ScreenOS Firewalls (NOT SRX)
ScreenOS Firewalls (NOT SRX)

Juniper SSG550 dual wan default route issue

‎03-07-2017 01:15 AM

Hi,everybody.

I have a issue with two default route on SSG FW.

HQ have a Juniper SSG550 and E0/1 public IP address 1.1.1.1/24 in Untrust Zone,E0/2 public IP address 2.2.2.2/24 in Untrust Zone.

 

There have two default route :

set route 0.0.0.0/0 interface  ethernet0/1 gateway 1.1.1.254 

set route 0.0.0.0/0 interface  ethernet0/2 gateway 2.2.2.254 metric 10

 

So, Any traffic from Trust to Untrust(To Internet)will pass through interface E0/1.

All right, This is a normal action.

 

Now, Our other site have a juniper SSG20 which have a public address 3.3.3.3/24 on interface E0/0 . (set route 0.0.0.0/0 interface  ethernet0/0 gateway 3.3.3.254)

 

We want routed-base vpn redundant  between SSG550 and SSG20. 

 

When I ping SSG550 E0/1 address 1.1.1.1 on SSG20, it's OK!

When I ping SSG550 E0/2 address 2.2.2.2 on SSG20, it's OK !!!!    Why???  

 

Is SSG550 recive the icmp request from E0/2 and lookup routing-table return this packet to E0/1 ? 

But After I delete the second default route(unset route 0.0.0.0/0 interface  ethernet0/2 gateway 2.2.2.254 metric 10),the ping failure(SSG 20 do not ping 2.2.2.2)

 

Anybody help me ?

 

 

 

 

2 REPLIES 2
ScreenOS Firewalls (NOT SRX)

Re: Juniper SSG550 dual wan default route issue

‎03-07-2017 10:50 PM

Hello,

 

Can you provide the output from SSG550 of command:

 

'get flow'

 

Regards,

 

Rushi

ScreenOS Firewalls (NOT SRX)

Re: Juniper SSG550 dual wan default route issue

‎03-11-2017 08:03 AM

The simpliest way to work around this issue is to install two identical routes to the remote gateway out of both providers.  This will allow both to respond and setup tunnels to the remote office.

 

 

set route 3.3.3.3/32 interface  ethernet0/1 gateway 1.1.1.254 
set route 3.3.3.3/32 interface  ethernet0/2 gateway 2.2.2.254

 

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home