GlobalProtect and overlapping networks - is it a problem?

Reply
Highlighted
L4 Transporter

GlobalProtect and overlapping networks - is it a problem?

Hello


I'm using GP since few years without any problem. Recently my colleagues complains abut situation when he can't established RDP connection. Local networks in their home is 192.168.1.x and my servers are on the same network 192.168.1.x -
That's their issue.


In my opinion it's not a problem because GP install virtual adapter that's have network designed for GP in my scenario 172.16.1.x.

I force also route 0.0.0.0/0


I tryed to find tech docs explained such situation but I can't find one. Could You point me in right directions of proofing my rights please.

 

 

With regards

SLawek

Highlighted
L6 Presenter

Re: GlobalProtect and overlapping networks - is it a problem?

Hi,

 

Do PCAP from the client when attempting connection to the RDP server. That will prove the source IP you are coming from. 

What is happening if they are not connected to the GP,  can they RDP to the server?

 

Thx,

Myky

L4 Transporter

Re: GlobalProtect and overlapping networks - is it a problem?

Hi,

 

Personally, I would never use 192.168.1.0/24 or 192.168.2.0/24 as a business network because so many home routers use those networks and you will run into overlaps. In your case, the local route for network 192.168.1.0/24 of the remote computer will have precedence over the default route 0.0.0.0/0, so the packet will not go through the VPN tunnel.

 

Benjamin

Highlighted
L4 Transporter

Re: GlobalProtect and overlapping networks - is it a problem?

Hello Benjamin

 

I know that in business we shouldn't use 192.168.1.x network - in my case this is historical - and very hard to change now.

 

I can't do pcap right now, I will do that in few days.

 

In my case I was able to ping any of my servers without problem. So are You sure that this is a route issue?

How to explain that ping was OK when RDP not?

 

Regards

SLawek

Highlighted
L7 Applicator

Re: GlobalProtect and overlapping networks - is it a problem?

I imagine that the end user is utilizing a Windows box? Overlap on the VPN networks are well known to cause serious issues with routing on Windows due to it prioritizing known paths. Everyone can say that this really shouldn't cause and issue, but it does for whatever reason even when running a 0.0.0.0/0. 

One thing that I would double check is if the end-user is properly initiating an RDP. If you can ping the server then it should be able to RDP as long as Windows isn't doing something funky in the background; are you sure that the user is properly logging into the server using the DOMAIN\user and the proper password? 

Highlighted
L4 Transporter

Re: GlobalProtect and overlapping networks - is it a problem?

Hello

 

Of course it's Windwos box ;)

I need to use 0.0.0.0/0 route because I need internet access from my IP's and access to local servers.

Is it other possibility to achieve this?

 

route print from my Windows box:

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.8.1    192.168.8.101     50
          0.0.0.0          0.0.0.0         On-link        172.16.1.6      1
    xxx.xxx.xxx.xxx  255.255.255.255      192.168.8.1    192.168.8.101     50

 

as we can see link from 172.16.1.6 has "1" metric. I belive that routing table was the same from laptop that has issue. I know that I'm using 192.168.8.x network.

 

I will check this in lab with router with 192.168.1.0 network on 3th January.

 

The user can not even logon because when he tryed to connect using mstsc.exe logon windows doesn't appear, only after about 60s popup with "cannot conect bla bla" appear.

 

Regards

Slawek

Highlighted
L7 Applicator

Re: GlobalProtect and overlapping networks - is it a problem?

You might just want to try and have him connect to the FQDN of the device; that's what we have all of our users do and we don't get any overlap issues. Generally that works alot better than simple IP connections. 

Highlighted
L4 Transporter

Re: GlobalProtect and overlapping networks - is it a problem?

This was my first step, we tryed to conenct using IP address - so this problem was eliminated.

Highlighted
Community Team Member

Re: GlobalProtect and overlapping networks - is it a problem?

The overlapping networks is ALWAYS a problem.. You have to either Exclude that network from the VPN OR you need to NAT. There is no way to easily avoid it when you have the overlap.

Stay Secure,
Joe
End of line
Highlighted
L4 Transporter

Re: GlobalProtect and overlapping networks - is it a problem?

Helllo

 

Thank You all for replays.

I will do NAT for connections between laptops and servers on 192.168.1.x network. I prefer to not NAT on connection between laptop and other servers ie. 192.168.10.x.

I hope that this solve my problems.

 

 

Regards

Slawek

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!