Good evening, I configured a SSL VPN on two different NGAF, both with private IP on the WAN and full nat from the internet to the WAN NGAF.
The VPN client is authenticated but the ping response from the remote host works only after 40-50 seconds.
The route on the VPN client PC appears, but the ping response is delayed. What should I set?



Enrico Vanzetto has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

hi, perform a trace route to see where your traffic is going on. After that, double check your firewall rules. On nsf's web ui, go to system -> troulbeshooting and performa a precise traffic analysis to check your traffic. If you still don't see anythong, enable global passthrough and do some traffic from a client connected to vpn ssl and check what policies are matched.
Is this answer helpful?
Newbie906049 Posted Mar-07-2025 15:03
  
Thanks for answer
Maximilian Lv1Posted Mar-04-2025 04:44
  
Sorry for not answering right away, but there was an exchange of emails and tests with Sangfor support.
The problem indicated is only present with W11. To update you today they sent me a new installer that solved the problem. Thanks
AR Lv2Posted Feb-26-2025 14:09
  
Hello,
Use the trace route to find out where your traffic is going.  Next, review your firewall rules one more time.  To check your traffic, navigate to system -> troubleshooting on the nsf online user interface and do a thorough traffic analysis.  Enable global passthrough, send some traffic from a client connected to a VPN SSL, and observe which policies match if you're still not seeing anything.
Maximilian Lv1Posted Feb-26-2025 00:44
  
Ciao, grazie per la risposta. Ti informo che una volta instaurata la VPN e facendo un ping verso un host della rete remota sniffando il traffico sia sul tunnel ssl che sull'interfaccia nonn c'è traccia di traffico ICMP.
Passati quei 30-40 secondi troviamo traffico ICMP sia su tunnel SSL che su LAN remota.
Aggiungo che ho installato easyconnect su macchina virtuale Windows 10 il problema non si presenta. Le installazioni delel 3 macchine con easyconnect eranon tutte su windows 11, macchine appena fornite. Pertanto sembra che il client Easyconnect su windows 11 è come se trovi dell'inerzia ad instradare il traffico nonostante compaia da subito sulle rotte delle reti facendo un routeprint da CLI

I Can Help:

Change

Moderator on This Board

1
148
3

Started Topics

Followers

Follow

917
183
94

Started Topics

Followers

Follow

Board Leaders