with this combination if the remote side is not also an SSG firewall.  I would either remove the setting or change this to use ping to a specific remote address from an interface on the SSG140 that is in the local proxy-id subnet.

 

Also if the status of the IKE and SA could be grabbed on both sides during the issue these might be helpful.  I see the IKE in some of the above but not the SA.

 

SSG

get ike cookie

get sa

SRX

show security security-association ike

show security security-association ipsec

 


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>