Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    wan -- pfsense -- Juniper SRX ipsec not working.

    Scheduled Pinned Locked Moved NAT
    19 Posts 4 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      virtualliquid
      last edited by

      Not sure if I am doing something wrong or this is bugged.

      I have tried all these suggestions to no avail.

      Created a 1:1 nat with the outside IP and internal device IP.
      Also created port forward rules for 4500, 500, ah and esp to be sure I am completely covered. Still no luck. I do however see port 4500 continuously hitting my firewall block logs as if it does not have a rule telling it where to go, but I have one setup for it.
      firewall log below. It is coming from my remote work off and going to my external WAN IP in the below picture.. Edited out for obvious reasons.

      alt text

      K 1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Post your port forwards and rules. That traffic is obviously not being passed by a firewall rule or a state.

        Your NAT rule posted up there had source port 4500. You don't want that. The source port is random.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • V
          virtualliquid
          last edited by virtualliquid

          I had to re-do the rules since I wiped everything to start fresh. I currently have ESP and AH disabled in the screenshots.

          but here is what I got.

          NAT Rules
          4500

          alt text

          alt text
          and the associated firewall rule.
          alt text

          Nat rule for port 500
          alt text

          Associated rule for 500
          alt text

          1 Reply Last reply Reply Quote 0
          • K
            Konstanti @virtualliquid
            last edited by

            @virtualliquid
            Hey
            and what device is trying to connect to Juniper ?
            Very strange, src port = 4500 / dst port random (or missing)

            1 Reply Last reply Reply Quote 0
            • V
              virtualliquid
              last edited by

              I am not certain of the device on the other end it is one of our large data centers that host multiple vpn concentrators. I would imagine it is just another juniper on the other end as well.

              K 1 Reply Last reply Reply Quote 0
              • K
                Konstanti @virtualliquid
                last edited by

                @virtualliquid

                Who initiated the connection ?
                Little Juniper or big ?
                It feels like PF is blocking traffic for the little Juniper that is going back

                V 1 Reply Last reply Reply Quote 0
                • V
                  virtualliquid
                  last edited by virtualliquid

                  took a new capture, same results. just filtered the source ip (office)
                  Every other one is the source of 4500 going to destination 39727 or some other random port.

                  alt text

                  1 Reply Last reply Reply Quote 0
                  • V
                    virtualliquid @Konstanti
                    last edited by

                    @konstanti Little Juniper I believe initiates the connection. Since I keep restarting it (Power cycle)

                    K 1 Reply Last reply Reply Quote 0
                    • K
                      Konstanti @virtualliquid
                      last edited by Konstanti

                      @virtualliquid
                      Try so
                      /diagnostics/command prompt/ cat /tmp/rules.debug | grep LAN
                      and check.
                      is there a keep state when outputting
                      for example,

                      pass in quick on $LAN inet from YOUR__LAN_NET to any tracker 0100000101 keep state label "USER_RULE: Default allow LAN to any rule"

                      1 Reply Last reply Reply Quote 0
                      • V
                        virtualliquid
                        last edited by virtualliquid

                        there is a lot of keep states, might need to filter more.

                        Perhaps this rule ?

                        pass in quick on $WAN reply-to ( em0 xxx.xxx.xxx.1 ) inet proto { tcp udp } from any to 10.1.4.10 port 4500 tracker 1549481406 keep state label "USER_RULE: NAT Juniper SRX"

                        K 2 Replies Last reply Reply Quote 0
                        • K
                          Konstanti @virtualliquid
                          last edited by

                          @virtualliquid

                          1. Are there floating rules ?
                          2. For a small Juniper is there a separate rule on the Lan interface ?
                            If yes , show it
                            If not , show the rules of the LAN nterface
                          1 Reply Last reply Reply Quote 0
                          • K
                            Konstanti @virtualliquid
                            last edited by Konstanti

                            @virtualliquid

                            cat /tmp/rules.debug | grep LAN
                            not WAN !!!
                            pass in quick on $LAN inet from YOUR__LAN_NET to any tracker 0100000101 keep state
                            or
                            pfctl -sr | grep em1
                            for example,
                            pass in quick on em1 inet from LAN_NET_IP to any flags S/SA keep state label "USER_RULE: Default allow LAN to any rule"

                            1 Reply Last reply Reply Quote 0
                            • V
                              virtualliquid
                              last edited by

                              Trying to post the output, but it keeps telling me its spam.

                              1 Reply Last reply Reply Quote 0
                              • V
                                virtualliquid
                                last edited by

                                Best I can do is a picture of the output.

                                alt text

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.