ScreenOS Firewalls (NOT SRX)
ScreenOS Firewalls (NOT SRX)

ssg20 routing problem

[ Edited ]
a week ago

Hello everyone,

 

I am new to Juniper, I hope someone can help me solve this problem.  Below is the network diagram of my environment.  I have established a policy based VPN connection from Site1 to Site2.  I would like to access Trust ethernet 0/2 from Site1 to Zone2 in Site2 and vice versa.  Any help is much appreciated.  Thanks.

Juniper network.JPG

3 REPLIES 3
ScreenOS Firewalls (NOT SRX)

Re: ssg20 routing problem

a week ago

Please check if these will help:

https://kb.juniper.net/InfoCenter/index?page=content&id=KB6210

https://kb.juniper.net/InfoCenter/index?page=content&id=KB4757&actp=METADATA

https://kb.juniper.net/InfoCenter/index?page=content&id=KB15074

 

Hope this helps.

Regards,
-r.

--------------------------------------------------

If this solves your problem, please mark this post as "Accepted Solution."
Kudos are always appreciated Smiley Happy.

ScreenOS Firewalls (NOT SRX)

Re: ssg20 routing problem

[ Edited ]
a week ago

Hi mriyaz,

 

Thanks for the reply.

As mentioned in my post, I already have the VPN established in my envrionment. I can access Trust from Site1 to Trust in Site2.  What I need is to access Trust from Site1 to Zone2 in Site2.

Juniper network2.JPG

 

 

Got it to work.  I needed to create two more policies.

ScreenOS Firewalls (NOT SRX)

Re: ssg20 routing problem

a week ago

For policy based vpn you need to have two separte tunnel enabled polcies adding one on both sides for the new ip address pair.

 

Locate your tunnel policy from 192.168.11.0/24 to 192.168.1.0/24

Create another policy with the same zone to zone designation using the new pair 192.168.11.0/24 to 172.16.2.0/16

The action needs to be tunnel and a pair policy

move this policy in the order to be right next to the current policy

 

This will need to be done on both SSG20

 

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home