Hi everybody,
yesterday I configured a simple QoS on a SRX210. I thought this should be no big deal, but I was wrong... This is my QoS config:
interfaces {
ge-0/0/0 {
per-unit-scheduler;
unit 0 {
family inet {
filter {
input bandwidth-management;
output bandwidth-management;
}
}
}
}
}
policy-options {
prefix-list preferred-hosts-4-10mbit {
193.xxx.xxx.21/32;
193.xxx.xxx.22/32;
193.xxx.xxx.23/32;
}
}
class-of-service {
forwarding-classes {
queue 4 bandwidth-10mb;
queue 5 bandwidth-5mb;
}
interfaces {
ge-0/0/0 {
unit 0 {
scheduler-map bandwidth-limit;
shaping-rate 15m;
}
}
}
scheduler-maps {
bandwidth-limit {
forwarding-class bandwidth-10mb scheduler scheduler-10mb;
forwarding-class bandwidth-5mb scheduler scheduler-5mb;
}
}
schedulers {
scheduler-10mb {
transmit-rate {
10m;
exact;
}
priority high;
}
scheduler-5mb {
transmit-rate {
5m;
exact;
}
}
}
}
firewall {
family inet {
filter bandwidth-management {
term 0 {
from {
destination-prefix-list {
preferred-hosts-4-10mbit;
}
}
then {
count bw-10mb;
forwarding-class bandwidth-10mb;
accept;
}
}
term 1 {
then {
count bw-5mb;
forwarding-class bandwidth-5mb;
accept;
}
}
}
}
}
My main problem is, that Client-2-Site VPN tunnels fail with a Phase 2 error, after applying this configuration. I figured out, that the Client-2-Site tunnels are working again, when I remove "per-unit-scheduler" from the interface config. If I re-apply "per-unit-scheduler", the Client-2-Site tunnels fail again.
Jul 2 06:24:05 srx-firewall kmd[1441]: IKE Phase-2: Failed to match the peer proxy IDs [p2_remote_proxy_id=ipv4_subnet(any:0,[0..7]=0.0.0.0/0), p2_local_proxy_id=ipv4(any:0,[0..3]=10.10.10.208)] for local ip: 10.0.0.1, remote peer ip:109.41.xxx.xxx
Any idea why this happens?
Thanks for advice.