SRX Services Gateway
Reply
Visitor
pasquale_lombardo
Posts: 2
Registered: ‎02-24-2012
0

Re: Can SRX series work with Shrew Soft VPN client?

I've tried the suggested configuration and it woks just for 200 seconds.

After that time I receive back :

gateway is not responding

tunnel disabled

detached from key daemon....

Tested with SRX240 10.4.8.5 junos version and Shrew 2.1.7 and 2.2.0(beta).

 

Any suggestion ?

 

Visitor
utahbmxer
Posts: 9
Registered: ‎10-19-2011
0

Re: Can SRX series work with Shrew Soft VPN client?

I have this same problem and would really love to figure this out.  The SRX deletes the SA after a couple minutes, then Shrew reports that the gateway is not responding and disconnects.   Running Wireshark and I am not seeing Heartbeats or any packets for that matter that are coming from the SRX.  From the IKE traceoption is appears that the SRX is receiving DPD packets from Shrew client.

 

10.4R8.5 with shrew 2.2.0.

 

Juniper Networks Access Manager works fine with dynamic VPN.

Visitor
pasquale_lombardo
Posts: 2
Registered: ‎02-24-2012
0

Re: Can SRX series work with Shrew Soft VPN client?

YES

Juniper Networks Access Manager works fine.

I've used it.

Juniper Employee
pgeenens
Posts: 1
Registered: ‎01-07-2008
0

Re: Can SRX series work with Shrew Soft VPN client?

I got the same problem with Shrew and SRX: disconnects consistently after 200 sec.

 

The workaround is to set Phase1 key life time to 180 sec while keeping Phase2 key life time on default 28800. This will force a rekey before the SA is deleted from the SRX. Tunnel connectivity is not disrupted and the tunnels stays up.

 

Have been testing the tunnel using icmp for the last hour and get occasional spikes of 70ms delay, I guess because of the rekey (min latency is 35ms and avg is 40ms).

 

Tested with SRX210H running Junos 11.4r2.1 and Shrew 2.1.6 on Windows and on Linux (Ubuntu).  

 

Pascal.

NCP
Contributor
NCP
Posts: 15
Registered: ‎05-03-2011
0

Re: Can SRX series work with Shrew Soft VPN client?

The proper supported IPsec VPN client is NCP: http://www.ncp-e.com.

It works with no problems, stable, reliable and fast. I think you get what you pay for 8)

Best Regards,
Rainer Enders
New User
jimboboy
Posts: 1
Registered: ‎09-12-2012
0

Re: Can SRX series work with Shrew Soft VPN client?

Hey, just grappled with this

 

Need to tell the Shrew client what networks are going to be tunneled.

 

To do this open the client

 

Policy tab 

Untick "Obtain Topology Automatically or Tunnel All"

Click "Add" and enter the network that you want to tunnel to 

Save and reconnect, should work.

Trusted Contributor
michael.saw
Posts: 1,048
Registered: ‎09-26-2011
0

Re: Can SRX series work with Shrew Soft VPN client?

Thanks for the great share!!!

Does it work in SRX 11.4?
Any other VPN client to test/share?
Thanks!

Michael
JNCIA-JUNOS, JNCIS-ENT/SEC, JNCIP-ENT
(CCNA, ACMP, ACFE, CISE)
"http://www.thechampioncommunity.com/"
CONNECT EVERYTHING. EMPOWER EVERYONE.
Share & Learn. Knowledge is Power.

"If there's a will, there's a way!"
Visitor
gcharot@evenium.com
Posts: 5
Registered: ‎11-28-2012
0

Re: Can SRX series work with Shrew Soft VPN client?

Hello all,

 

Asked Shrew Core Dev about this :

 

http://lists.shrew.net/pipermail/vpn-help/2012-December/004655.html

 

This is internal to the Shrew client, this should be fix next year.

 

Hope that helps,

Cheers,

Greg

Trusted Contributor
michael.saw
Posts: 1,048
Registered: ‎09-26-2011
0

Re: Can SRX series work with Shrew Soft VPN client?

Thanks.

Anyone tried any shrewsoft lookalike on mobile or smart devices?

Merry X'mas!
Thanks!

Michael
JNCIA-JUNOS, JNCIS-ENT/SEC, JNCIP-ENT
(CCNA, ACMP, ACFE, CISE)
"http://www.thechampioncommunity.com/"
CONNECT EVERYTHING. EMPOWER EVERYONE.
Share & Learn. Knowledge is Power.

"If there's a will, there's a way!"
Visitor
khalid.alshamsi
Posts: 1
Registered: ‎03-08-2013
0

Re: Can SRX series work with Shrew Soft VPN client?

from my experience, the device disconnects after 60 seconds, just like whats mentioned in the link

 

https://lists.shrew.net/pipermail/vpn-help/2012-December/014094.html

 

once i set the key life time limit to 55 seconds its stays up with no issues. Anyways it should be fixed hopefully in the next release of shrew.

 

HTH

khalid.

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.