Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    wan -- pfsense -- Juniper SRX ipsec not working.

    Scheduled Pinned Locked Moved NAT
    19 Posts 4 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      Konstanti @virtualliquid
      last edited by

      @virtualliquid
      Hey
      and what device is trying to connect to Juniper ?
      Very strange, src port = 4500 / dst port random (or missing)

      1 Reply Last reply Reply Quote 0
      • V
        virtualliquid
        last edited by

        I am not certain of the device on the other end it is one of our large data centers that host multiple vpn concentrators. I would imagine it is just another juniper on the other end as well.

        K 1 Reply Last reply Reply Quote 0
        • K
          Konstanti @virtualliquid
          last edited by

          @virtualliquid

          Who initiated the connection ?
          Little Juniper or big ?
          It feels like PF is blocking traffic for the little Juniper that is going back

          V 1 Reply Last reply Reply Quote 0
          • V
            virtualliquid
            last edited by virtualliquid

            took a new capture, same results. just filtered the source ip (office)
            Every other one is the source of 4500 going to destination 39727 or some other random port.

            alt text

            1 Reply Last reply Reply Quote 0
            • V
              virtualliquid @Konstanti
              last edited by

              @konstanti Little Juniper I believe initiates the connection. Since I keep restarting it (Power cycle)

              K 1 Reply Last reply Reply Quote 0
              • K
                Konstanti @virtualliquid
                last edited by Konstanti

                @virtualliquid
                Try so
                /diagnostics/command prompt/ cat /tmp/rules.debug | grep LAN
                and check.
                is there a keep state when outputting
                for example,

                pass in quick on $LAN inet from YOUR__LAN_NET to any tracker 0100000101 keep state label "USER_RULE: Default allow LAN to any rule"

                1 Reply Last reply Reply Quote 0
                • V
                  virtualliquid
                  last edited by virtualliquid

                  there is a lot of keep states, might need to filter more.

                  Perhaps this rule ?

                  pass in quick on $WAN reply-to ( em0 xxx.xxx.xxx.1 ) inet proto { tcp udp } from any to 10.1.4.10 port 4500 tracker 1549481406 keep state label "USER_RULE: NAT Juniper SRX"

                  K 2 Replies Last reply Reply Quote 0
                  • K
                    Konstanti @virtualliquid
                    last edited by

                    @virtualliquid

                    1. Are there floating rules ?
                    2. For a small Juniper is there a separate rule on the Lan interface ?
                      If yes , show it
                      If not , show the rules of the LAN nterface
                    1 Reply Last reply Reply Quote 0
                    • K
                      Konstanti @virtualliquid
                      last edited by Konstanti

                      @virtualliquid

                      cat /tmp/rules.debug | grep LAN
                      not WAN !!!
                      pass in quick on $LAN inet from YOUR__LAN_NET to any tracker 0100000101 keep state
                      or
                      pfctl -sr | grep em1
                      for example,
                      pass in quick on em1 inet from LAN_NET_IP to any flags S/SA keep state label "USER_RULE: Default allow LAN to any rule"

                      1 Reply Last reply Reply Quote 0
                      • V
                        virtualliquid
                        last edited by

                        Trying to post the output, but it keeps telling me its spam.

                        1 Reply Last reply Reply Quote 0
                        • V
                          virtualliquid
                          last edited by

                          Best I can do is a picture of the output.

                          alt text

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.