Screen OS

last person joined: 8 months ago 

This is a legacy community with limited Juniper monitoring.
  • 1.  SSG5 - 2 sites 2 tunnels 1 for voice 1 for data. Ideas?

    Posted 09-28-2008 18:00

    How do I get this working?

    I have the tunnels setup on seperate ADSL services however I can't get both tunnels to open at the same time.

    I have some PBR setup so that all trafic to or from a specific address should go via tunnel 2 but it all still goes by tunnel 1.

    Tunnel 2 doesn't even attempt to establish until I unlug tunnel 1 or disable the port.

     

    Both tunnels are unnumbered.

    Both go to the same physical location.

    Both go to from the same subnets.

    2 routes configured in destination routing. Preferences tunnel 1 : 40 Tunnel 2 : 20.

    PBR to send some trafic to tunnel 1

    Two seperate adsl services and sets of static IP's.

     

    Essentially in the end I want to be sending voice trafic down tunnel 1 and everything else down tunnel 2.

     

    Suggestions and Help?



  • 2.  RE: SSG5 - 2 sites 2 tunnels 1 for voice 1 for data. Ideas?
    Best Answer

    Posted 10-01-2008 06:58

    The reason both tunnels are not up at the same time is because of the preference that you have given them. They are setup to failover if tunnel 2 (preference 20) goes down then and only then will tunnel 1 (preference 40) take over. I believe you if you setup a second network on your remote site, have it use your VOIP application, and have that new network use tunnel 1 things will work. I would change the preference too 20 again. The other thing I would do is to put in a second route statement for each to the other tunnel with a higher preference.

     

    Example:

    192.168.10.0 tunnel 1 preference 20

    192.168.10.0 tunnel 2 preference 30

     

    192.168.20.0 tunnel 2 preference 20

    192.168.20.0 tunnel 1 preference 30

     

    This way if one of your ISP goes down the traffic will go to the other tunnel. You need to do some configuration on the LAN to make the failover work but it is possible.