renuka_nadkarni at YAHOO.COM
Thu Mar 8 13:00:42 EST 2001
1) Check the default route on the Netscreen-2
Your VPN is up since you can ping host1(trusted) to
I think in your case the untrusted IP address of the
other netscreen should be the default route since you
do not have a router in between.
2) in your VPN policy make sure that the host-2 IP
address does not fall in any other subnet like the
management interface or so. For eg- I have an IP
address of host-2 (22.214.171.124) same as that of
untrusted network and a management platform on the
untrusted network (126.96.36.199). Now I define host
group behind the VPN tunnel as 188.8.131.52/24). Then
the pings get lost. I have seen this happen so you
have to check VPN policy.
--- "L. David Leija" <ldl1971 at HOTMAIL.COM> wrote:
> Labsetup Visual Description:-
> Labsetup Verbal Description:-
> 2 Netscreen boxes with their untrusted interfaces
> connected with a
> cross-over cable.
> Hosts each are connected to the trusted inteface of
> each Netscreen box.
> Manual Key VPN configured between LAN1 and LAN2
> What works:-
> I can ping from Host2 to the untrusted interface of
> I can ping from Host2 to the trusted interface of
> I can ping from Host2 to the interface of Host1
> I can telnet from Host2 to the interface of Host1
> What doesn't work:-
> I cannot ping from Host1 to the untrusted interface
> of Netscreen2
> I cannot ping from Host1 to the trusted interface of
> I cannot ping from Host1 to the interface of Host2
> I cannot telnet from Host1 to the interface of Host2
> I haven't noticed anything that obvious in the
> Netscreen routing tables. If
> there were a routing problem, I doubt the icmp
> replies would find thier way
> back to Host2 on pinging Host1. Is there some policy
> issue that I'm missing?
> I can't understand why only 1/2 of the tunnel works.
> That just doesn't make
> any sense. TIA
> Get your FREE download of MSN Explorer at
> VPN is sponsored by SecurityFocus.COM
Do You Yahoo!?
Get email at your own domain with Yahoo! Mail.
VPN is sponsored by SecurityFocus.COM
More information about the VPN