SRX240 Max IPSec VPN's
Hi All, Can anyone help out with experiences on SRX240 IPSec VPN tunnels? Specifically the 'actual' maximum number supported? I posed a question to JTAC to clarify the number (1000 according to the...
View ArticleSRX SSLVPN config
Hello, Please advise me if this is off topic and if it should be in another section.I am looking to implement SSLVPN with a Pulse Connect Secure appliance. The termination will be a SRX3xx.Can someone...
View ArticleRe: SRX SSLVPN config
Hi, using SRX3xx u need use NCP as SSL VPN client not pulse secure. Thanks
View ArticleRe: SRX SSLVPN config
Hi, SSL VPN on the srx is only supported for the NCP client andthis support starts from the Junos version 15.1X49-D80 onwards.For using SSL Vpn through pulse secure the only appliance available is from...
View ArticleRe: SRX SSLVPN config
Hi Prasad, Do u mean even if we use ver 15.1X49-D80 , we can still use pulse secure as SSL VPN client? Thanks and appreciate your feedback
View ArticleRe: SRX SSLVPN config
Hi, SSLVPN on the SRX is only supported for NCP client.my point was that NCP client support started from 15.1X49-D80 onwards.So if you wish to use SSL VPN termination on the SRX then you will have to...
View ArticleIKE negotiation failed with error: IKE gateway configuration lookup failed...
Hi All, I am trying to set up Route-based IPSec VPN between SRX345 and Cisco RVI 130 but not work with the following error: IKE negotiation failed with error: IKE gateway configuration lookup failed...
View ArticleRe: IKE negotiation failed with error: IKE gateway configuration lookup...
Hi, From the screen shots and the configuration, I could find 2 issues.1. You are using aggressive modeon both the sides, please change it to main mode for the phase 1 IKE negotiation.policy...
View ArticleRe: IKE negotiation failed with error: IKE gateway configuration lookup...
Hi, Also the 3rd issue which i found is that on the cisco side you have definitely specified the local and the remote subnets however on the SRX there is nothing of that sort configured. Please...
View ArticleRe: IKE negotiation failed with error: IKE gateway configuration lookup...
Hi Guru, Thanks for your advice! The st8.0 is assigned to the corresponding security zone as below config. Actually, there are several VPN tunnels from various site to SRX345 and this is the no.8 site...
View ArticleRe: IKE negotiation failed with error: IKE gateway configuration lookup...
Hi, yes there is an issue with the configuration.becasue SRX does not support st8.0 if it is the 8th tunnel then it should be st0.8 instead of st8.0 regards,Guru Prasad
View ArticleRe: Traffic fails over VPN SRX
As there are messages about fragmentationMay 22 08:33:52 08:33:52.477285:CID-0:RT:packet need to be fragged. ip len 1460, max_ip_len 1452I would start with adjusting tcp mss on both ends#set security...
View ArticleRe: Traffic fails over VPN SRX
Hi,Thank you for the response. The tcp-mss is set to 1300 at both ends.
View ArticleSRX240 only one IPSec tunnel is slow in one direction.
Hello.I have SRX240H with multiple IPsec tunnels and SRX210H with multiple tunnels too.both boxes has JUNOS Software Release [12.1X46-D60.4] and only one IPsec tunnel at one direction 240->210 is...
View ArticleRe: VRRP Issues
Hi, firstly thanks for taking the time to reply. I thought that the default gateway would be the virtual ip and that was the point of it? You are suggesting that the traffic is hitting the .2 address...
View ArticleRe: VRRP Issues
Traffic is hitting virtual IP's but for one subnet it is managed by one firewall and for other the second firewal. Firewalls don't share information about sessions and traffic is blocked. There would...
View ArticleRe: SRX SSLVPN config
However, do not use the Juniper version of NCP client as that is now EOL and the standard version works perfectly well. From the NCP web site - End of Life announcement for NCP Secure Client - Juniper...
View ArticleSRX 550 ethernet aggregate configuration
Hi teamI have four SRX 550 devices at two data center.below is the topology. SRX1 DC1 connected to SRX2 DC2 via 1G link.SRX3 DC1 connected to SRX4 DC2 via 1G link. i need to know is there any chance i...
View ArticleRe: SRX SSLVPN config
Has anyone used the NCP and what do you think of it? How does it compare to the Pulse Secure? Thanks,
View Article