Posts Tagged ‘ipsec’

To access the Secondary unit without changing HA Primary unit , which I would advise against if you are not sure of the VPN status run the following

execute ha manage 1

Login with the credentials

Then run 

diagnose vpn ike gateway

Lists all the current VPNS

diagnose vpn tunnel stat

Check how many are up


VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: 0 (from 0 votes)

SRX210[1]In configuring a IPSec site to site vpn with SRX 240 we need to set the st0/1/2 Adapters to manual address

For this I choose Subnet 30 which only gives 2 IP’s per subnet (between SRX1 and SRX2)

If you try and assign an IP in the Broadcast Address or Subnet Address wou will get

Cannot assign broadcast address as ip address


Cannot assign address 0 on subnet

Use a subnet caculator for checking these address’ and only use the values in between the Min and Max Host

VN:F [1.9.22_1171]
Rating: 9.0/10 (2 votes cast)
VN:F [1.9.22_1171]
Rating: +1 (from 1 vote)