Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Tunnel created but can't ping other sides

$
0
0

OK, I ran the debug on both sides, simultaneously. Our main site (192.168.1.1/24) recorded absolutely nothing to the other IP (172.16.10.1/24). However from the satellite side (172.16.10.1/24) I recorded:

   SSG140-> get db stream
   install v6 vector flow_ttl_vector
   install v6 vector flow_l2prepare_xlate_vector
   install v6 vector flow_frag_list_vector
   install v6 vector flow_fragging_vector1
   install v6 vector flow_encap_vector
   install v6 vector flow_fragging_vector
   install v6 vector flow_send_shape_vector
   ## 2017-11-02 15:33:54 : NHTB entry search not found: vpn none tif tunnel.1 nexthop 192.168.1.1
   ## 2017-11-02 15:33:54 : NHTB entry search not found: vpn none tif tunnel.1 nexthop 192.168.1.1
   ## 2017-11-02 15:33:55 : NHTB entry search not found: vpn none tif tunnel.1 nexthop 192.168.1.1
   ## 2017-11-02 15:33:55 : NHTB entry search not found: vpn none tif tunnel.1 nexthop 192.168.1.1
   ## 2017-11-02 15:33:56 : NHTB entry search not found: vpn none tif tunnel.1 nexthop 192.168.1.1
   ## 2017-11-02 15:33:56 : NHTB entry search not found: vpn none tif tunnel.1 nexthop 192.168.1.1
   ## 2017-11-02 15:33:57 : NHTB entry search not found: vpn none tif tunnel.1 nexthop 192.168.1.1
   ## 2017-11-02 15:33:57 : NHTB entry search not found: vpn none tif tunnel.1 nexthop 192.168.1.1
   ## 2017-11-02 15:33:58 : NHTB entry search not found: vpn none tif tunnel.1 nexthop 192.168.1.1
   ## 2017-11-02 15:33:58 : NHTB entry search not found: vpn none tif tunnel.1 nexthop 192.168.1.1

 

This led me to believe the NHTB entries may be incomplete, so I added the 192.168.1.1 as shown below:

   D 68.179.20.145 Site B VPN Up -
   S 192.168.1.1 Site B VPN Up Remove

I then ran the debug again with 5 pings to the destination:


  ## 2017-11-02 15:38:51 : NHTB entry search found: vpn none tif tunnel.1 nexthop 192.168.1.1 tunnelid 0x2, flag 0x0, status 4
  ## 2017-11-02 15:38:51 : NHTB entry search found: vpn none tif tunnel.1 nexthop 192.168.1.1 tunnelid 0x2, flag 0x0, status 4
  ## 2017-11-02 15:38:52 : NHTB entry search found: vpn none tif tunnel.1 nexthop 192.168.1.1 tunnelid 0x2, flag 0x0, status 4
  ## 2017-11-02 15:38:52 : NHTB entry search found: vpn none tif tunnel.1 nexthop 192.168.1.1 tunnelid 0x2, flag 0x0, status 4
  ## 2017-11-02 15:38:53 : NHTB entry search found: vpn none tif tunnel.1 nexthop 192.168.1.1 tunnelid 0x2, flag 0x0, status 4
  ## 2017-11-02 15:38:53 : NHTB entry search found: vpn none tif tunnel.1 nexthop 192.168.1.1 tunnelid 0x2, flag 0x0, status 4
  ## 2017-11-02 15:38:54 : NHTB entry search found: vpn none tif tunnel.1 nexthop 192.168.1.1 tunnelid 0x2, flag 0x0, status 4
  ## 2017-11-02 15:38:54 : NHTB entry search found: vpn none tif tunnel.1 nexthop 192.168.1.1 tunnelid 0x2, flag 0x0, status 4
  ## 2017-11-02 15:38:55 : NHTB entry search found: vpn none tif tunnel.1 nexthop 192.168.1.1 tunnelid 0x2, flag 0x0, status 4
  ## 2017-11-02 15:38:55 : NHTB entry search found: vpn none tif tunnel.1 nexthop 192.168.1.1 tunnelid 0x2, flag 0x0, status 4


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>