Re: [j-nsp] Juniper Policy based VPN

2010-02-16 Thread George
How about get sa cmd All my other working tunnels are in A/U except this one in A/U and I/U as shown below. Why would be my outgoing SA be Inactive, due to this I cannot tunnel traffic to the specific host. 008d< 192.168.8.8 500 esp:a256/md5 35153af8 3533 unlim A/U 159 0 008d> 192.1

Re: [j-nsp] Juniper Policy based VPN

2010-02-15 Thread George
Hello Ali I got no output in get ike cookie cmd for the remote peer, below is the output of get sa (with IP replace). 008c< 192.168.8.8 500 esp:a256/md5 expir unlim I/I 163 0 008c> 192.168.8.8 500 esp:a256/md5 expir unlim I/I 164 0 I was reading this http://f

[j-nsp] Juniper Policy based VPN

2010-02-15 Thread George
Hello We had a Juniper policy based VPN which was initially working, all of a sudden it became intermittent and we decided to re-do it. Now after redoing it, it refused to come up even as of now. How do i sort it, and can a policy based VPN be binded to a tunnel. For the policy im using the Mapped