- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
07-12-2013 12:32 PM
We have a SSL VPN setup through the Global Protect Gateway. The SSL-VPN tunnel is in its own zone and I have an any - any rule for this zone to my trusted zone. I am able to pass traffic to one interface in a trusted zone but I am not able to pass traffic to another interface in the trusted zone. What am I missing?
07-12-2013 01:02 PM
so you mean although you have interface management profile with ping(if not do that for troubleshoot)
you can not ping any except eth1/2
07-12-2013 12:40 PM
are you sure you configured an unused pool for vpn clients ?
can you share interface ip's of Trust and VR table
07-12-2013 12:53 PM
We are using an unused pool for vpn clients. interface eth1/2, eth1/2.161, and eth1/4 are all in the trust network. I can get to eth2 but not the others.
interface id vr address
- --------- -- -- -------
* tunnel 4 default
* ethernet1/1 16 default 199.96.116.59/28
* ethernet1/2 17 default 192.168.11.4/24
* ethernet1/4 19 default 10.2.100.255/16
* ethernet1/2.161 259 default 192.168.161.6/24
* default/i3 61441 default
07-12-2013 01:02 PM
so you mean although you have interface management profile with ping(if not do that for troubleshoot)
you can not ping any except eth1/2
07-12-2013 01:12 PM
Ok, We are getting somewhere. I can ping eth1/2 and eth1/4 but I cannot ping anything else on the eth1/4 network but I can on the eth1/2 network. Seems like a routing issue somewhere but I don't know where. I added 10.2.0.0/16 to the access route list in the GlobalProtect Gateway client config. I also added 10.2.0.0/16 to the static route table of the tunnel interface.
07-12-2013 01:15 PM
what is the vpn pool ?
07-12-2013 01:18 PM
The VPN pool is: 192.168.251.250-192.168.251.252. (I am keeping it small for now).
07-12-2013 01:23 PM
"I also added 10.2.0.0/16 to the static route table of the tunnel interface." what do you mean with that
look for traceroute on the vpn client
07-12-2013 01:59 PM
In the GUI, Virtual Router --> Static Routes
Destination 10.2.0.0/16 and the tunnel interface, metric 10, next hop none.
Traceroute times out without a list of hops.
07-12-2013 02:31 PM
Problem resolved. Using multiple gateways outbound to the internet. Thank you for your responses.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!