Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: Proxy-ID

$
0
0

Hello,

 

Proxy-ID and Traffic selector both of them do identical function:- Define set of traffic that can go over tunnel.

 

With proxy-ID, a single VPN (bound to a tunnel interface) can have a single Local Subnet & single Remote Subnet.

 

If there are multiple subnets on each side of a route based VPN, since single tunnel interface can have single set of remote and local subnet, the solution used to become complex involving multiple tunnel interface and/or routing-instances with FBF.

 

But with introduction of traffic selector in a route based VPN, this complexity is gone. You create a single VPN (bound to a tunnel interface) and configure permitted subnets under traffic selector.

 

For more information, you can refer links below:

 

https://kb.juniper.net/InfoCenter/index?page=content&id=KB28820

 

https://www.juniper.net/documentation/en_US/junos/topics/concept/ipsec-vpn-traffic-selector-understanding.html

 

Regards,

 

Rushi

 

 


Viewing all articles
Browse latest Browse all 17645

Latest Images

Trending Articles



Latest Images