- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-24-2011 02:25 AM
Hi all,
I have a little problem, I've installed a PA-500 and configured SSL-VPN, it works fine, I can reach the internal network correctly but I can't reach the management Interface.
This is the scenario:
VPN Clients:
IP: 10.31.31.10-10.31.31.254
Management Interface:
IP: 10.7.10.251
Gateway: 10.7.10.3
The gateway already knows the routes to reach 10.31.31.0/24 via Ethernet1/2 of PAN.
I can see in Traffic Log that packets pass through Interface tunnel.1 to Ethernet1/2 (Trust to Trust), but nothing came back.
Have you any idea about?
03-24-2011 04:33 PM
triitech wrote:
Hi all,
I have a little problem, I've installed a PA-500 and configured SSL-VPN, it works fine, I can reach the internal network correctly but I can't reach the management Interface.
This is the scenario:
VPN Clients:
IP: 10.31.31.10-10.31.31.254
Management Interface:
IP: 10.7.10.251
Gateway: 10.7.10.3
The gateway already knows the routes to reach 10.31.31.0/24 via Ethernet1/2 of PAN.
I can see in Traffic Log that packets pass through Interface tunnel.1 to Ethernet1/2 (Trust to Trust), but nothing came back.
Have you any idea about?
What security policy do you have on your SSL VPN? Does it allow https to the network range (or specific IP address) your management interface is connected to?
03-24-2011 06:24 AM
Do you have the management interface locked down to certain IP addresses?
03-24-2011 04:33 PM
triitech wrote:
Hi all,
I have a little problem, I've installed a PA-500 and configured SSL-VPN, it works fine, I can reach the internal network correctly but I can't reach the management Interface.
This is the scenario:
VPN Clients:
IP: 10.31.31.10-10.31.31.254
Management Interface:
IP: 10.7.10.251
Gateway: 10.7.10.3
The gateway already knows the routes to reach 10.31.31.0/24 via Ethernet1/2 of PAN.
I can see in Traffic Log that packets pass through Interface tunnel.1 to Ethernet1/2 (Trust to Trust), but nothing came back.
Have you any idea about?
What security policy do you have on your SSL VPN? Does it allow https to the network range (or specific IP address) your management interface is connected to?
03-25-2011 02:02 AM
Thanks for all replies,
the problem was that was missing the correct policy to permit traffic from tunnel to management interface for class 10.31.31.0/24.
Now I can reach the managemente interface without problems.
Regards
Alessio
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!