Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

SRX 210HE to SSG550 VPN Tunnel

$
0
0

Hi All,

 

One of our site firewall is replaced from netscreen to SRX210. The tunnel is up and both LAN side users can ping each others. Recently, SRX210 users request to reach other side DMZ server. I have added policy on both firewall (SRX, trust to untrust) (SSG, Untrust to DMZ), however, the traffic still go through from untrust to trust network. 

 

In the SSG monitor status, the bottom tunnel still inactive.

LXX_VPN000002e3389/3886x.xx.xx.15xAutoIKEActiveUp
LXX_VPN000002e41257/-16x.xx.xx.15xAutoIKEInactiveInactive

 

SSG Firewall Policy

Traffic log for policy :
IDSourceDestinationServiceAction
389Untrust/LXX_OfficeTrust/XXX_OfficeANYTunnel

 

Date/TimeSource Address/PortDestination Address/PortTranslated Source Address/PortTranslated Destination Address/PortServiceDurationBytes SentBytes ReceivedClose Reason
2016-08-25 15:03:04192.168.193.1:133172.16.0.20:581370.0.0.0:00.0.0.0:0ICMP0 sec.064Traffic Denied
2016-08-25 15:03:03192.168.193.1:132172.16.0.20:581370.0.0.0:00.0.0.0:0ICMP0 sec.064Traffic Denied
2016-08-25 15:03:02192.168.193.1:131172.16.0.20:581370.0.0.0:00.0.0.0:0ICMP0 sec.064Traffic Denied
2016-08-25 15:03:01192.168.193.1:130172.16.0.20:581370.0.0.0:00.0.0.0:0ICMP0 sec.064Traffic Denied

 

Any idea how to fix it?

 

Many Thanks,

Kay


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>