SSL VPN
Reply
Visitor
William Lee
Posts: 3
Registered: ‎05-13-2012
0
Accepted Solution

Connection delay issue with JUNOS Pulse 3.0R1.1

Hi,

 

I have a pair of MAG6611 setup as active/active cluster. The software version is Secure Access 7.2R1.1.

I have configured VPN Tunneling for user for remote access and it works.

But there's problem when I'm using JUNOS Pulse client version 3.0R1.1, after connected to SSL VPN, I'll experience a delay betweem 30sec to 1min before being able to access or ping to a host in remote network.

I have verified the routing table on the client PC, the client PC received the route to remote network after connected to SSL VPN.

I have not experience this problem when using JUNOS Pulse client version 2.1R4. I'm able to access to the host near instant after connected to the SSL VPN.

I have not made any changes to the cluster.

Could anyone share some idea on how to troubleshoot on this issue?


Thank you

 

Moderator Moderator
Moderator
AJA
Posts: 130
Registered: ‎05-07-2010
0

Re: Connection delay issue with JUNOS Pulse 3.0R1.1

Is this happening on any specific operating system as in Windows 7, Windows XP etc?

Is this seen by all the user's or is this a global effect?

When you say - you are trying to access certain resource and it takes 30 seconds - may I know if it's with all individual resource or is it only until you access the first resource behind the SA?

 

Moderator Moderator
Moderator
AJA
Posts: 130
Registered: ‎05-07-2010
0

Re: Connection delay issue with JUNOS Pulse 3.0R1.1

Are you able to consistently reproduce the problem?

 

If "YES" - I would suggest you to open a JTAC ticket for the same side-by-side.

 

I would also say - please ensure you dont have any other third party VPN Clients on your machine. If you do have any applications along with the Pulse app - please try to uninstall all the other VPN app's and install pulse first to check if that helps.

 

 

Please mark this post as 'accepted solution' if this answers your question that way it might help others as well, a kudo would be a bonus thanks

Visitor
William Lee
Posts: 3
Registered: ‎05-13-2012
0

Re: Connection delay issue with JUNOS Pulse 3.0R1.1

Hi,

 

I have been testing it on Windows 7 and MAC OS X Lion 10.7.3. When I used the JUNOS Pulse 3.0 R1.1 client, I'll experience the connection delay issue. It only happened when I tried to access to the first resource behind the SA, accessing to subsequent resource will not have any connection issue.

 

Visitor
William Lee
Posts: 3
Registered: ‎05-13-2012
0

Re: Connection delay issue with JUNOS Pulse 3.0R1.1

Hi,

 

I have proceed to raise a JTAC ticket. Thank you

Contributor
dark1587
Posts: 64
Registered: ‎08-01-2008
0

Re: Connection delay issue with JUNOS Pulse 3.0R1.1

Hello Lee,

I am having the exact same issue as well. Any update from JTAC on the issue?

---
JNCIE-SEC #69, JNCIP-ENT, JNCSP-SEC, JNCIS-SA, JNCIS-AC, JNCIA-IDP, JNCIA-WX
Visitor
StuartBrainerd
Posts: 1
Registered: ‎07-23-2008
0

Re: Connection delay issue with JUNOS Pulse 3.0R1.1

We are having the same issue with 7.2r1.1 and the MAG2600, have tested with multiple machines all running Windows 7 Professional 64-bit.  We will open a JTAC case as well.

Contributor
sajidalisajid
Posts: 14
Registered: ‎07-08-2010
0

Re: Connection delay issue with JUNOS Pulse 3.0R1.1

Hi William,

 

I already resolved this issue.

 

FYI

http://forums.juniper.net/t5/SSL-VPN/Junos-Pulse-3-0-1-20017-Reponse-Issue-from-SA-7-2R1-1-build/m-p...

 

Open Below ports on the Firewall from Untrust to SSL-VPN Zone...

From SSL-VPN Guide:

 

For VPN tunneling to communicate, the following ports must be open: UDP port 4242 on loopback address TCP port 443 If using ESP mode, the UDP port configured on the Secure Access Service ( default is UDP 4500).

 

http://kb.juniper.net/InfoCenter/index?page=content&id=KB21762&actp=search&viewlocale=en_US&searchid...

 

 Admin Guide: http://www.juniper.net/techpubs/software/ive/admin/j-sa-sslvpn-7.2-adminguide.pdf

 

Pg # 740

 

 

From my previous post***************

I just opened a port 4500 UDP on the firewall from Untrust to SSL-VPN.

 

Actually the problem is with JunosPulse Client v3 fallback from ESP to SSL tunnel.

 

Previous version v2.1 is switch quicky from ESP to SSL as fallback, but in v3 they have some delay.

 

its up to you either switch your connection profile from ESP to SSL or keep ESP and open port 4500 UDP.

 

 

VPN Tunneling Connection Profiles > "Connection Profile name"

 

Connection Settings

Transport

 

Default is

 

ESP (maximize performance)  "Required port 4500 UDP to open on the Firewall"

 

2nd option

SSL (maximize compatibility)  "work with port 443"

 

 

 

From EBailleul

JunosPulse Version 2.1.x did not support ESP actually. It's a new feature of IVE 7.2 and Pulse 3.

 

Let us know if you have any query.

 

Regards,

Sajid

 

Contributor
sajidalisajid
Posts: 14
Registered: ‎07-08-2010
0

Re: Connection delay issue with JUNOS Pulse 3.0R1.1

From the Relese Note:

 

http://www.juniper.net/techpubs/software/ive/releasenotes/j-sa-sslvpn-7.2R1-whatsnew.pdf

 

ESP Transport Mode (Junos Pulse Secure Access Service/SSL VPN)

 

Junos Pulse 3.0 on Microsoft Windows now includes support for SSL VPN ESP transport mode. UDP-based ESP transport mode provides higher throughput than the TCP-based SSL transport mode. Juniper’s dual-transport Junos Pulse client will attempt to establish the VPN tunnel over ESP transport mode by default. If this is unsuccessful, Junos Pulse will automatically attempt to set up the tunnel over SSL. A newly introduced administrative option in Pulse Secure Access Service (SSL VPN) 7.2 allows administrators to prevent the failover from ESP to SSL transport mode. If the administrator option is enabled, Junos Pulse attempts to connect only via the ESP transport mode.

Contributor
RexPGP
Posts: 145
Registered: ‎05-04-2009
0

Re: Connection delay issue with JUNOS Pulse 3.0R1.1

To auto fail over and keep customres happy is worth the 30 seconds

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.