Application Acceleration
Highlighted
Application Acceleration

Can't access WebUI for remote spoke

‎10-12-2011 09:27 AM
Hello,

Everything seems to be working fine on the new WAN acceleration deployment that has gone through a lot of troubleshooting in the past few weeks. However, there's an issue with accessing a spoke device from the hub via WebUI & SSH.

Deployment is in a hub (1) & spoke (10) topology all in offpath mode with WCCP packet interception mode. WXOS - 5.7.7.7.

This particular site (spoke) doesn't have re-direction enabled on it, yet I can't access it via webUI & SSH. I can ping the spoke & it's gateway. I have asked client to check for any possible access lists/policies that could cause this but none was found.

Can someone help with this?

PS: I asked for the spoke device to be 'power cycled' at the branch. I could access the spoke through SSH & WebUI for a brief period (either during or shortly after power cycling) but I got denied again after this short period.

Thanks in anticipation
6 REPLIES 6
Highlighted
Application Acceleration

Re: Can't access WebUI for remote spoke

[ Edited ]
‎10-12-2011 01:12 PM

Hi there,

It looks like your spoke' "own subnet" is enabled for compression, that's why you were able to briefly connect to WebUI/SSH from behind spoke when this subnet wasn't yet advertised.

Disable compression for spokes' own subnets or configure source-destination filters on hub for every /32 spoke IP to avoid losing contact.

Locally-generated WXOS traffic is never compressed/tunneled anyway so generally speaking you wouldn't need source/dest filters on spokes.

HTH

Rgds
Alex 

_____________________________________________________________________

Please ask Your Juniper account team about Juniper Professional Services offerings.
Juniper PS can design, test & build the network/part of the network as per Your requirements

+++++++++++++++++++++++++++++++++++++++++++++

Accept as Solution = cool !
Accept as Solution+Kudo = You are a Star !
Highlighted
Application Acceleration

Re: Can't access WebUI for remote spoke

‎10-12-2011 09:37 PM
Thanks for the response.

So let me get you clearly here. Are you saying a possible solution would be to configure source-destination filters on hub for every /32 spoke IP to avoid losing contact??

Because your last statement seems to contradict this. Or you were only trying to say the source/destination filter configuration needs to be done on the hub and not the spoke?

Thanks
Highlighted
Application Acceleration

Re: Can't access WebUI for remote spoke

‎10-13-2011 02:48 AM

Hello,

I think you have 2 choices here:

1/ do _not_ advertise spoke' local subnet as "compression subnet" from every spoke, or

2/ configure source/destination filters for every spoke' /32 address on the hub. No need to configure src/dst filters for hub' /32 on spokes.

HTH

Rgds
Alex 

_____________________________________________________________________

Please ask Your Juniper account team about Juniper Professional Services offerings.
Juniper PS can design, test & build the network/part of the network as per Your requirements

+++++++++++++++++++++++++++++++++++++++++++++

Accept as Solution = cool !
Accept as Solution+Kudo = You are a Star !
Highlighted
Application Acceleration

Re: Can't access WebUI for remote spoke

‎10-13-2011 03:10 AM
Hi,

I just tried the src/dest filter & the situation is thesame (still can't access the spoke device from hub).

About the second option, all the other working spoke devices are configured thesame way (including this). Also, since I can't log into the box, there's no way I can make any changes.

PS: This site was working fine before.

Thanks

Highlighted
Application Acceleration

Re: Can't access WebUI for remote spoke

‎10-13-2011 05:08 AM

Hello,

 


@Okunz wrote:
Hi,

I just tried the src/dest filter & the situation is thesame (still can't access the spoke device from hub).




I hope you properly wrote your filter before applying:

- src.IP = your mgmt subnet/workstation IP

- dst.IP = spoke's IP

 

If you do a pkt capture on the hub with filter applied, with properly-constructed filter you should see your WebUI/SSH packets going out in the clear (not compressed, not tunnelled).

HTH

Rgds

Alex


 

_____________________________________________________________________

Please ask Your Juniper account team about Juniper Professional Services offerings.
Juniper PS can design, test & build the network/part of the network as per Your requirements

+++++++++++++++++++++++++++++++++++++++++++++

Accept as Solution = cool !
Accept as Solution+Kudo = You are a Star !
Highlighted
Application Acceleration

Re: Can't access WebUI for remote spoke

‎10-17-2011 04:45 AM
Hi Alex,

I tried your suggestion but it didn't work. However, I was able to identify the issue. It was an ip conflict on the spoke device. Like I mentioned earlier, whenever the device is restarted, I can get access into the device for sometime & I get 'kicked out' of the GUI (or SSH) after a short period. I guessed this was due to an ip conflict with another device whenever there's a broadcast from the device.

I worked with the customer on this and my assumption was right so we resolved the ip addressing issue.

Thanks for your contribution.

Regards
Femi
Feedback