Solved

Juniper Netscreen L2L VPN with Public IP Addresses

Posted on 2013-05-20
7
761 Views
Last Modified: 2013-06-10
I have a requirement to implement multiple VPN L2L tunnels to a number of different peers.

Some of the resources behind my side of the VPN will need to be accessed by several of the remote sites.

To avoid same-private-subnet issues a number of the peers that I need to connect to insist on having pubic IP NATs applied to the hosts to be accessed on either side of the tunnel.

I can set this up with no issues on my Cisco ASA. I just setup the static NAT for each host that needs to be accessed over a tunnel and then apply whatever access rules are needed per tunnel in the interface and crypto ACLs.

This seems to be an issue, however, on the Juniper.

It seems that, on the Juniper, once a host has been NAT'd to a public IP and applied to a tunnel it cannot be applied to another tunnel. This means that those resources on my side of the VPN that need to be shared by multiple peers can only be accessed by one peer.

Is this correct ? Is there no way around this ?

If this is correct it would appear to be a fairly fundamental issue with regard to the functionality of this kit.

TIA.
0
Comment
Question by:ccfcfc
  • 3
  • 2
  • 2
7 Comments
 
LVL 18

Expert Comment

by:Sanga Collins
ID: 39181538
With juniper devices you can use a Dynamic IP pool (DIP) to assign IPs to be NATd to private network servers and devices. This will get around the limitations of using a MIP.
0
 

Author Comment

by:ccfcfc
ID: 39181557
sangamc,

Thanks for the quick response.

Can you point me at any info on this ? I am from the Cisco world and am new to Juniper so any relevant how-to or configuration example would be really useful.

Thanks.
0
 
LVL 18

Accepted Solution

by:
Sanga Collins earned 350 total points
ID: 39181574
here is the KB article for DIP pool on juniper devices with ScreenOS. If you have an srx serise device thats running Junos firmware, let me know and I will post the KB article for DIP configurations.

http://kb.juniper.net/InfoCenter/index?page=content&id=KB4748
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 69

Assisted Solution

by:Qlemo
Qlemo earned 150 total points
ID: 39181624
Are you are using different public IPs for each server, or perform port forwarding on one or a few public IPs?

DIPs only work as source address, that is for outgoing traffic. This needs to be set up in the respective policy. You would have to combine that with a incoming policy applying destination NAT. This allows for a bidrectional communication, if necessary.

VIPs only work for incoming traffic, and are used commonly for port-mapping.

MIPs implement 1:1 NAT.

Having said that, what your peers demand is nonsense. It makes sense to map to another private network, but usually only one party has to do that. It also makes sense to use a "transfer network" type of translation on both sides - this can be done on your side with either MIPs or DIPs and appropriately set up policies, as described above.
0
 
LVL 18

Expert Comment

by:Sanga Collins
ID: 39181672
I had some concerns about what the remote site admin was asking as well, but didn't want to step on any toes inadvertently.
0
 

Author Comment

by:ccfcfc
ID: 39181735
I agree on the issue of the requirement for Public IP address utilisation. However, when you are dealing with huge global organisations and that is their policy it can be difficult to get them to change it.
0
 
LVL 69

Expert Comment

by:Qlemo
ID: 39181758
Well, public IPs are likely to collide with not yet used public IPs ;-) IPv4 doesn't allow for many "free" IP addresses any more.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question