No access to email server while on SSL VPN
I have a USG110 set up with several static IPs. Behind one of them is an email server. When connecting via SSL (via SecuExtender), I can no longer access the email server. From what I can see, the traffic is getting thru, but perhaps not back? Has anyone else experienced this issue?
Comments
-
If your connecting externally you would normally DNS to get the WAN IP of the email server.
If you open up your SSL VPN rule and uncheck “Force all client traffic to enter SSL VPN tunnel” can you get to your Email server like that?
0 -
Hi @Stephen,
Can you post the following command result and network topology for further checking?
Router# show sslvpn policy
0 -
@PeterUK - yep. Unchecking "Force all client traffic to enter SSL VPN tunnel" does seem to fix that. That being said...is there a way to have both?
@Zyxel_Cooldia -- do you want that run from the Console? I've had trouble getting that to run, so I'll need to get that fixed.
0 -
Is your Email set with a NAT LAN IP? Like 192.168.1.10? if so and you have a NAT rule check NAT loopback.
When you attempt to connect to your Email server are their any blocks to it in the logs?
0 -
0
-
In the above example, the SSL addresses are being given a 192.168.2.X address upon connection.0
-
@Zyxel_Cooldia -- sorry for the delay.
<p>index: 1</p> <p> active: yes</p> <p> name: Stephen_SSL</p> <p> description: SSL VPN for Stephen</p> <p> user: stephen</p> <p> ssl application: </p> <p> network extension: yes</p> <p> traffic enforcement: yes</p> <p> netbios broadcast: no</p> <p> ip pool: SSL_VPN_USERS</p> <p> dns server 1: 0.0.0.0</p> <p> dns server 2: 1.1.1.1</p> <p> wins server 1: </p> <p> wins server 2: </p> <p> network: </p> <p> reference count: 1</p>
0 -
DNS 0.0.0.0 ? I know there is a 1.1.1.1 DNS but don't think theirs a 0.0.0.0 as that IP is reserved.
When you attempt to connect to your Email server are their any blocks to it in the logs? You may need a firewall rule as your connecting down the VPN for a WAN IP of your server with NAT loopback.
Or as a test you could put in the host file of the PC/laptop with the Emails server LAN IP.
0 -
Under the first DNS option, in the GUI, it's set to ZyWALL. I'm not sure why it's showing up as 0.0.0.0. I've tried having 8.8.8.8 in there as well, but no success changing the DNS around.
No, I'm not seeing any blocks. I'm seeing it all forwarded. I can see the computer hitting the email server as well. If I'm local on the network, the NAT loopback is working as expected. I'll experiment around with firewall rules later.0
Categories
- All Categories
- 395 Beta Program
- 2.1K Nebula
- 117 Nebula Ideas
- 81 Nebula Status and Incidents
- 5.1K Security
- 83 USG FLEX H Series
- 247 Security Ideas
- 1.3K Switch
- 69 Switch Ideas
- 914 WirelessLAN
- 34 WLAN Ideas
- 5.9K Consumer Product
- 211 Service & License
- 337 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2K FAQ
- 912 Nebula FAQ
- 419 Security FAQ
- 237 Switch FAQ
- 207 WirelessLAN FAQ
- 46 Consumer Product FAQ
- 139 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 72 About Community
- 62 Security Highlight