SRX Services Gateway
Reply
Contributor
aeroplane
Posts: 724
Registered: ‎06-30-2009
0

IPSEC termination on loopback interface or physical interface on SRX3600?

Hi Experts

 

I heard that on higher end SRX 3000/5000, IPSEC termination on loopback interface or physical interface  is not supported. Is that true?

 

Thanks

Recognized Expert
JunOS_Fan
Posts: 241
Registered: ‎02-13-2012
0

Re: IPSEC termination on loopback interface or physical interface on SRX3600?

Yes,it's true. KB19829 confirms the same . http://kb.juniper.net/kb19829
Best regards
Pradeep (JNCIP-SEC,ENT,SP)
www.networker.co.in
Juniper Employee
tleung
Posts: 11
Registered: ‎12-11-2009
0

Re: IPSEC termination on loopback interface or physical interface on SRX3600?

Hi Aeroplane,

 

Just to clarify, for HE platform, IPSec VPN termination on loopback is not supported no matter it is in chassis cluster.

Physical interface can be used to terminate IPSec VPN if it is on in chassis cluster.

If the box is in chassis cluster, only reth can be used to terminate IPsec VPN.

 

Cheers,

 

Tim.

Recognized Expert
mhariry
Posts: 334
Registered: ‎06-01-2011
0

Re: IPSEC termination on loopback interface or physical interface on SRX3600?

Hi,

 

check this post it might be helpful for you

 

http://forums.juniper.net/t5/SRX-Services-Gateway/Issues-terminating-VPN-to-lo0-0-on-SRX3400-cluster...

 

 

Regards,

 

Mohamed Elhariry

 

JNCIE-M/T # 1059, CCNP & CCIP

 

----------------------------------------------------------------------------------------------------------------------------------------

If this post was helpful, please mark this post as an "Accepted Solution".Kudos are always appreciated!

Regards,
Mohamed Elhariry
2* JNCIE (SEC # 159, SP # 1059),JNCIP-ENT

[Click the "Star" for Kudos if you think I earned it!
If this solution worked for you please flag my post as an "Accepted Solution" so others can benefit..]
Contributor
aeroplane
Posts: 724
Registered: ‎06-30-2009
0

Re: IPSEC termination on loopback interface or physical interface on SRX3600?

Thanks guys. Could you please provide this to me as well:

 

1- IPSEC termination on non-reth interfaces (physical, loopback) for branch SRX in chassis cluster mode

2- IPSEC termination on non-reth interfaces (physical, loopback) for HE SRX in chassis cluster mode

3- IPSEC termination on loopback interface for HE SRX standalone

 

Thanks

Visitor
mtucker502
Posts: 6
Registered: ‎03-26-2012
0

Re: IPSEC termination on loopback interface or physical interface on SRX3600?

tleung is correct, it doesn't matter if the HE SRX is in a cluster or not. Phase 2 will not come up if you're using loopback interfaces.

 

I hope KB19829 is updated to relfect this soon.

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.