Forum Discussion

Joe_48617's avatar
Joe_48617
Icon for Nimbostratus rankNimbostratus
Jul 18, 2012

F5 and Juniper SSL-VPN

We are setting up our new Juniper SSL-VPN's behind our F5s so we can use them in an active active conifguration. We are not having any problems with the regular SSL-VPN communications. However when we try to use the parts that allow you to do a try VPN tunnel we are getting either a Invalid certificate response or the app refuses the start.

 

 

Right now I have ports 443 tcp and 4500 UDP configured.

 

 

 

 

I've looked through all the docs and tried everything that appears to be close to what we want to do. So far nothing is working. Does anyone have any ideas on what I should do to configure this ?

 

 

 

 

 

Our F5 is currently on 9.4.5 LTM

 

 

 

 

 

Thanks for any ideas and help that will get us moving forward.

 

 

 

 

Joe

 

 

4 Replies

  • not sure if this is relevant and whether it is still correct now.

     

     

    i have worked with one customer about rdp service. connection failed when starting rdp session (web application was working fine). finally, juniper tac informed that there is specific scurity mechanism in client and ive which discarding packet because they detect man-in-the-middle attack. layer 4 load balancing should be no issue.
    • Narendren_S_658's avatar
      Narendren_S_658
      Icon for Nimbostratus rankNimbostratus

      Hi All, Anybody have solution for this issue? Instead of layer-4 policy, if we use layer-7 for port 443 and layer-4 for udp 4500, will it resolve the issue?

       

  • not sure if this is relevant and whether it is still correct now.

     

     

    i have worked with one customer about rdp service. connection failed when starting rdp session (web application was working fine). finally, juniper tac informed that there is specific scurity mechanism in client and ive which discarding packet because they detect man-in-the-middle attack. layer 4 load balancing should be no issue.
    • Narendren_S_658's avatar
      Narendren_S_658
      Icon for Nimbostratus rankNimbostratus

      Hi All, Anybody have solution for this issue? Instead of layer-4 policy, if we use layer-7 for port 443 and layer-4 for udp 4500, will it resolve the issue?