I am trying to configure multiple IPSec tunnels in one zone, but I want to use unnumbered interfaces so that I can conserve IP addresses. I could use NextHop Tunnel Binding (NHTB), but Junos requires me to eat up more IP addresses.
So I simply added a second st0 interface to the zone with a static route for each st0 interface, as a workaround to avoid NHTB and save my IP addresses. But when I do so, I am unable to send traffic down the second st0 interface. In my traffic logs, I get a "Tunnel invalid" message:
RT_FLOW_SESSION_CLOSE: session closed Tunnel invalid: 10.0.250.18/34749->192.168.100.200/33437 None 10.0.250.18/34749->192.168.100.200/33437 None None 17 Test-Outbound-Default Test Campus 80959889 1(40) 0(0) 1 UNKNOWN UNKNOWN N/A(N/A) st0.3
Is there some way around this limitation, or am I forced to use NHTB if I want to have more than one tunnel in a particular zone?
Here is a snippet of my config that does not work:
[edit interfaces st0]
unit 2 {
family inet;
}
unit 3 {
family inet;
}
[edit security zones security-zone ZoneTest]
host-inbound-traffic {
system-services {
ping;
}
protocols {
all;
}
}
interfaces {
st0.2;
st0.3;
}
[edit routing-instances VrTest]
interface st0.2;
interface st0.3;
routing-options {
static {
route 10.0.250.0/28 next-hop st0.2;
route 10.0.250.16/28 next-hop st0.3;
}
}
Thanks.
Clarke Morledge
College of WIlliam and Mary