Branch Access HQ Server Through Sangfor VPN Failed

|
  • 232
  • 7

Issue Description

Branch side PC try to access HQ FTP server failed. User do packet capture in FTP server found out branch side PC use vpn interface IP to access the FTP server.

Handling Process

  • Use firewall in HQ to telnet FTP server. Success.
  • Use one pc in branch side to ping the FTP server.
  • Do packet capture in branch and HQ side. Result the pc ip being NAT to the vpn interface IP.
  • Check the interface and zone setting. Found the vpntun being select into WAN zone.
  • As WAN zone being use for SNAT for LAN > WAN cause when internal pc access HQ the source ip will be NAT to vpn interface ip.
  • Remove the vpntun from WAN zone. PC use it ip to access the FTP server

Root Cause

vpntun being selected into WAN zone. As WAN zone use for SNAT for LAN > WAN cause the source ip being NAT to vpn interface ip.

Solution

Remove vpntun from WAN zone.
Faisal Posted 21 Aug 2020 08:07
  
Thank you very much for the information ...
Muhammad Bilal Lv4Posted 14 Sep 2020 02:50
  
Thanks for sharing
Faisal Posted 23 Oct 2020 08:40
  
Nice article ...
Faisal Posted 18 Dec 2020 10:13
  
Great info ...
Ellechar Lv4Posted 26 Jan 2021 15:30
  
Very nice infoooooooooooooooooooooooooooooo
Faisal Posted 19 Mar 2021 07:17
  
Very informative …
Faisal Posted 04 Jun 2021 12:15
  
Nice guidance ...

I want to write a case
Doc ID: 2368
Author: Niubility
Updated: 2019-12-22 18:35
Version: