Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: Site to site VPN routing problem

$
0
0

Hi,

 

The problem description is not very clear.

If you want to route all the traffic from the remote office to the Main Office, please change the following route on the Branch Side :-

 

 

set routing-options static route 193.168.135.0/25 next-hop st0.10

TO

set routing-options static route 0/0 next-hop st0.10

set routing-options static route 193.168.135.253/32 next-hop <Gateway_IP>

 

However, when the VPN tunnel goes down, this route would still be present in the routing table of the Branch SRX and your traffic would stop working.

 

You can use vpn-monitoring for this tunnel so that the st interface is brought down when the tunnel goes down and your other default route takes over.

 

The Second route makes sure that the peer gateway is reachable through the default gateway at all times even when the tunnel is down for re-negotiation.

 

Regards,

Sahil Sharma

---------------------------------------------------

Please mark my solution as accepted if it helped, Kudos are appreciated as well.


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>