SRX

last person joined: 2 days ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  SRX240 to pass through a IPSec VPN tunnel.

    Posted 10-25-2012 01:03

    Hi everybody. I´m haveing some trouble with passing through a IPSec VPN tunnel. Network is, as follows:

     

    VPN router1-->Internet-->Juniper SRX240-->VPN router2

     

    My goal is just to let that VPN tunnel pass through the Juniper- I dont want to configure that VPN into Juniper, because I dont want to get access to that tunnel. So far I have tried the following:

     

    IKE-ESP is allowed

    I have tried allowing all incoming and outgoing traffic

    Created st0.0 logical interface, assigned it to trust-zone and allowed all protocols

     

    So far we have managed to get that tunnel up, but no traffic is active through that tunnel and from "VPN router1" side they saw, that Juniper is trying to establish IPSec connection (even though IPSec is not configured).

     

    Any help would be appreciated!



  • 2.  RE: SRX240 to pass through a IPSec VPN tunnel.
    Best Answer

    Posted 10-25-2012 14:55

    You could just through a FW filter rule up and let the traffic flow through in packet mode. Bypass the whole SRX security function. Make sure you write an ingress and egress filter. 



  • 3.  RE: SRX240 to pass through a IPSec VPN tunnel.

    Posted 10-29-2012 02:41

    Thank You for the tip and guidance. Somehow the tunnel still seems to freeze...



  • 4.  RE: SRX240 to pass through a IPSec VPN tunnel.

    Posted 10-29-2012 09:25

    Can you post up the relevant portions of your config and we'll have a look?



  • 5.  RE: SRX240 to pass through a IPSec VPN tunnel.

    Posted 11-01-2012 07:12

    Sorry for the late reply. Problem is solved now- by changing the VPN tunnel, so it would transmit data with udp packets- now Juniper lets traffic just pass by.



  • 6.  RE: SRX240 to pass through a IPSec VPN tunnel.

    Posted 10-25-2012 14:56

    Oh - and next time post your SRX questions in the SRX Security Forum. You will get a much greater response rate. This forum is for the SSL box only.