SRX Services Gateway
Highlighted
SRX Services Gateway

VPN support in SRX A-A cluster

‎01-13-2015 12:49 AM

Hello

 

Is it possible to configure VPN in A-A cluster on both branch and High-end SRX's?

cause I found in the release notes that its not supported for High-end firewalls working in A-A, so is it not supported at all in high-end A-A cluster, or it will be working only on the active node?

 

another question about loopback support for VPN;

I knew that its supported starting from 12.1x44, but is it supported on both the branch and high-end firewalls?

 

Regards

Mahmoud

6 REPLIES 6
Highlighted
SRX Services Gateway

Re: VPN support in SRX A-A cluster

‎01-13-2015 12:58 AM

VPN on A-A cluster is not possible as of now. As per the latest news this feature is available on upcoming releases.

 

Loopback support is for both branch and high end.

 

Thanks,

Suraj

 

Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too

Thanks,
Suraj
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too
Highlighted
SRX Services Gateway

Re: VPN support in SRX A-A cluster

‎01-13-2015 01:00 AM

Hi Mahmood

 

Active-Active SRX cluster is not recommended in HE SRX devices.

You could use loopback interfaces in both branch and HE SRX devices.

 

Regards,

Raveen

Note: If this answers your question, you could mark this post as accepted solution, that way it helps others as well. Kudos will be cool if I earned it!
Highlighted
SRX Services Gateway

Re: VPN support in SRX A-A cluster

‎01-13-2015 06:21 AM

So is it possible to have VPN configured on the unit which has the active RE ?

or its not supported at all in H.E A-A setup??

 

Thanks

Highlighted
SRX Services Gateway

Re: VPN support in SRX A-A cluster

‎01-13-2015 07:00 PM

HE Active-Active cluster is not recommended as of today.

There is a new enhancement in upcoming release which would support HE A/A cluster.

 

Regards,

Raveen

Note: If this answers your question, you could mark this post as accepted solution, that way it helps others as well. Kudos will be cool if I earned it!
Highlighted
SRX Services Gateway

Re: VPN support in SRX A-A cluster

‎01-14-2015 01:23 AM

Ok, but what about VPN!

Can I configure it in A-A cluster on the unit which has the active RE at least?

Highlighted
SRX Services Gateway
Solution
Accepted by topic author eng_mahmood48@yahoo.com
‎08-26-2015 01:27 AM

Re: VPN support in SRX A-A cluster

[ Edited ]
‎01-14-2015 01:33 AM

Unfortunately, thats not possible as of now.

 

On all high-end SRX Series devices, IPsec VPN is not supported in active/active chassis cluster configuration (that is, when there are multiple RG1+ redundancy groups).

 

http://www.juniper.net/techpubs/en_US/junos12.1x44/information-products/topic-collections/release-no...

 

The below URL will help us to understand the limitation in a better way.

 

http://www.juniper.net/techpubs/en_US/junos12.1x45/topics/concept/security-loopback-interface-ha-for...

 

VPN on High end devices are supported only with Active/Passive Setup.

 

Thanks,

Suraj

Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too

 

Thanks,
Suraj
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too
Feedback