SRX Services Gateway
SRX Services Gateway

st0.6 interface not coming up IPSEC VPN

Thursday

I have attached configuration in SRX 5800, in order to prepare the VPN with AWS.

i used st0.6 this time, from st0.0 to st0.5 are already working with other tunnels.

st0.6 is little different to other tunnel interface, it has reth2.2410 as outside interface, 

and routing-instance is SGi-VR.

Can anyone help in spoting the config mistake I am making here, unless st0.6 coming UP, I can't establish tunnel

Thanks

Attachments

6 REPLIES 6
SRX Services Gateway

Re: st0.6 interface not coming up IPSEC VPN

Thursday

under zone configuration of untrust, you have

SRX Services Gateway

Re: st0.6 interface not coming up IPSEC VPN

Thursday

Just curious, Is reth2.2410 configured in default instance and part of a security zone with ike enabled for the host bound services ?


 

SRX Services Gateway

Re: st0.6 interface not coming up IPSEC VPN

Friday

set security zones security-zone vpn-TESCO interfaces st0.6
set security zones security-zone vpn-TESCO interfaces st0.6 host-inbound-traffic system-services all
set security zones security-zone vpn-TESCO interfaces st0.6 host-inbound-traffic protocols all
set security zones security-zone vpn-TESCO interfaces st0.6 host-inbound-traffic system-services ike

 

set security zones security-zone inside description "Gi Inside Traffic "
set security zones security-zone inside screen ATTACK-SCAN
set security zones security-zone inside host-inbound-traffic system-services ping
set security zones security-zone inside host-inbound-traffic system-services traceroute
set security zones security-zone inside host-inbound-traffic protocols ospf
set security zones security-zone inside interfaces reth1.410

SRX Services Gateway

Re: st0.6 interface not coming up IPSEC VPN

Friday

My zone configuration

trust zone

set security zones security-zone inside description "Gi Inside Traffic "
set security zones security-zone inside screen ATTACK-SCAN
set security zones security-zone inside host-inbound-traffic system-services ping
set security zones security-zone inside host-inbound-traffic system-services traceroute
set security zones security-zone inside host-inbound-traffic protocols ospf
set security zones security-zone inside interfaces reth1.410

 

vpn zone or untrust zone

set security zones security-zone vpn-TESCO interfaces st0.6
set security zones security-zone vpn-TESCO interfaces st0.6 host-inbound-traffic system-services all
set security zones security-zone vpn-TESCO interfaces st0.6 host-inbound-traffic protocols all
set security zones security-zone vpn-TESCO interfaces st0.6 host-inbound-traffic system-services ike

SRX Services Gateway

Re: st0.6 interface not coming up IPSEC VPN

Friday

set security zones security-zone Internet description "ISP Internet "
set security zones security-zone Internet screen ATTACK-SCAN
set security zones security-zone Internet host-inbound-traffic system-services ike
set security zones security-zone Internet interfaces reth2.2410

 

set routing-instances SGi-VR interface reth1.281
set routing-instances SGi-VR interface reth1.410
set routing-instances SGi-VR interface reth2.2410
set routing-instances SGi-VR interface reth3.280

 

set routing-instances SGi-VR instance-type virtual-router
set routing-instances SGi-VR interface reth1.281
set routing-instances SGi-VR interface reth1.410
set routing-instances SGi-VR interface reth2.2410
set routing-instances SGi-VR interface reth3.280

SRX Services Gateway

Re: st0.6 interface not coming up IPSEC VPN

Friday

The config on SRX side looks good. 
i would suggest the following as next steps to troubleshoot such issues:

1.  Remove the vpn-monitor and check if the ike and ipsec SAs stays up. Also check if st0.6 stays up

2. Use the trceoptions feature to analyze the issue further.

https://kb.juniper.net/InfoCenter/index?page=content&id=KB19943&actp=METADATA&act=login