ScreenOS Firewalls (NOT SRX)
ScreenOS Firewalls (NOT SRX)

ssg20 routing problem

[ Edited ]
‎12-02-2019 06:34 AM

Hello everyone,

 

I am new to Juniper, I hope someone can help me solve this problem.  Below is the network diagram of my environment.  I have established a policy based VPN connection from Site1 to Site2.  I would like to access Trust ethernet 0/2 from Site1 to Zone2 in Site2 and vice versa.  Any help is much appreciated.  Thanks.

Juniper network.JPG

3 REPLIES 3
ScreenOS Firewalls (NOT SRX)

Re: ssg20 routing problem

‎12-02-2019 08:40 AM

Please check if these will help:

https://kb.juniper.net/InfoCenter/index?page=content&id=KB6210

https://kb.juniper.net/InfoCenter/index?page=content&id=KB4757&actp=METADATA

https://kb.juniper.net/InfoCenter/index?page=content&id=KB15074

 

Hope this helps.

Regards,
-r.

--------------------------------------------------

If this solves your problem, please mark this post as "Accepted Solution."
Kudos are always appreciated Smiley Happy.

ScreenOS Firewalls (NOT SRX)

Re: ssg20 routing problem

[ Edited ]
‎12-02-2019 08:49 AM

Hi mriyaz,

 

Thanks for the reply.

As mentioned in my post, I already have the VPN established in my envrionment. I can access Trust from Site1 to Trust in Site2.  What I need is to access Trust from Site1 to Zone2 in Site2.

Juniper network2.JPG

 

 

Got it to work.  I needed to create two more policies.

ScreenOS Firewalls (NOT SRX)

Re: ssg20 routing problem

‎12-02-2019 05:23 PM

For policy based vpn you need to have two separte tunnel enabled polcies adding one on both sides for the new ip address pair.

 

Locate your tunnel policy from 192.168.11.0/24 to 192.168.1.0/24

Create another policy with the same zone to zone designation using the new pair 192.168.11.0/24 to 172.16.2.0/16

The action needs to be tunnel and a pair policy

move this policy in the order to be right next to the current policy

 

This will need to be done on both SSG20

 

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home