- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- SSH TO GATEWAY OVER VPN
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SSH TO GATEWAY OVER VPN
I have a gateway that has remote access vpn enabled. I am trying to ssh directly to it, when i connect to it over vpn, but for some reason i am unable to, i don't even see the traffic coming to the gateway. Is this possible or is there a workaround for this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you ping the same GW IP addresses, internal and external, and/or open WebUI to it, when on VPN. Are you using Office Mode?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please make sure that Office mode IP addresses are routed to the external interface of the GW and not to internal network.
Most probably a routing issue, office mode is routed back to internal networks and not to the VPN tunnel
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Where are you saying to add the route, because shouldn't the firewall know how to route office mode ip's since its the one that assigns them to the client.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1. In Gaia config, do you have Office mode range defined as permitted clients?
2. In Security Policy, do you allow SSH from Office mode to the gateway object?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello, thanks,
1-Yes, in Gaia is allow connections from any source (i have a lab environment)
2-In the Policies, I created rules to allow connections from all networks to Gateways, but it doesnt works
Something that I see is that the internal IP address of gateway is not inside the VPN Domain for RemoteUsers (the network of that IP address is inside vpn domain), due that reason my test connections are not showed in the logs, if i do a traceroute to internal IP address of gateway with vpn client connected the connections to the gateway take the path to internet modem, they does not go by the VPN tunnel,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check the Excluded services either in global properties or the VPN community.
I believe that SSH is counted as one and thus may be excluded from the tunnel when destination is the gateway.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello!
did you find the solution for the access to GW over client vpn?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Bhaizlett,
I am experiencing the same issue. Have you found a solution to accessing the firewall over VPN?
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello all,
the same issue here: no access to the internat interface of the appliance via VPN.
Weird addition: https access is possible, but ssh is not.
Is there any update?
Thanks and regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As @Vladimir mentioned above, it is most probably because SSH is excluded from VPN services. Check advanced properties of your VPN community.
