Wednesday, June 23, 2021

Site-to-Site VPN between Juniper SRX and AWS VPC

I'm fairly new to VPNs but am trying to set up a VPN connection between my AWS VPC and my Juniper Edge Router. Now, I've got a bit of a wonky set up here that creates a double NAT situation.

Host computer (192.168.1.2/24) -> First Router (Source NAT to 192.168.252.2/24) -> Second Router (public IP address configured for VPN to aws) -> AWS VPC (destination of 192.168.250.2/24)

I went to AWS and gave it my public static IP address and said I need the 192.168.252.0/24 subnet to be able to communicate with the VPC. It spits back a config which I enter and from the second router, I can ping a device in the VPC so long as I set my source of the ping to be 192.168.252.1 (the "inside" interface of the second Router). So I think GREAT!, it works.

Then I try to ping from my host computer... and it does not work. I'm sure the NAT is to blame since it works when I ping directly from the router, but I'm not sure what else to do configuration wise. I am dreading a support call with Juniper.



No comments:

Post a Comment