{"id":236,"date":"2017-08-13T16:47:01","date_gmt":"2017-08-13T20:47:01","guid":{"rendered":"http:\/\/puluka.com\/home\/?p=236"},"modified":"2017-08-13T16:47:01","modified_gmt":"2017-08-13T20:47:01","slug":"branch-office-vpn-with-wan-accelerator","status":"publish","type":"post","link":"http:\/\/puluka.com\/home\/networking\/screenos\/branch-office-vpn-with-wan-accelerator\/","title":{"rendered":"Branch Office VPN with WAN Accelerator"},"content":{"rendered":"<p><strong>Products<\/strong>: WXC WAN Accelerator any model &amp; SSG Firewall any Model<br \/>\n<strong>Version<\/strong>:\u00a0 Tested with ScreenOS 6.1 &amp; 6.2 &amp; WXC 5.7<\/p>\n<h2>Network Topology:<\/h2>\n<p><strong>Network diagram:<\/strong><br \/>\n<a href=\"http:\/\/puluka.com\/home\/wp-content\/uploads\/2017\/08\/WANACC-SSG-Branch.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-237 alignnone\" src=\"http:\/\/puluka.com\/home\/wp-content\/uploads\/2017\/08\/WANACC-SSG-Branch-300x281.jpg\" alt=\"\" width=\"300\" height=\"281\" srcset=\"http:\/\/puluka.com\/home\/wp-content\/uploads\/2017\/08\/WANACC-SSG-Branch-300x281.jpg 300w, http:\/\/puluka.com\/home\/wp-content\/uploads\/2017\/08\/WANACC-SSG-Branch.jpg 415w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nSSG5 is the sample design<\/p>\n<blockquote><p>eth0\/0 &#8211; WAN<br \/>\neth0\/1 &#8211; WXC Remote<br \/>\neth0\/2 &#8211; WXC Local<br \/>\nbgroup0 &#8211; layer 2 local LAN ports eth0\/2-0\/6<\/p><\/blockquote>\n<h2>Description:<\/h2>\n<p>The WXC WAN Accelerator product can operate in-line or off-path mode.\u00a0 The in-line mode is simplest to setup where all traffic from the site passes through the device.\u00a0 Acceleration tunnels are created between the branch office device and the data center device.<\/p>\n<p>This in-line deploy on a branch firewall requires that all ports for the branch LAN be on the local port side of the WXC device.\u00a0 Generally this means only one port on the firewall will be used for the remote connection of the WXC and all local devices are then connected to switch(es) on the local interface side of the WXC.<\/p>\n<p>This design uses the ScreenOS ability to create layer2 groups of interfaces in order to isolate all available ports on the firewall and keep them on the local connection of the WXC.\u00a0 Thus all firewall ports are usable again.\u00a0 This also prevents the accidental connection of local computers or network devices on the incorrect side of the WXC and excluding them from the WXC acceleration tunnel.<\/p>\n<p>This configuration allows an IPSEC VPN site then to participate in the WXC mesh while preserving the use of all available ethernet ports on the firewall.<\/p>\n<p>When configuring interfaces on a WXC mesh be sure to select fixed speed and duplex whenever possible.\u00a0 For the SSG series this will be 100 full on the interfaces connected.\u00a0 This will avoid potential throughput problems that can occur when auto-negociation falls back to half-duplex.<\/p>\n<p><strong>SSG configuration steps<\/strong><br \/>\n\u2022 \u00a0\u00a0\u00a0 Remove ip address and convert bgroup0 to layer 2 mode<br \/>\nunset interface bgroup0 ip<br \/>\n\u2022 \u00a0\u00a0\u00a0 Set fixed link speed and duplex to 100 full on local port eth0\/2<br \/>\nset interface eth0\/2 phy full 100mb<br \/>\n\u2022 \u00a0\u00a0\u00a0 Configure eth0\/1 with LAN ip address<br \/>\nset interface eth0\/1 ip 192.168.1.1\/24<br \/>\n\u2022 \u00a0\u00a0\u00a0 Configure trust zone on eth0\/1<br \/>\nset interface eth0\/1 zone trust<br \/>\n\u2022 \u00a0\u00a0 Configure management options for eth0\/1<br \/>\nset interface eth0\/1 manage ssl<br \/>\nset interface eth0\/1 manage ssh<br \/>\nset interface eth0\/1 manage telnet<br \/>\nset interface eth0\/1 manage web<br \/>\n\u2022 \u00a0\u00a0 Set fixed link speed and duplex to 100 full on remote port eth0\/2<br \/>\nset interface eth0\/1 phy full 100mb<br \/>\n\u2022 \u00a0\u00a0\u00a0 Configure normal WAN &amp; VPN settings on firewall for the site<\/p>\n<p><strong>WXC Configuration steps<\/strong><br \/>\n\u2022 \u00a0\u00a0\u00a0 Configure link speed and duplex to 100 full on remote &amp; local ports<br \/>\nconfig interface set speed-duplex local 100-full<br \/>\nconfig interface set speed-duplex remote 100-full<br \/>\n\u2022 \u00a0\u00a0 Configure ip information for local LAN<br \/>\nconfig ip set ip-address 192.168.1.254<br \/>\nconfig ip set default-gateway 192.168.1.1<br \/>\nconfig ip set subnet-mask 255.255.255.0<br \/>\n\u2022 \u00a0\u00a0 Configure matching policy load for the WXC mesh for your network<\/p>\n<h2>Verification:<\/h2>\n<p><strong>SSG Interface checks<\/strong><br \/>\nVerify the speed\/duplex, ip address and zone assignment of the interface.<\/p>\n<blockquote><p>get interface eth0\/1<br \/>\nInterface ethernet0\/1:<br \/>\ndescription ethernet0\/1<br \/>\nnumber 5, if_info 440, if_index 0, mode nat<br \/>\nlink up, phy-link up\/full-duplex<br \/>\nstatus change:3, last change:10\/24\/2001 21:00:20<br \/>\nvsys Root, zone Trust, vr trust-vr&nbsp;<\/p><\/blockquote>\n<p><strong>WXC Interface checks<\/strong><br \/>\nOn the CLI:<\/p>\n<blockquote><p>show interface<br \/>\nSettings for local interface<br \/>\nLink state: up<br \/>\nSpeed\/duplex: 100-full<br \/>\nHardware address: 00:30:48:9c:56:28<br \/>\nMedia type: copper<br \/>\nSettings for remote interface<br \/>\nLink state: up<br \/>\nSpeed\/duplex: 100-full<br \/>\nHardware address: 00:30:48:9c:56:29<br \/>\nMedia type: copper<\/p><\/blockquote>\n<p>Log into the web interface on the WXC<\/p>\n<blockquote><p>Menu: Device Setup &#8211; Interfaces<br \/>\n&#8220;Test Settings&#8221; button<br \/>\nSelect &#8220;remote&#8221; and the ip address of SSG eth0\/1 (192.168.1.1)<br \/>\nsubmit<br \/>\nThe interface test will confirm the remote port is correctly connected to eth0\/1 on the firewall<br \/>\nRepeat with an ip address active on the LAN for the &#8220;local&#8221; port.<\/p><\/blockquote>\n<h2>References:<\/h2>\n<p><strong>ScreenOS Concepts &amp; Examples Guides<\/strong><br \/>\n<a href=\"http:\/\/www.juniper.net\/techpubs\/software\/screenos\/screenos6.2.0\/index.html\">http:\/\/www.juniper.net\/techpubs\/software\/screenos\/screenos6.2.0\/index.html<\/a><br \/>\nVolume 2: Fundamentals &#8211; Chapter 3 Interfaces<\/p>\n<p><strong>WXOS 5.7 Operator&#8217;s Guide<\/strong><br \/>\n<a href=\"http:\/\/www.juniper.net\/techpubs\/hardware\/wx\/\">http:\/\/www.juniper.net\/techpubs\/hardware\/wx\/<\/a><br \/>\nChapter 3 &#8211; Configuring Interface Settings<\/p>\n<p>Originally Posted October 16, 2010<br \/>\nLast Revised on November 27, 2010<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Products: WXC WAN Accelerator any model &amp; SSG Firewall any Model Version:\u00a0 Tested with ScreenOS 6.1 &amp; 6.2 &amp; WXC 5.7 Network Topology: Network diagram: SSG5 is the sample design eth0\/0 &#8211; WAN eth0\/1 &#8211; [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-236","post","type-post","status-publish","format-standard","hentry","category-screenos"],"_links":{"self":[{"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/posts\/236","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/comments?post=236"}],"version-history":[{"count":1,"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/posts\/236\/revisions"}],"predecessor-version":[{"id":238,"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/posts\/236\/revisions\/238"}],"wp:attachment":[{"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/media?parent=236"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/categories?post=236"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/puluka.com\/home\/wp-json\/wp\/v2\/tags?post=236"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}