Junos OS

Expand all | Collapse all

Trouble with Policies Not Working

Jump to Best Answer
  • 1.  Trouble with Policies Not Working

    Posted 10-08-2019 08:07

     

     

    h



  • 2.  RE: Trouble with Policies Not Working
    Best Answer

     
    Posted 10-08-2019 08:39

    Hi,

     

    Assuming I've been able to follow the topology from the config correctly, appears to me there's an inconsistency with the inet addresses configured on ge-0/0/1 & ge-0/0/2, the security zones and the address book.

     

    For instance ge-0/0/1 is configured with .68, under zone FR but in address-book is SLS. The 1st policy is looking for src address FR (.50) coming into zone FR, whereas the traffic would be the opposite.

     

    ge-0/0/1.0    .68    Zone: FRZone
    ge-0/0/2.0 .50 Zone: SLSZone


    Address-Books:
    FR: 192.168.0.50
    SLS: 192.168.0.68

    You might need to reverse either the policy & zones or the interface addressing, the latter being the easier I believe.

     

    Also the interface addressing overlaps, although that might not contribute to the problem in this case as they are directly connected interfaces.

     

    Hope this helps.

     

    Cheers, 

    Ashvin