ScreenOS Firewalls (NOT SRX)
ScreenOS Firewalls (NOT SRX)

Problem with VPN communication between 2 NS5XTs

05.19.09   |  
‎05-19-2009 11:08 AM

I have 2 locations with static IPs with a NS5XT on each side. They have a VPN between each other that was created by the vpn wizard. The issue I'm having is that I can ping and connect via remote desktop using ip addresses from one side (garage network of 192.168.0.0) to the other (colonial network of 192.168.1.0) but can't ping or connect from the colonial network to the garage network. Both devices have both "Trust" to "Untrust" & "Untrust" to "Trust" to the other network with the Any policy.

 

3 REPLIES
ScreenOS Firewalls (NOT SRX)
Solution
Accepted by topic author theberidox
‎08-26-2015 01:27 AM

Re: Problem with VPN communication between 2 NS5XTs

05.19.09   |  
‎05-19-2009 12:13 PM

Hi,

 

I would make sure the VPN is up using "get sa" from the CLI.  If the VPN is up, I would check to make sure the Policy is at the top (get pol from trust to untrust).  If it's not, the first policy would match and your traffic might not be encrypted across the tunnel.

 

-John

John Judge
JNCIS-SEC, JNCIS-ENT,

If this solves your problem, please mark this post as "Accepted Solution". Kudos are appreciated.
ScreenOS Firewalls (NOT SRX)

Re: Problem with VPN communication between 2 NS5XTs

05.19.09   |  
‎05-19-2009 12:56 PM

Sounds like a policy issue. Can you access the firewall via CLI and show the config for both side?

 

get conf | i ike

get conf | i vpn

 

and the policy as well. 

****pls click the button " Accept as Solution" if my post helped to solve your problem****
ScreenOS Firewalls (NOT SRX)

Re: Problem with VPN communication between 2 NS5XTs

05.20.09   |  
‎05-20-2009 08:17 AM

Hi Guys,

 Thank you for the help. I policys were at the bottom of the lists. I moved them to the top and now it seems to work. I would have never thought to move them. Thanks again.

 

Mike