Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
chanthar_tak
Explorer

Site to Site VPN between Quantum Spark and 3rd party Juniper SRX

We are doing a Site to Site VPN Route based Preshared key- between 3rd party firewall (Static IP) and  Quantum spark (Dynamic IP with SIM card)

Although Phase1 and Phase 2 is up, traffic is not passing through IPSec tunnel. We have configured everything Security Policies. and showing policy hit counts at 3rd party firewall site. But still no traffic passing. checking with TAC doesn't resolve the issue yet and they point ISP might have a problem.

Did anyone have experiences similar scenarios - Dynamic IP at Quantum spark side? If so, can you share working configuration ? Because I think there might be configuration issue or compatibility issue at QS side. 

0 Kudos
3 Replies
Lesley
Mentor Mentor
Mentor

How would the remote party 'know' if the dynamic IP on your side changes? Does the ISP allow ESP (50) , 4500 and UDP500? I would assume so, because p1 and p2 is up. Check this with tcpdump -> tcpdump -nni any host X.X.X.X 

x.x.x.x is remote peer IP. Ask them to send traffic or you send traffic. You need to see encrypted ESP traffic and IKE500. If you see traffic incomming from remote peer you know ISP allows traffic.

Would recommend static IP. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
chanthar_tak
Explorer

We configured hostname on QS so SRX can identify IKE aggressive peer ID. SRX has existing dynamic IPsec tunnels so we can assume ISP allow IKE traffic.

At QS side, we need to use dynamic IP because will use SIM card. 

Is it possible QS has compatibility issue with dynamic IPsec? 

 

0 Kudos
chanthar_tak
Explorer

I forgot to mention when we check TCP dump we don't see reply packets at QS. At SRX side, we verified it has replied decrypted packets. Also, we are seeing Phase1 is established on SRX with random port from checkpoint.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events