SRX/J ipsec packets discarded after flow process before entering ESP encryption
Having some strange problems with a J6350 lately. IPSEC tunnel comes up fine with both P1 and P2. ICMP packets can get through the tunnel just fine. SSH or any other type traffic dispears after the...
View ArticleRe: Connectivity Between 2 SRX
Hello, Finally its started working..............Thanks a lot SRX1:root> ping 1.1.1.2PING 1.1.1.2 (1.1.1.2): 56 data bytes64 bytes from 1.1.1.2: icmp_seq=0 ttl=64 time=201.241 ms64 bytes from...
View ArticleRe: Dynamic VPN, Pulse Secure Error 1453
Hello, Thank you for replying to my post. I upgraded the firmware to 12.1X47-D35.2 last night, and I'm still getting the same error, however. I attached some photos of my Pulse client.
View ArticleRe: SRX210H-POE problem with device access
May this be a JTAG port? I'm particularly interested in this port because a update to JTAC recomended (junos-srxsme-12.1X46-D50.4-domestic.tgz) version messed up with my U-Boot.
View ArticleRe: SRX210, MPIM Gig-E and Ethernet Switching
I can confirm that 12.1X46 does work with ethernet-switching, using a 1GE mini-PIM.
View ArticleRe: SRX240 and vpls on untagged interface
I tried above configuration example and it works well.
View ArticleDifference between address with subnet and range-address in address-book
Does someone knows the diffrence between : book { address ABC 192.168.1.0/24 } and book { address ABC { range-address 192.168.1.0 { to { 192.168.1.255; } } } }For me it is the same thing...
View ArticleRe: Difference between address with subnet and range-address in address-book
They are different. The first encompasses 256 addresses, the other is about 19.3 million addresses.
View ArticleRe: Difference between address with subnet and range-address in address-book
Well, obviously the entered range of address was wrong. They are both 256 addresses.
View ArticleRe: Dynamic VPN, Pulse Secure Error 1453
I was following a number of tutorials online. What I have is mostly based off of these two: http://www.mustbegeek.com/configure-dynamic-remote-access-vpn-in-juniper-srx/...
View ArticleRe: Difference between address with subnet and range-address in address-book
I think in your example they are the same but the address range does not have to fit the bit boundry. For example an address range could be 192.168.1.10 to 192.168.1.20. You can not achieve this with...
View ArticleRe: address-assignment pool static options
Hi Rob, If you're still running SRX 1xx, 2xx, 5xx then there is probably no reason to stop using the old DHCP server. The only reason I've switched any boxes over is to support DHCPv6, but that...
View ArticleRe: Difference between address with subnet and range-address in address-book
Oh yes! That make sense. So the first one define a range based on a binary boundary while the second one define a numerical range. Feeling a bit shy I did not think about it.... :-(
View ArticleRe: route failover using ip-monitoring not working
For this situation where you want to load balance over the two ISP you would use filter based forwarding to sort out the traffic and choose what type of traffic uses each ISP. You can do this by...
View ArticleRe: Replacing a SSG5 with SRX100H2 in branch office
You will probably want to remove the proxy-id from both sides of the tunnel then in this situation. these restrict what subnets can be sent over the tunnel. If you remove them on both sides the...
View ArticleSwitching from SSG to SRX (SRX110 EoL?)
Hi @all, First of all a big HELLO to the whole community. Some of my customers are equipped with the SSG5 and soon there will be time to replace them. All that SSG5 work very fine without any problems...
View ArticleRe: srx flow
Hello , Please check : http://kb.juniper.net/InfoCenter/index?page=content&id=kb16677&actp=searchhttp://kb.juniper.net/InfoCenter/index?page=content&id=KB21023&actp=search
View ArticleRe: Switching from SSG to SRX (SRX110 EoL?)
Hello , SRX110 will be EOL only on 2019 only .
View ArticleRe: Dynamic VPN, Pulse Secure Error 1453
Hello , This issue should have a fix on pulse 5.1R5.1 . Can you try pulse 5.1R5 ( yours is 5.1R1)
View Article