ezg5016
asked on
Can't Route Traffice Between 2 Branch Offices Using Netscreen Routers
I have inherited a network consisting of a main operation office and 2 branch offices. For conectivity, the main office uses a Juniper Networks Netscreen NS-25 and the branch offices use Netscreen NS5XP & NS5GT. By looking at the existing policies I can see that the main office is connected to each branch office via VPN tunnel. At the main office I can ping each branch office and vice versa, however while at branch office 1, I cannot ping branch office 2.
I'm sure that what I am trying to do is possible, I just am too unfamiliar with JUNOS. Essentially I would like to do this: Route traffic between 2 branch offices using the main office as a go between. Consider this diagram of the current network:
Branch 1 <----VPN----> Main Branch 2 <----VPN----> Main
(dedicated IP on both public sides) (Dynamic IP at Branch 2)
I would like to accomplish the following:
Branch1 <---- Main ----> Branch2
Any suggestion would greatly be appreciated.
I'm sure that what I am trying to do is possible, I just am too unfamiliar with JUNOS. Essentially I would like to do this: Route traffic between 2 branch offices using the main office as a go between. Consider this diagram of the current network:
Branch 1 <----VPN----> Main Branch 2 <----VPN----> Main
(dedicated IP on both public sides) (Dynamic IP at Branch 2)
I would like to accomplish the following:
Branch1 <---- Main ----> Branch2
Any suggestion would greatly be appreciated.
ASKER
From Branch office 1 segment (192.168.253.1/24) I can ping main office segment (10.1.1.1/24) and vice versa. Same holds true for Branch office 2. Server farm lives in the main office segment so both branches can ping within.
We installed a data collection device within the branch office 2 segment (10.3.1.1/24) but the data monitoring software is installed at the Branch office 1 segment.
I hope this helps.
We installed a data collection device within the branch office 2 segment (10.3.1.1/24) but the data monitoring software is installed at the Branch office 1 segment.
I hope this helps.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Thank you all. I have been away on special project and am revisiting this issue later this afternoon. I will keep you posted
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
What are you pinging at branch office 2? Hopefully it is something inside and not the VPN termination point?
harbor235 ;}