Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Steve_Walker
Explorer

VPN Access Rules

We have a couple of users who access services based on the IP address of their VPN.  However, they then can't access services as their local computer IP address, not the allowed address, is being seen by the firewall which then blocks them.

These users do not have a static local IP address.

I am not sure how to resolve this.  Any thoughts?

Running R81.20

 

Thanks -

Steve

0 Kudos
7 Replies
_Val_
Admin
Admin

Just to clarify, they can establish a VPN tunnel but cannot access internal resources? Some additional information would be helpful. Are you using Office Mode? Do you see which rule is dropping the problematic traffic?

0 Kudos
(1)
Steve_Walker
Explorer

_Val_ -

Your comment "Do you see which rule is dropping the problematic traffic?" pointed me in a direction I missed on my original troubleshooting.  The rule dropping the traffic is the cleanup rule.

I need to explore this further on my end.

the_rock
Legend
Legend

Hey Steve,

Just make sure rule to allow this is above clean up rule.

Andy

0 Kudos
_Val_
Admin
Admin

Sure, let us know if you need any additional assistance

0 Kudos
the_rock
Legend
Legend

Hi Steve,

Not sure how many rules you have in the rulebase, but generally, at least my recommendation is always to create RA access rule towards the top, something like bwlow (example from my lab)

 

Andy

 

0 Kudos
PhoneBoy
Admin
Admin

The thought that went through my mind is that the clients installed as SecuRemote...which would also cause this behavior.

0 Kudos
AkosBakos
Leader Leader
Leader

True, check the installed version of the VPN client on the affected endpoints.

----------------
\m/_(>_<)_\m/
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events