Description

This document a possible issue found in the setup


vSRX chassis cluster on KVM running 22.2R2-S2.


Connection is done Client to Server using HTTPS TCP 1433 port.


From SRX perspective client is directly connected while server is reachable using a tunnel interface (IPsec VPN).

Symptoms

Without any configuration changes the application stops working, PCAP at the client shows normal packets plus some extra RST packets but it is unclear why.

Solution

As a workaround you can add a firewall filter (to the client-side interface) that counts the impacted flow, this will fix the issue.





Modification History

2024-05-29 : Article Created