Re: [j-nsp] ICMP from SRX accross policy vpn tunnel

2019-05-09 Thread Craig Askings
Alternative solution. Keep doing route based tunnels, but use traffic selectors. I use it to have the remote end doing policy based ipsec (old cisco cpe as an example) while keeping the SRX as a route (st interface) based ipsec implementation. https://www.juniper.net/documentation/en_US/junos/topi

[j-nsp] ICMP from SRX accross policy vpn tunnel

2019-05-08 Thread Lenny Shovsky
Wondering how to get ping to work directly from SRX across ipsec policy tunnels. Have no issues dong it with route based tunnels, simply using lo0 with tunneled subnet address and default-address-selection option, but can't make it work with policy tunnels. Long term goal is to get vpn-monitor op