Posts Topics Forums Images
Search videos from message boards Videos Search messages from microblogs Microblogs Search messages from imdb.com Imdb Search messages from yuku.com Yuku Search messages from lefora.com (free forums) Lefora
My account: Login | Sign Up
Loading... 

Thread: One Question with the port status of Juniper Firew... - J-Net Community

Started 1 month, 2 weeks ago by blueseabin
Hi, there;   There is one question with the port status of Juniper NetScreen Firewall. The firewall has one ethernet port (10M/100M) connected with the CISCO Switch. in the Switch side the interface shows:   GigabitEthernet1/0/2 is up, line protocol is up (connected)   However, in the Firewall parts: the Box is powered off. Could the Physical and Line protocol still be detected as up ?  ...
Site: Forums - J-Net Community  Forums - J-Net Community - site profile
Forum: Firewalls  Firewalls - forum profile
Total authors: 172 authors
Total thread posts: 2 posts
Thread activity: 62 new posts during last week
Domain info for: juniper.net

Other posts in this thread:

pacmagsjfw replied 2 years, 1 month ago
Anyone can help me to explain this alert please? [00001] 2007-11-09 12:52:23 [Root]system-alert-00026: IPSec tunnel on interface ethernet3/2 with tunnel ID 0x30 received a packet with a bad SPI. 139.130.*.*->202.122.*.*/128, ESP, SPI 0x4a6471e9, SEQ 0x1. What does it mean by bad SPI? It seems like the VPN tunnel is working fine even this alert appears

rkim replied 2 years, 1 month ago
Are you seeing these messages about once every hour on the hour?  If so then this could mean that both peers attempted to rekey at the same time due to phase 2 lifetime default of 1 hour.  During this time there could be a very brief moment where both peers may be sending different SPI values.  Once phase 2 rekey completes then the messages go away.  One way to prevent this is to adjust IKE soft...

pacmagsjfw replied 2 years, 1 month ago
Thanks, it's acceptable if the two side are negotiating. But the time it happened is unpredictable Date / Time Level Description 2007-11-11 03:15:57 alert IPSec tunnel on interface ethernet3/2 with tunnel ID 0x1a received a packet with a bad SPI. 139.130.*.*->202.122.*.*/136, ESP, SPI 0xc57971e9, SEQ 0x1. 2007-11-09 12:52:23 alert IPSec tunnel on interface ethernet3/2 with tunnel ID 0x30 ...

rkim replied 2 years, 1 month ago
Is the other side a NetScreen/SSG device? If so is either side using VPN monitoring? If one side is then try enabling VPN monitoring with rekey on both sides and see if you still see the same problem. Otherwise you may need to capture via sniffer and/or snoop along with debug ike detail the failing error condition. If you still see issues or are unable to enable VPN monitoring then I'd recommend...

ModelCitizen replied 1 year, 10 months ago
We too receive Bad SPI messages, i.e. 2008-02-01 14:12:42 Local0.Alert 192.168.168.3 ns5gt: NetScreen device_id=ns5gt [Root]system-alert-00026: IPSec tunnel on int untrust with tunnel ID 0x3 received a packet with a bad SPI. 88.97.***.***->81.3.**.**/**, ESP, SPI 0xe7af, SEQ 0x1 (2008-02-01 14:25:28)000> (Note: IP address replaced with *'s for security reasons). We only one have bad SPI entry ...

ppaiva replied 1 year, 10 months ago
Anyone have any experience setting up Xbox Live access on the SSG 5?  I have all the ports open as suggested by Microsoft but sometimes it takes forever for the Xbox live connections to occur (connecting with other players, etc.)

PentinProcessor replied 1 year, 9 months ago
The Juniper firewalls do not have an Application Layer Gateway (ALG) for xbox. Are these the ports you opened up? http://support.microsoft.com/kb/911728 If so, the next time you encounter the slow connection, try clearing the sessions related to the xbox using the 'clear session' command.  If you enter clear session ?, you can see the different options to clear by. It may be easier to do it by ...

dcruz replied 1 year, 9 months ago
Have you enabled Multi-port VIP?  What is the result for NAT when you run a connection test on the XBox?  I had to enable multi-port VIP and forward the necessary ports listed in the KB to get an "Open" result.

JoeKim13 replied 1 year, 9 months ago
ScreenoS 5.4 and 6.0   All i had to do was allow an outbound any from the xbox and it works great no vip or inbound rules. In addtion i had to tweak the source ip based session limit, udp flood protection a bit.   http://support.microsoft.com/kb/908874   Try doing a debug or if it still doesn't work

dcruz replied 1 year, 9 months ago
So when you do a connection test within Live!, what does your NAT status come up as?  I found that I couldn't get it to be open unless I forwarded the ports over.   What did you tweak exactly?  I'm always getting alerts after I play  

 

Top contributing authors

Name
Posts
arizvi
71
user's latest post:
Nokia Mobile VPN - J-Net Community
Published (2009-12-09 15:05:00)
Hi,   Please make sure the VPN are UP by following commad:   get sa get ike coo get event   IF the VPN is UP , then run the following debugswhich could help us to find the clue of the issue: 1) set ff src-ip x.x.x.x 2) set ff dst-ip x.x.x.x 3) debug flow basic 4) clear db   NOW run the test   4) Press "ESC" to turn off the debug 5) get db s     Thanks Atif
muttbarker
23
user's latest post:
DMZ Setup issues - J-Net Community
Published (2009-11-27 08:31:00)
OK - Dumb question time - did you configure the DMZ I/F to allow for ping?
Cesar
19
user's latest post:
SSH Hash MAC failure with ISG...
Published (2009-11-16 13:57:00)
Can you issue debug ssh all cl db <Start SSH session> get db str
klwong
15
user's latest post:
Need a continuous ping to keep...
Published (2009-11-24 00:02:00)
Last and final, I changed the firewall to fix the problem !!!
TSG
13
user's latest post:
Ping connection to DMZ host. -...
Published (2009-12-03 09:16:00)
Hi there policy is as follows   Trusted -DMZ Source ANY Destination ANY Service ICMP ANY.   DMZ-Trusted Source ANY Destination ANY Service ICMP ANY.   Paul  
SSHSSH
13
user's latest post:
Dual firewall question. - J-Net...
Published (2009-12-07 05:51:00)
can you post policies & routes &policies you added at both firewalls to allow the communication ?
mehdi
12
user's latest post:
Best Practice for changing...
Published (2009-11-27 07:08:00)
hi dkrut i have met the same situation, last mounth, i have  did that :  I have dowload the config files for the both devic, after that i have opned it with winmerge application for editing the files , i have replaced only  old  ip address to new ip address  for iterfaces untrust "IP ISP" and all mip and vip. and after that i  compared the old file and  a  new file with Winmerge application.   after i injected the new file...
blueseabin
12
user's latest post:
Can not set the DHCP server IP...
Published (2009-12-09 23:27:00)
Dear ALL:   Try to config the DHCP IP range in the Interface 1 (NS25 + 5.4.r10), however, the command cannot be implemented in the interface eth1:   set interface ethernet0/1 dhcp server ip 172.16.10.10 to 172.16.10.19   error message : Failed command - set interface ethernet1 dhcp server ip 172.16.10.10 to 172.16.10.19   Thanks for any suggestion. BTW, The other command related with interface eth1 could work very well.        
link2ali
11
user's latest post:
VPN Redundancy Using BGP - J-Net...
Published (2009-12-06 23:59:00)
Hi,   So is it that the VPN will terminate on the Tunnel Interface and is it mandaroty to have a numbered tunnel interface,if yes can you help in guiding the reason for the same..?     Regards Ali  
Screenie
11
user's latest post:
VIP Setup Issue for HTTP Port...
Published (2009-12-07 14:09:00)
Can you run a debug on it?   set ff dst-ip <IP VIP> debug flow basic >>>  traffic to the VIP undebug all (or ESC when you don't like typing ) get db stream   It might give an idea what's going on.

Related threads on "Forums - J-Net Community":

Related threads on other sites:

Thread profile page for "One Question with the port status of Juniper Firew... - J-Net Community" on http://www.juniper.net. This report page is a snippet summary view from a single thread "One Question with the port status of Juniper Firew... - J-Net Community", located on the Message Board at http://www.juniper.net. This thread profile page shows the thread statistics for: Total Authors, Total Thread Posts, and Thread Activity