Description

Site to site policy-based VPN between a Juniper SRX300 and Forcepoint had phase 1 and phase 2 security associations up, but just one-way traffic.

Solution

Source NAT was causing return traffic to be left out of the VPN. Added a separate rule for specific source and destination IPs and source-nat interface off action. Issue resolved.

Modification History

11/2: Changed status to non-validated
11-9-2023: Formatting corrections made.