No access to email server while on SSL VPN
Comments
-
Yes - a packet capture off the USG shows TCP SYN to the server and server sending SYN ACK back to the user/device.0
-
But not more then that? No ACK from user/device?
So it looks like it tries to lookback but fails...
Does the IP pool VPN not over lapping with another subnet?
If your using the USG as the DNS in System > DNS you could add a Address/PTR Record with FQDN your Email server domain and IP Address the LAN IP of the server.
0 -
Does not appear that way.
It was not, but I changed it to overlap with a subnet I know works and that did not fix anything.
I added the DNS record, also with no success.
Just attempting a simple ping test - while sitting on the network (i.e. 192.168.1.33) attempting to ping the server (which I forgot to mention is on the DMZ) at 172.16.2.33 I can check email and ping the server. The moment I turn on the SSL and take on a 192.168.1.250 address, the ping drops and email access drops.0 -
Did you point the DNS record to 172.16.2.33?
what firmware are you on?
So at the moment uncheck “Force all client traffic to enter SSL VPN tunnel” works but I guess you would like internet down the VPN.
0 -
Ok I might have a workaround which ping works down the SSL VPN to your server at 172.16.2.3 on the DMZ port.
Firewall
from SSL_VPN
to DMZ
source and destination any
service any or ICMP or ping
Routing
incoming SSL_VPN
member SSL_VPN
source and destination any
service ICMP or ping
next hop
type Interface
Interface DMZ
address translation
source network address translation outgoing-interface
You should now be able to ping from the SSL VPN to 172.16.2.3
0 -
Okay - did all that. That comes back with:
Warning message:<br>CLI Number: 3<br>Warning Number: 28005<br>Warning Message: 'Invalid gateway from Next-Hop interface. Policy route will not work.'
0 -
I get that error too but it works
0 -
I lose all access to the internet when doing that. Not only can I not ping the device, I can no longer get any internet access.0
-
Yes if you route with service any it does that so if you do destination IP 172.16.2.33 for the Routing rule that should allow internet on the SSL VPN and ping 172.16.2.33.
0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 101 Nebula Status and Incidents
- 5.8K Security
- 296 USG FLEX H Series
- 281 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 254 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 76 Security Highlight