Junos OS

last person joined: yesterday 

Ask questions and share experiences about Junos OS.
  • 1.  SRX - Dynamic VPN on Custom Port not Working

    Posted 03-10-2016 10:20

    hey experts,

     

    i am currently facing an issue with dyn vpn on srx 100. It was running against a custom port but is not working anymore. it runs at port 4443 just as the https management. when i access srx through https://wan ip:4443 i get redirected to dyn vpn page. it was a working setup already but it does not work anymore . Of course there have been no changes .. ;). I think the problem is related to a destination nat for at port 443 pointing at an internal server at port 443. If i do a "show security flow session source prefix DYNVPNCLIENT-IP" i see that the policy that is configured for the dnat to the internal exchange server is hit for the initial connection of the dyn vpn client which comes at port 443 even if i configure WANIP:4443 in pulse client. Is this a known problem?i guess my only option would be a second wan ip adress or changing the dnat for the internal server from 443 to lets say 555 right?



  • 2.  RE: SRX - Dynamic VPN on Custom Port not Working
    Best Answer

     
    Posted 03-30-2016 06:16

    Hello ,

     

    You can try using management-url  for distingushing J-Web and Dynamic VPN :

     

    http://www.juniper.net/documentation/en_US/junos12.1x46/topics/example/vpn-security-dynamic-jweb-unique-url-configuring.html