Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: Why is the SRX using NAT-T for the IPSEC?

$
0
0

Thanks!

 

This seems to work and not make a mess of everything else Smiley Happy

set security nat source rule-set SNAT_use_interface rule snat_exclude_ipsec match source-address <Local-Public-IP-external-int>/32
set security nat source rule-set SNAT_use_interface rule snat_exclude_ipsec match destination-address <remote-GW-public-IP>/32
set security nat source rule-set SNAT_use_interface rule snat_exclude_ipsec match application junos-ike
set security nat source rule-set SNAT_use_interface rule snat_exclude_ipsec then source-nat off

 

//Robert


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>