No access to email server while on SSL VPN
I have a USG110 set up with several static IPs. Behind one of them is an email server. When connecting via SSL (via SecuExtender), I can no longer access the email server. From what I can see, the traffic is getting thru, but perhaps not back? Has anyone else experienced this issue?
Comments
-
If your connecting externally you would normally DNS to get the WAN IP of the email server.
If you open up your SSL VPN rule and uncheck “Force all client traffic to enter SSL VPN tunnel” can you get to your Email server like that?
0 -
Hi @Stephen,
Can you post the following command result and network topology for further checking?
Router# show sslvpn policy
0 -
@PeterUK - yep. Unchecking "Force all client traffic to enter SSL VPN tunnel" does seem to fix that. That being said...is there a way to have both?
@Zyxel_Cooldia -- do you want that run from the Console? I've had trouble getting that to run, so I'll need to get that fixed.
0 -
Is your Email set with a NAT LAN IP? Like 192.168.1.10? if so and you have a NAT rule check NAT loopback.
When you attempt to connect to your Email server are their any blocks to it in the logs?
0 -
0
-
In the above example, the SSL addresses are being given a 192.168.2.X address upon connection.0
-
@Zyxel_Cooldia -- sorry for the delay.
<p>index: 1</p> <p> active: yes</p> <p> name: Stephen_SSL</p> <p> description: SSL VPN for Stephen</p> <p> user: stephen</p> <p> ssl application: </p> <p> network extension: yes</p> <p> traffic enforcement: yes</p> <p> netbios broadcast: no</p> <p> ip pool: SSL_VPN_USERS</p> <p> dns server 1: 0.0.0.0</p> <p> dns server 2: 1.1.1.1</p> <p> wins server 1: </p> <p> wins server 2: </p> <p> network: </p> <p> reference count: 1</p>
0 -
DNS 0.0.0.0 ? I know there is a 1.1.1.1 DNS but don't think theirs a 0.0.0.0 as that IP is reserved.
When you attempt to connect to your Email server are their any blocks to it in the logs? You may need a firewall rule as your connecting down the VPN for a WAN IP of your server with NAT loopback.
Or as a test you could put in the host file of the PC/laptop with the Emails server LAN IP.
0 -
Under the first DNS option, in the GUI, it's set to ZyWALL. I'm not sure why it's showing up as 0.0.0.0. I've tried having 8.8.8.8 in there as well, but no success changing the DNS around.
No, I'm not seeing any blocks. I'm seeing it all forwarded. I can see the computer hitting the email server as well. If I'm local on the network, the NAT loopback is working as expected. I'll experiment around with firewall rules later.0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 101 Nebula Status and Incidents
- 5.8K Security
- 296 USG FLEX H Series
- 281 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 254 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 76 Security Highlight