Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: SRX100H2 SRX100H2 Dynamic VPN - Configuration Order

$
0
0

Hello,

Speaking of experience :

1/ the SRX behind NAT _MUST_ have "establish-tunnels immediately" configured.

2/ the SRX with public IP should NOT have "establish-tunnels immediately" configured, because

2a/ it makes no sense to poke udp/500 on remote end behind NAT, on SRX port 500 won't be translated into by default

2b/ "establish-tunnels immediately" seems to be broken with JUNOS 12.1X47-D15 - I got no tunnels up when both ends have "establish-tunnels immediately" and one end with public IP has JUNOS 12.1X47-D15. 

Once I got it configured as above, IPSec VPN works fine.

HTH

Thx

Alex


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>