Actually, when I disable the first link of node 1, all nodes could pass every kind of traffic well, except node 2. And I build an same lab system, the issue not happen.
-----邮件原件----- 发件人: Ojamo, V. [mailto:[email protected]] 发送时间: 2013年8月5日 15:02 收件人: '徐见'; [email protected] 主题: RE: [j-nsp] SRX650 full-mesh vpn, ssh not passed The pictures cannot be viewed without Weibo account? -V > -----Original Message----- > From: juniper-nsp [mailto:[email protected]] > On Behalf Of ?? > Sent: Monday, August 05, 2013 1:18 PM > To: [email protected] > Subject: [j-nsp] SRX650 full-mesh vpn, ssh not passed > > Hi all: > > As the theme said, I have a route-based vpn, full-mesh > topology, > and run ospf protocol. > > Physical link topology is here: > > http://photo.weibo.com/2110817105/photos/detail/photo_id/3607 > 937263216169#36 > 07937263216169 > > logical link topology is here: > > > http://photo.weibo.com/2110817105/photos/detail/photo_id/3607 > 931668041778#36 > 07926685185940 > > the issue just between node 1 and node 2. > > As you can see, there are four links on node 1, and one link on node > 2, and > 2 vpn tunnel have been built between both,(st0.0, st0.1) > > And the two tunnel works as primary(st0.0) and backup(st0.1). > > The problem is, when primary down, ssh traffic from NET A to NET > B, can’t > passed, but from NET B to NET A is ok, > > Show route “NET B”, show route “NET A” commands show both of > them have > learned route from right tunnel (st0.1), ping command in bidirection > is ok > too. > > Anyone could give any idea? > > > > _______________________________________________ > juniper-nsp mailing list [email protected] > https://puck.nether.net/mailman/listinfo/juniper-nsp _______________________________________________ juniper-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/juniper-nsp

