This KB article addresses an issue where a customer experienced internet slowness and remote users faced difficulties connecting to Juniper Secure Connect. The root cause was identified as an incorrect topology configuration in a chassis cluster setup involving SRX and Fortinet firewalls. The article provides details on identifying the issue and the steps taken to resolve it.
During troubleshooting, the customer reported no changes in the SRX configuration. However, it was later discovered that the network topology was misconfigured. In the setup, both SRX and Fortinet firewalls were part of a chassis cluster, with a Link Aggregation Group (LAG) configured. One of the Fortinet firewall's active links was connected to the SRX active node, while another link in the LAG was connected to the SRX standby node. This configuration caused traffic drops when traffic hit the Fortinet interface connected to the SRX standby node, leading to the reported issues.
To resolve the issue, the following steps were taken:
After correcting the topology, the internet slowness and remote access issues were resolved. For more details on configuring chassis clusters and LAGs, please refer to the related KB articles KB22474 [juniper.net].