- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-08-2018 03:00 PM - edited 08-08-2018 03:09 PM
I have realy weired issue,
I have two sites connected with IPSEC vpn, PAVM200 to PA3020.
the sites are connected with IPSEC very stable vpn, remote site trying to access DMZ zone on the local site.
The routing confiured and policy rule allowing the access from VPN to DMZ.
everything works fine and I was able to see the traffic,
suddenly after the VPN drop and esteblish the connection again the remote site users can only access the local site network but no DMZ zone on local site.
on the logs for the remote site I see the traffic egress to the right tunnel without reply, on the local site I don't see the traffic is coming.
On last try I was creating new policy rule for DMZ to remote site network for checking the reply routing and suddenly everything come back to normal and working even after I disalbe the new policy rule.
Now after 5 months that it's working the VPN dropped again and once again I needed to create that new policy for bring everything to work again, very weired.
any suggestion what to check?
Thank you for the help.
08-09-2018 12:58 PM
Do you log the interzone default rule so that you can see if the policy is getting denied in the logs? It would be very odd to see this happen unless for some reason the security policy that was matching this traffic for some reason no longer matched the traffic as it should. (Either changes on the Local or Remote end; or the XML getting corrupt following changes or upgrades).
08-09-2018 03:33 PM - edited 08-09-2018 03:34 PM
Hi @BPry thank you for the reply,
Yes I'm log the interzone, in day to day basic I don't have policy to allow DMZ accessing the VPN tunnel (the opposite direction) so when I trying to ping I see it denies on the interzone-default rule.
That's why for testing the return routing I created new policy allowing DMZ to access VPN tunnel for PING/ICMP and then suddenly the opposite way, VPN tunnel to DMZ started to work.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!