IPSEC VPN issue

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

IPSEC VPN issue

L3 Networker

I have realy weired issue, 

 

I have two sites connected with IPSEC vpn, PAVM200 to PA3020.

 

the sites are connected with IPSEC very stable vpn, remote site trying to access DMZ zone on the local site.

The routing confiured and policy rule allowing the access from VPN to DMZ.

 

everything works fine and I was able to see the traffic,

suddenly after the VPN drop and esteblish the connection again the remote site users can only access the local site network but no DMZ zone on local site.

 

on the logs for the remote site I see the traffic egress to the right tunnel without reply, on the local site I don't see the traffic is coming.

 

On last try I was creating new policy rule for DMZ to remote site network for checking the reply routing and suddenly everything come back to normal and working even after I disalbe the new policy rule.

 

Now after 5 months that it's working the VPN dropped again and once again I needed to create that new policy for bring everything to work again, very weired.  

 

any suggestion what to check?

 

Thank you for the help.

2 REPLIES 2

Cyber Elite
Cyber Elite

@SShnap,

Do you log the interzone default rule so that you can see if the policy is getting denied in the logs? It would be very odd to see this happen unless for some reason the security policy that was matching this traffic for some reason no longer matched the traffic as it should. (Either changes on the Local or Remote end; or the XML getting corrupt following changes or upgrades). 

Hi @BPry thank you for the reply,

 

Yes I'm log the interzone, in day to day basic I don't have policy to allow DMZ accessing the VPN tunnel (the opposite direction) so when I trying to ping I see it denies on the interzone-default rule.

 

That's why for testing the return routing I created new policy allowing DMZ to access VPN tunnel for PING/ICMP and then suddenly the opposite way, VPN tunnel to DMZ started to work.

 

 

  

 

  • 2076 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!