<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Client, Can't connect to internal zone? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-can-t-connect-to-internal-zone/m-p/142739#M48586</link>
    <description>&lt;P&gt;I'm just harboring&amp;nbsp;a guess here but that would seem to indicate that your return path either isn't allowed or the route back is misconfigured.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Feb 2017 17:14:20 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-02-13T17:14:20Z</dc:date>
    <item>
      <title>VPN Client, Can't connect to internal zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-can-t-connect-to-internal-zone/m-p/142420#M48540</link>
      <description>&lt;P&gt;Hi, Good day!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to ask what would be the problem,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From outside user accessing via ssl vpn (VPN ZONE) below details are working.&lt;/P&gt;&lt;P&gt;1. It can connect / has the ip pool assigned&lt;/P&gt;&lt;P&gt;2. It can reach the internet using the assigned pool.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem is from VPN Zone user can't reach the internal zone even though we already created a policy from vpnzone -&amp;gt; Internal (vise versa). When we trace last hop stop is on ip address of the vpn interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We also tried adding static route exit interface tunnel. but still doesn't work. Also based on logs there's a byte sent (from uservpn) but no bytes received (reply from the internal server)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when creating a nat policy from vpn zone -&amp;gt; internal it works.&lt;/P&gt;&lt;P&gt;But this doesn't scale well since it will be translated in one ip only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is missing on this setup?&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 18:02:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-can-t-connect-to-internal-zone/m-p/142420#M48540</guid>
      <dc:creator>searching1</dc:creator>
      <dc:date>2017-02-10T18:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client, Can't connect to internal zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-can-t-connect-to-internal-zone/m-p/142435#M48541</link>
      <description>&lt;P&gt;Kind of hard to follow the question with a quick glance, but I would attempt to look for the following.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) What does your Access Route look like in your GP Client Configuration. Are you routing 0.0.0.0/0 or do you have a split tunnel setup.&lt;/P&gt;&lt;P&gt;2) Do you actually have a security rule that allows the traffic to/from GP zone to/from internal network&amp;nbsp;&lt;STRONG&gt;that is being hit&lt;/STRONG&gt;?&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) If you are not hitting the right security policies look in the log and see if you can even see the traffic. If you can't see the traffic then you have an Access Route config issue, if you can see the traffic in the log and it isn't hitting the rule that you expect then you are likely just configuring your security policy wrong or it doesn't 'make it down' to the rule that you want it to. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 18:18:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-can-t-connect-to-internal-zone/m-p/142435#M48541</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-02-10T18:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client, Can't connect to internal zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-can-t-connect-to-internal-zone/m-p/142523#M48551</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Diagram:&lt;/P&gt;&lt;P&gt;VPN ZONE ----(tunel Interface)-&amp;gt;(FW)&amp;lt;-----(L3)----- Internal Zone&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. 1.1.1.X (VPN Pool segment) 255.255.255.0 &amp;gt; tunnel interface&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; 2.2.2.X (Internal segment) 255.255.255.0 &amp;gt; tunnel interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. &amp;nbsp;Yes, there's a policy already and it's hitting the policy. the problem is when pinging from VPN Pool to Internal, Bytes sent increaase but Bytes out always 0 which theres no reply from the server or server can't reach the vpn client ip.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2017 07:32:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-can-t-connect-to-internal-zone/m-p/142523#M48551</guid>
      <dc:creator>searching1</dc:creator>
      <dc:date>2017-02-11T07:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client, Can't connect to internal zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-can-t-connect-to-internal-zone/m-p/142594#M48564</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So when you NATing the&amp;nbsp;VPN Zone &amp;gt; Internal Zone things are working fine? Try to do a ping or traceroute from the&amp;nbsp;Internal &amp;gt; VPN Zone. See the traffic flow, check your routing.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Feb 2017 18:11:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-can-t-connect-to-internal-zone/m-p/142594#M48564</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-02-12T18:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client, Can't connect to internal zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-can-t-connect-to-internal-zone/m-p/142612#M48566</link>
      <description>&lt;P&gt;You should do a packet capture on the server to see if it actually receives the packets and if anything is sent back. After that,&amp;nbsp;do a packet capture on the firewall to see if it's receiving the response and if it's dropping it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 00:00:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-can-t-connect-to-internal-zone/m-p/142612#M48566</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2017-02-13T00:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client, Can't connect to internal zone?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-can-t-connect-to-internal-zone/m-p/142739#M48586</link>
      <description>&lt;P&gt;I'm just harboring&amp;nbsp;a guess here but that would seem to indicate that your return path either isn't allowed or the route back is misconfigured.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 17:14:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-can-t-connect-to-internal-zone/m-p/142739#M48586</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-02-13T17:14:20Z</dc:date>
    </item>
  </channel>
</rss>

