- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: VPN Access Rules
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VPN Access Rules
We have a couple of users who access services based on the IP address of their VPN. However, they then can't access services as their local computer IP address, not the allowed address, is being seen by the firewall which then blocks them.
These users do not have a static local IP address.
I am not sure how to resolve this. Any thoughts?
Running R81.20
Thanks -
Steve
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just to clarify, they can establish a VPN tunnel but cannot access internal resources? Some additional information would be helpful. Are you using Office Mode? Do you see which rule is dropping the problematic traffic?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
_Val_ -
Your comment "Do you see which rule is dropping the problematic traffic?" pointed me in a direction I missed on my original troubleshooting. The rule dropping the traffic is the cleanup rule.
I need to explore this further on my end.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Steve,
Just make sure rule to allow this is above clean up rule.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sure, let us know if you need any additional assistance
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Steve,
Not sure how many rules you have in the rulebase, but generally, at least my recommendation is always to create RA access rule towards the top, something like bwlow (example from my lab)
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The thought that went through my mind is that the clients installed as SecuRemote...which would also cause this behavior.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
True, check the installed version of the VPN client on the affected endpoints.
\m/_(>_<)_\m/
