VPN SSL traffic

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

VPN SSL traffic

Not applicable

We have a SSL VPN setup through the Global Protect Gateway. The SSL-VPN tunnel is in its own zone and I have an any - any rule for this zone to my trusted zone. I am able to pass traffic to one interface in a trusted zone but I am not able to pass traffic to another interface in the trusted zone. What am I missing?

1 accepted solution

Accepted Solutions

so you mean although you have interface management profile with ping(if not do that for troubleshoot)

you can not ping any except eth1/2

View solution in original post

9 REPLIES 9

L6 Presenter

are you sure you configured an unused pool for vpn clients ?

can you share interface ip's of Trust and VR table

Not applicable

We are using an unused pool for vpn clients. interface eth1/2, eth1/2.161, and eth1/4 are all in the trust network. I can get to eth2 but not the others.

   interface                id    vr       address

  - ---------                --    --       -------

  * tunnel                        4    default

  * ethernet1/1              16    default  199.96.116.59/28

  * ethernet1/2              17    default  192.168.11.4/24

  * ethernet1/4              19    default  10.2.100.255/16

  * ethernet1/2.161          259   default  192.168.161.6/24

  * default/i3               61441 default

so you mean although you have interface management profile with ping(if not do that for troubleshoot)

you can not ping any except eth1/2

Not applicable

Ok, We are getting somewhere. I can ping eth1/2 and eth1/4 but I cannot ping anything else on the eth1/4 network but I can on the eth1/2 network. Seems like a routing issue somewhere but I don't know where. I added 10.2.0.0/16 to the access route list in the GlobalProtect Gateway client config. I also added 10.2.0.0/16 to the static route table of the tunnel interface.

what is the vpn pool ?

Not applicable

The VPN pool is: 192.168.251.250-192.168.251.252. (I am keeping it small for now).

"I also added 10.2.0.0/16 to the static route table of the tunnel interface." what do you mean with that

look for traceroute on the vpn client

Not applicable

In the GUI, Virtual Router --> Static Routes

Destination 10.2.0.0/16 and the tunnel interface, metric 10, next hop none.

Traceroute times out without a list of hops.

Not applicable

Problem resolved. Using multiple gateways outbound to the internet.  Thank you for your responses.

  • 1 accepted solution
  • 3632 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!