Unable to access internal resources from sslvpn

Newbie164021 Lv1Posted 10 Jun 2024 13:30

Unable to access internal resources from sslvpn subnet

pmateus has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Hi,

This usually is related with missing routes. Try to check if your networks have routes from SSLVPN subnet to internal resources subnet and from internal subnet to sslvpn subnet too.
Is this answer helpful?
Prosi Lv3Posted 11 Jun 2024 11:20
  
Hi

Open the IE browser and enter the SSL VPN address and HTTPS port
(https://10.254.254.254:4430) into the address bar. Press Enter key to visit the login page to SSLVPN administrator Web console

SSO: With this license, Single Sign-On (SSO) feature can apply to users access to the SSLVPN.

Once multiline policy of SSL VPN is enabled, the line selection policy will help the systemautomatically detect the lines and choose the optimal one to let the user connect in faster
when it accesses the SSL VPN, improving the data transfer and stability of SSLVPNconnections.  SSL VPN users connect in directly(local device owns public IP): If Sangfor device is
deployed in gateway mode, and owns public IP, then VPN user can connect it directly.  SSL VPN users connect in via front-end device(local device owns no public IPaddress): If Sangfor device is deployed on Intranet and does not own public IP, thenVPN users connect in via front-end device.  If the Sangfor device is deployed in gateway mode and SSL VPN users connect in viafront-end device(local device owns no public IP address) option is selected, and needs
to use multiple Internet lines, map front-end network device’s public addresses to the
Sangfor device and launch the ports, simply by configuring port mapping rules under
Lines Of Front-End Device. To do that, click Add to enter the Edit Line for SSLVPNpage
Adam Suhail Lv1Posted 11 Jun 2024 11:24
  
In order to reach to the internal resources , you need to define the network segments or ip address at ssl vpn > resource , Make sure the ssl user roles is link to the resource defined.
mdamores Lv3Posted 11 Jun 2024 12:04
  
Hi,

Can you try the following?

1. Try creating Layer 3 VPN then assign all preferred IP pool to the VPN that you created
2. try adding role, then assign it to the Layer VPN that you created
3. Try to create a user then assign it to the role that you created.
4. Optional: try adding alternate public DNS like 8.8.8.8 or 8.8.4.4

hope this work
CLELUQMAN Lv3Posted 11 Jun 2024 12:57
  
can u verify if u can connect to the ssl vpn or no?

how many user are affected?
Newbie429120 Lv1Posted 11 Jun 2024 13:44
  
Hi there,
Sorry to hear about the trouble accessing internal resources from the SSLVPN subnet. Could you provide more details about the issue? It could be related to network configurations or permissions. Let's troubleshoot together to resolve this.
Newbie164021 Lv1Posted 11 Jun 2024 15:02
  
For NSF models, there a new features which you can customize the routing precedence on the network.
My problem is the firewall having problem send back the packet to the SSL Subnet, the resolution was to change the routing precedence and make the SSLVPN routes next to direct routes and that resolved my issue.
Newbie517762 Lv5Posted 11 Jun 2024 15:24
  
HiHi,

Pls find the attached file the link - "Sangfor VPN Success Build Up But Some Subnet Cannot Ping To Other Side" for your Ref.
Sangfor VPN Success Build Up But Some Subnet Cannot Ping To Other Side.pdf (48.35 KB, Downloads: 112)
Taha Lv2Posted 11 Jun 2024 15:56
  
May there is wrong configuration at some end .Please follow the guide for correct configuration of ssl Vpn from support community .
pmateus Lv2Posted 11 Jun 2024 16:33
  
Hi,

This usually is related with missing routes. Try to check if your networks have routes from SSLVPN subnet to internal resources subnet and from internal subnet to sslvpn subnet too.

I Can Help:

Change

Moderator on This Board

11
3
4

Started Topics

Followers

Follow

1
1
5

Started Topics

Followers

Follow

0
2
4

Started Topics

Followers

Follow

67
17
3

Started Topics

Followers

Follow

3
6
3

Started Topics

Followers

Follow

1
135
3

Started Topics

Followers

Follow

Board Leaders