05-25-2012 04:49 AM
Solved! Go to Solution.
05-26-2012 11:33 AM
05-26-2012 09:04 PM
I'm tracking this issue as well. By chance, how is the SA deployed? Is it standalone or clustered, one-armed/two-armed configuration, and is the interface behind a firewall?
05-27-2012 09:35 PM
05-27-2012 09:36 PM
05-27-2012 09:39 PM
05-29-2012 09:55 AM - edited 05-29-2012 09:57 AM
Solution![]()
Open Below ports on the Firewall from Untrust to SSL-VPN Zone...
From SSL-VPN Guide:
For VPN tunneling to communicate, the following ports must be open: UDP port 4242 on loopback address TCP port 443 If using ESP mode, the UDP port configured on the Secure Access Service ( default is UDP 4500).
Admin Guide: http://www.juniper.net/techpubs/software/ive/admin
Pg # 740
Regards,
Sajid
05-29-2012 11:48 AM
Thanks Sajid. I'm going to try this solution. Did you have make changes on your endpoints? Or on the perimeter firewall? Thanks!
05-29-2012 12:24 PM
Hi Everette,
I just opened a port 4500 UDP on the firewall from Untrust to SSL-VPN.
Actually the problem is with JunosPulse Client v3 fallback from ESP to SSL tunnel.
Previous version v2.1 is switch quicky from ESP to SSL as fallback, but in v3 they have some delay.
its up to you either switch your connection profile from ESP to SSL or keep ESP and open port 4500 UDP.
VPN Tunneling Connection Profiles > "Connection Profile name"
Connection Settings
Transport
Default is
ESP (maximize performance) "Required port 4500 UDP to open on the Firewall"
2nd option
SSL (maximize compatibility) "work with port 443"
Let me know if you have any query.
Regards,
Sajid
05-30-2012 01:41 AM
Hi,
Version 2.1.x did not support ESP actually. It's a new feature of IVE 7.2 and Pulse 3.
b.r.
Emmanuel