VPN Communication Failure: Unable To Obtain Internet IP

|
  • 551
  • 16

Issue Description

Sangfor VPN established but unable to access to local subnet

Handling Process

  • Confirmed that the IP is in the local subnet
  • Confirmed that the routing has no issue
  • Check on VPN status, saw that there is no Internet IP


Root Cause


When Internet IP is not obtained, fake connection is established. This fake connection is unable to allow access to local subnet.
This type of issue is normally seen when using UDP transmission protocol to build VPN. When using this type of transmission protocol to build VPN, TCP protocol will be used for the three-way handshake, after successfully performed the three-way handshake, UDP protocol will be used for communication.
If there are issue with the traffic for example packet drop or traffic blocked, the issue of unable to obtain Internet IP will occur.

Solution

  • Ensure HQ has stable UDP port connection and UDP port forward
  • Or modify the transmission protocol of the VPN connection in branch device TCP






Newbie280530 Lv3Posted 26 Dec 2019 17:44
  
Bewok Lv3Posted 21 Jan 2020 16:44
  
good information
Sangfor_Brando Lv5Posted 26 Feb 2020 09:09
  
Very useful.
Muhammad Bilal Lv4Posted 13 Aug 2020 19:50
  
Great information
Faisal Posted 28 Aug 2020 08:22
  
Thank you very much for the information ...
Osama Muhammad Lv3Posted 28 Aug 2020 15:15
  
Thanks for sharing great info
Faisal Posted 14 Oct 2020 09:48
  
Nice article ...
Faisal Posted 25 Dec 2020 09:45
  
Great info ...
Faisal Posted 31 Dec 2020 07:03
  
Very informative

I want to write a case
Doc ID: 2391
Author: CTI TF
Updated: 2019-12-20 16:07
Version: