Привет @wyobsUPDATE: РаботаюСчитаю, что тот, кто работает над вашим SRX, знает, как настраивать политики безопасности и понимает flow-based FW, поэтому я не стал прописывать свои политики безопасности.SRX Сторонаset security ike proposal Rattle-Proposal authentication-method pre-shared-keys
set security ike proposal Rattle-Proposal dh-group group2
set security ike proposal Rattle-Proposal authentication-algorithm sha-256
set security ike proposal Rattle-Proposal encryption-algorithm aes-256-cbc
set security ike proposal Rattle-Proposal lifetime-seconds 28800
set security ike policy Rattle_Phase1_Policy mode main
set security ike policy Rattle_Phase1_Policy proposals Rattle-Proposal
set security ike policy Rattle_Phase1_Policy pre-shared-key ascii-text <<RANDOM-PASSWORD>>
set security ike gateway gw-Rattle ike-policy Rattle_Phase1_Policy
set security ike gateway gw-Rattle address <<UDMP-WAN-IP>>
set security ike gateway gw-Rattle external-interface ge-0/0/7.0
set security ike gateway gw-Rattle local-address <<SRX-WAN-IP>>
set security ike gateway gw-Rattle version v1-only
set security ipsec proposal Rattle-Proposals protocol esp
set security ipsec proposal Rattle-Proposals authentication-algorithm hmac-sha-256-128
set security ipsec proposal Rattle-Proposals encryption-algorithm aes-256-cbc
set security ipsec proposal Rattle-Proposals lifetime-seconds 3600
set security ipsec policy Rattle-Policy proposals Rattle-Proposals
set security ipsec vpn vpn-Rattle bind-interface st0.950
set security ipsec vpn vpn-Rattle ike gateway gw-Rattle
set security ipsec vpn vpn-Rattle ike ipsec-policy Rattle-Policy
set security ipsec vpn vpn-Rattle establish-tunnels immediately
UDMP Сторона Вывод SRXRattlehead@MS-SRX-2# run show security flow session source-prefix 172.16.252.1 Sep 21 12:52:52Session ID: 9816, Policy name: Temp-Allow-All/51, Timeout: 4, Valid In: 172.16.252.1/6 --> 10.180.255.68/13806;icmp, Conn Tag: 0x0, If: st0.950, Pkts: 1, Bytes: 84, Out: 10.180.255.68/13806 --> 172.16.252.1/6;icmp, Conn Tag: 0x0, If: irb.30, Pkts: 1, Bytes: 84, Session ID: 40204, Policy name: Temp-Allow-All/51, Timeout: 2, Valid In: 172.16.252.1/4 --> 10.180.255.68/13806;icmp, Conn Tag: 0x0, If: st0.950, Pkts: 1, Bytes: 84, Out: 10.180.255.68/13806 --> 172.16.252.1/4;icmp, Conn Tag: 0x0, If: irb.30, Pkts: 1, Bytes: 84,