Hi Spuluka / everyone,
Here is the issue I now have:
This is all on the same physical SRX300:
CPE 192.168.20.2/30 --> SRX300-ge-0/0/4.0 - 192.168.20.1/30 --> SRX300 irb.10 - 10.10.10.1/30 --> Core 10.10.10.2/30
So, here is what can be achieved successfully:
ping from SRX300, source ge-0/0/4, to Internet 8.8.8.8 - Successful
ping from CPE to 8.8.8.8 - unsuccessful
ping from SRX300, source irb.10 to CPE - unsuccessful
ping from srx300 direct to CPE - successful
Given that I can ping the internet from source port on the same network as the CPE but cannot ping the internet from the CPE, maybe the following is happening (but I am asking to confirm):
Interface irb.10 is a VLAN, albeit with an interface address. So, as the packets are being tagged on their way out, I'm going to say a layer 2 VLAN (I have proved the tagging with a monito traffic interface, command).
As I cannot ping the internet from the CPE I am wondering if the following occurs:
I ping from the actual SRX, with a source of ge-0/0/4, to 8.8.8.8 and it works. From the CPE connected to this port it does not work (but I can ping the ge-0/0/4 interface). This leads me to believe (maybe) that when I ping directly from the SRX the system already knows that the packet needs to be tagged and so therefore will send it across the VLAN. When a packet from the CPE enters the ge-0/0/4 interface, it is at Layer 3 and therefore the packet will not get tagged with any VLAN information. Has anyone seen this before and if so, how did they get around it?