Solved

Juniper VPN with one site having 2 internet connections

Posted on 2009-04-09
5
408 Views
Last Modified: 2012-05-06
I am having an issue with my 2 juniper routers that i am attempting to build a vpn between.... it gets interisting in the fact that the Main site has 2 untrust networks. and the current config has worked great up until now... we have a T1 and a DSL connection coming into the main site. email and some other services come into the T1 and general browsing goes out the DSL connection. i have preference and metric set on the destination routes as you will see in the config files. here is the issue i am having, i am trying to build the VPN from the remote site into the T1 however it has a lower metric and preference than the DSL connection. i need to know how to correct what i am almost certain i setup incorrectly in the first place when i put this junipter in place. I want to thank you in advance.
Main-Clean.txt
Remote-Clean.txt
0
Comment
Question by:kn1564
  • 3
  • 2
5 Comments
 
LVL 18

Expert Comment

by:deimark
ID: 24114655
Hiya

Ok, from the main config we see the routes as follows:

set route 0.0.0.0/0 interface ethernet0/0 gateway 1.1.1.5 preference 20
set route 0.0.0.0/0 interface ethernet0/1 gateway 2.2.2.5 preference 30 metric 2 permanent
set route 192.168.11.0/24 interface tunnel.1
set route source 192.168.10.8/32 interface ethernet0/1 gateway 2.2.2.4 preference 20 permanent

To me, this looks like you have 2 default routes configured, with the main route to be used is for 1.1.1.5 and a scindary preferred route of 2.2.2.5.  If I understand you correct, we have the T1 on 1.1.1.1 and DSL on 2.2.2.2.  Is that right?

SO, form what I can see, the top 3 routes are fine (including the route based VPN on the 3rd line).  This leaves the 4th line, the source route which may be causing the issue here.

I take it when you try to establish the VPN, you are trying it from host 192.168.10.8/32?  Or are there any other hosts for this VPN?

If it is just thta host, then it is unlikely the VN will come up, as the route above, tries to send all traffic from that host out the DSL line, which has a different IP address from the 1.  This iwll result in VPN negotiations hitting the remote firewall from an unknown IP address, namely 2.2.2.2.  This may result in the VPN failing to come up.

To confirm this, try the following:

1.  Clear event logs on each firewall (please back up before you do this
      clear event
2.  In current config, try to set up the VPN, ie send traffic across it
3.  When you think the VPN has failed, on each firewall run the following comand and save the output (perhaps redirect to a TFTP host if you can, saves time)
   get event type 536
4.  Remove the source route from the firewall, ie
   unset route source 192.168.10.8/32 interface ethernet0/1 gateway 2.2.2.4
5.  Try again to bring up the vpn and again collect the logs as above on each firewall.

Basically the routes you have here are sending all traffic from 192.168.10.8/32 out through the DSL interface.

If all you want to send out the DSL interface is HTTP traffic, then policy based routing (PBR) is your freind here.

See the attached guide to assist.  The guide is for Screenos 6.2, but the other version to relate to your particular install are avail on www.juniper.net/techpubs
routing-info-screenos.pdf
0
 
LVL 1

Author Comment

by:kn1564
ID: 24115678
thank you for the responce. 1.1.1.5 is the DSL and i can establish the AutoIKE VPN perfectly 2.2.2.5 is the T1 and the VPN will not pass phase 1.   the Source route on 192.168.10.8 is nothing to worry about it is simply a mail server. if i have 1.1.1.5 in there i am unable to establish a vpn between 2.2.2.1 and 3.3.3.1 which is a site to site AutoIKE
0
 
LVL 18

Accepted Solution

by:
deimark earned 500 total points
ID: 24115822
So, so that I fully understand this:

1.1.1.1 is the T1 interface on main fw
2.2.2.2 is the DSl interface on the main fw
3.3.3.3 is the untrust interface on the remote fw

On main FW, the default route is being sent out the T1 interface, not the DSL

You are trying to bring up a VPN between the remote FW and the DSL interface on the main FW.

Is that right?

If so, run the following commands on the main firewall

get route ip 3.3.3.3
to see where the packets for your remote firewall are going.  I would suspect that they are going out via the T1, which has a diff IP, and thus the VPN is being dropped.

If the traffic is indeed going out the T1, we need to add a route to send the traffic to the remote FW out through the DSL, ie

set route 3.3.3.3 interface ethernet0/1 gateway 2.2.2.5

This should then send the traffic to the remote FW out the DSL interface.

As above, the get event type 536 will show us more specific VPN logs
0
 
LVL 1

Author Comment

by:kn1564
ID: 24117022
you my friend are a hero..... i set the route and it came right up.... YIPPY... ty *Happy Dance*
0
 
LVL 1

Author Closing Comment

by:kn1564
ID: 31568828
Thsi worked perfrect... very knowledgeable person
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Home wifi - Does it matter what router? 9 74
Configure IP on Sonicwall 2 28
Show IP BGP Information 10 48
Unable to login to Cisco C800 Ver 15.3(3)M4 8 16
Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question