[j-nsp] VPN between SRX with dynamic IP address to Cisco ASA

James S. Smith JSmith at WindMobile.ca
Thu Mar 17 16:09:41 EDT 2011


I'm having a bit of trouble with this configuration:   I have an SRX 240 (JunOS 10.0R3.10) that is connected to the Internet with a CX-111.  The CX-111 has a 3G stick for its Internet.  The SRX receives a DHCP address on ge-0/0/0.0 and can reach the Internet without a problem.

I'd now like to setup a site-to-site style VPN between the SRX and a Cisco ASA 5540.  The traditional site-to-site VPN configuration won't work since the Juniper IP address is dynamic.  Additionally, the Juniper cannot receive traffic initiated from the Internet.  It can only initiate traffic itself.

I've setup a similar configuration using the Cisco 800 series and Cisco EZVPN.  Anyone know a any sort of configuration for the Juniper that will work in this situation?

James

________________________________
This message contains confidential information and is intended only for the individual named. If you are not the intended recipient you are notified that disclosing, copying, distributing or taking any action in reliance on the contents of this information is strictly prohibited.


More information about the juniper-nsp mailing list