Link to home
Start Free TrialLog in
Avatar of ezg5016
ezg5016

asked on

Can't Route Traffice Between 2 Branch Offices Using Netscreen Routers

I have inherited a network consisting of a main operation office and 2 branch offices. For conectivity, the main office uses a Juniper Networks Netscreen NS-25 and the branch offices use  Netscreen NS5XP & NS5GT. By looking at the existing policies I can see that the main office is connected to each branch office via VPN tunnel. At the main office I can ping each branch office and vice versa, however while at branch office 1, I cannot ping branch office 2.

I'm sure that what I am trying to do is possible, I just am too unfamiliar with JUNOS. Essentially I would like to do this: Route traffic between 2 branch offices using the main office as a go between. Consider this diagram of the current network:

Branch 1 <----VPN----> Main                              Branch 2 <----VPN----> Main
(dedicated IP on both public sides)                   (Dynamic IP at Branch 2)

I would like to accomplish the following:

Branch1 <---- Main ----> Branch2

Any suggestion would greatly be appreciated.
Avatar of harbor235
harbor235
Flag of United States of America image



What are you pinging at branch office 2? Hopefully it is something inside and not the VPN termination point?


harbor235 ;}
Avatar of ezg5016
ezg5016

ASKER

From Branch office 1 segment (192.168.253.1/24) I can ping main office segment (10.1.1.1/24) and vice versa. Same holds true for Branch office 2. Server farm lives in the main office segment so both branches can ping within.

We installed a data collection device within the branch office 2 segment (10.3.1.1/24) but the data monitoring software is installed at the Branch office 1 segment.

I hope this helps.
ASKER CERTIFIED SOLUTION
Avatar of thechaosrealm
thechaosrealm
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of ezg5016

ASKER

Thank you all. I have been away on special project and am revisiting this issue later this afternoon. I will keep you posted
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial