Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
rlamerico
Contributor

SDL with location awareness

I am working on a specific requirement with Endpoint security VPN E84.40 clients. I read the admin guide in order to enable SDL and location awareness (Global properties>Endpoint connect). It contains a group with our internal IP addresses.

SDL is enabled on the client. Now when these users connect over an external network the SDL pops up which is good. But when the user comes into office the client pops up to connect on VPN again, as I understand client need to recognize that host is in a internal network and give a bypass on VPN client.

 

I have a network with many locations linked by MPLS links and this problem happens just in locations connected on my Datacenter by MPLS, when I connect directly on my LAN on my DataCenter it no happen.

 

I raised a ticket with CP TAC and receive the answer that is necessary to be connected directly on the same network than my gateway, but it is not clear for me, because my locations is connected by MPLS but have access to firewall directly.

 

Maybe there is a configuration missing in some point.

0 Kudos
6 Replies
PhoneBoy
Admin
Admin

What settings are you using?

rlamerico
Contributor

Hi PhoneBoy,

I have enabled the SDL on my client and configure "network location awareness" with my network range 10.0.0.0/8.

Screenshot_223.png

 

PhoneBoy
Admin
Admin

In the remote sites, it is connecting to the gateway via the internal interface or via the external interface?

rlamerico
Contributor

Hi PhoneBoy,
In remote sites, we have an MPLS connecting with my DataCenter, in this case we are connecting with the internal interface, but I don´t have a specific configuration for that, on my client, I just configure my external IP when creating a profile.

The only configuration that I have to inform what is my internal LAN is on "location awareness".

 

PhoneBoy
Admin
Admin

Have you confirmed traffic to the gateway's external IP is in fact traversing the MPLS?

0 Kudos
rlamerico
Contributor

Yes, in this case, the client can´t reach the gateway´s external IP and it is correct because he is on my LAN, in my mind the client when connected on the first time on VPN need to receive the topology and the information about my internal range and based on this information don´t request to connect when receive one ip from my internal range.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events