Answer the question
In order to leave comments, you need to log in
Racoon - Juniper SRX and Redundant IPSEC
You need to set up a fallback IPSEC between the Ubuntu server running Racoon and the Juniper SRX router. There are 2 Internet channels on the router in the office. An IPSEC tunnel is now configured between the office and the server through the main Internet channel of the office.
The problem is that setkey complains that its policy is to encrypt the same subnets for two remote peers, and it ignores the configuration of the second tunnel.
Previously, I configured the same only between “iron” routers (cisco-cisco, juniper-cisco) - everything is simple here: from the side where there are 2 channels - a cryptomap is hung on both external interfaces, from the side where there is 1 channel - 2 peers are simply indicated in the cryptomap.
Nobody faced a similar problem, what solutions can be?
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question