Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Problems dynamincally routing down VPN tunnel

Status
Not open for further replies.

fatkid

Programmer
Feb 26, 2002
11
US
As a test in preperation for setting things up on a larger scale, I have set up a VPN between two netscreen 5gt's that is terminated in the untrust zone on each end. I have turned on OSPF routing, but I am unable to see any routes populate between the two firewalls. If I terminate in the trust zones the routes populate. Is there something that I am missing to be able to do this from the untrust zones?
 
Hello,

Did you use tunnel interfaces? If so, which VR are they bound to?

Let me know.

Rgds,

John
 
Hi John,
I did use tunnel interfaces.
tunnel.1 is terminated in the untrust-vr on both firewalls.
tunnel.2 is terminated in the trust-vr on both firewalls.
When I am using tunnel.1 I dynamic ospf routing doesn't populate the routing table.
When I am going down tunnel.2 in the trust-vr dynamic ospf routing works just fine.

Bob
 
Hi Bob,

Can you try tunnel.1 and post the output from:

get ike cookie
get sa
get vr untrust-vr route proto ospf detail
get vr untrust-vr route proto ospf ne
get int tun.1

Rgds,

John
 
Hi John
I will do that as soon as I get another firewall back. One of mine has been used to replace a failed production firewall. I'll have another one tomorrow or the next day.

Thank you,

Bob
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top