Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

ScreenOS to JunOS: the journey continues... IPSec VPN very slow to reconnect

$
0
0

Hello,

I'm slowly getting my feet wet with JunOS as described in this earlier post: 

https://forums.juniper.net/t5/ScreenOS-Firewalls-NOT-SRX/Moving-away-from-SSG-ScreenOS-to-SRX-JunOS-best-way-to-proceed/m-p/322890#M32632

 

Over the past week, I have successfully inserted an SRX between my SSG and the ISP's equipment.

At this time, the SRX purely performs 1-to-1 static NAT for the SSG.

 

Now I'm noticing that IPSec VPNs configured between the SSG and other ScreenOS appliance reconnected immediately.

However, VPNs configured between SSG and remote SRX devices take *forever* to reconnect/pass traffic. Like 15-20 agonizing minutes or more.

 

Barring any misconfigurations, the VPNs typically show as 'up' on the remote SRX side, as I'm initiating ping traffic from my SSG side.

As I frantically checked and re-checked the configs on both sides, I did notice that anytime I add or remove a proxy ID check on both sides, the VPN auto-magically starts passing traffic upon commit.

 

What gives?

 

Any insight would be appreciated.


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>