Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Route based IPSEC VPN Config between SSG-550M and Cisco ASA

$
0
0

Hi,

 

If your query is about A/D then please cehck below from KB :https://kb.juniper.net/InfoCenter/index?page=content&id=KB6134&actp=METADATA 

 

A/D: VPN tunnel is Active, but the link (detected thru VPN Monitor) is DOWN. VPN Monitor is not getting a response to its pings.  This could be happening because the device that is being pinged is down or has ping disabled.  This could also be happening if the other side of the VPN is not a NetScreen/Juniper Firewall.

 

If you are using not ScreenOS device then please configure VPN monitor with IPs which can ping each other, or need not to use it.

https://kb.juniper.net/InfoCenter/index?page=content&id=KB8530&cat=IPSEC&actp=LIST

 

To enable PFS you need to configure  DH group instead of no-pfs in your phase-2 proposal.

 

Thanks,

Vikas

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>