06-15-2011 08:48 AM
Hello All,
We have a shrew soft vpn that appears to be working just fine..... when we look at the corresponding policy log within the Juniper SSG 520 we can see our activity.....
policy:
source:
[V1-Untrust/Dial-Up VPN]
destination:
[V1-Trust/10.1.1.0/24]
BUT.... the activity is all Traffic Denied..... (trying to do ANYTHING between any 10.1.1.* ip address)
example: pinging from 10.1.1.6 TO 10.1.1.2 gives the following policy log entry:
[datetime][source address port][destination address port][translated source][translated destin][service][duration][bytes sent][bytes received][close reason]
[11:40][10.1.1.6:25][10.1.1.2.1][0.0.0.0:0][0.0.0.
help!
Solved! Go to Solution.
06-22-2011 04:44 PM - edited 06-22-2011 04:46 PM
Hi,
when the device is not in transparent mode, the zone is untrust not v1-untrust.
please also take a look , where your dial-up vpn client is terminating in whitch zone...
i can also post a working config (non transparent mode)....if you wish..
Regards
06-30-2011 08:58 AM
We discovered that our 'randomly' created ip address grouping (behind firewall) was not defined as a vlan