Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: SSG140 Site to Site VPN with ASA Multiple Subnets

$
0
0

You will need to verify that these configuration objects are the same on the ASA and the SSG.  These need to contain

 

Proxy-id on the SSG

ACL for the VPN on the ASA

192.168.70.0/24 - 192.168.50.0/24 
192.168.70.0/24 - 10.10.0.0/16 

Then confirm routing:

SSG needs a static route to the tunnel interface for both remote networks

192.168.50.0/24 & 10.10.0.0/16

 

Cisco router B needs a static route to 192.168.70.0/24 to cisco router A

Cisco router A needs a static route to 192.168.70.0/24 to the ASA

 

Confirm a security policy allows from your local subnet to the tunnel interface zone on the VPN

 

Confirm the VPN is active:

SSG

get ike

get sa

 

If VPN is not up

https://kb.juniper.net/InfoCenter/index?page=content&id=KB9221

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>