Hey guys,
I really hope someone can help me solve this issue for the customer, as it has been going on for last almost 2 years and we had at least 4-5 TAC cases without any resolution and there is one open presently, but I feel like its going to go nowhere again (sadly).
Here is the gist of it...when I initially worked with customer before CP was even in production, as they are mostly Mac shop (they have maybe 10% windows computers), TAC escalations suggested them to use IA agents back then to solve this issue, as AD server was not sending proper events to the firewall to enforce right identities via IA blade/access roles. Now, this was great and it did work, BUT, what ended up happening eventually was that when their Macbooks were upgraded from OS Catalina to BigSur, even when connected with IA agents, it only works randomly, and sometimes does not even work with IP address, let alone fqdn when trying to access one of their few hosted internal websites.
To make situation worse, as there is no IA agent app for Iphones, when using VPN capsule to connect, yes, connection works fine, but then you cant resolve anything internally by fqdn and IP works maybe 20-30% of the time.
TAC had us do captures, we collected logs, but its not clear at all why it fails. I reviewed them myself and even from my work laptop, which works fine when connected to their VPN, when I access one of their internal sites, I see bunch of TCP retransmissions in the wireshark.
Windows machines used to work 100% of the time WITHOUT IA agent, but at this point, even that is super inconsistent.
To clarify, when their Macbooks were on catalina OS, they could resolve everything fine by IP or fqdn internally when connected on VPN WITHOUT having to connect IA agent.
@PhoneBoy , I feel you being MAC guru, are the last hope for solving this issue permanently : - ).
Just as a test, I even disabled vpn accel and sxl off and it did absolutely nothing.
TAC asked us to install jumbo 81 on top or R81.10, but I feel that was more to buy time (I already knew that was not going to do anything).
Thanks as always for the help/suggestions.
So I dont forget, multiple TAC people reviewed their IA config and found noithing wrong with it. Also, for context, when their iphones were on 15.xx version, all this worked just fine by fqdn/IP address, but as soon as they were upgraded to 16.xx, everything stopped working.
I looked on the support site and could not find any compatibility issues.
Cheers!