Client has configure SSL VPN but found that unable to access the web UI through LAN IP

|
  • 2319
  • 23

Issue Description

Client has configured SSL VPN for LAN segment, it included the LAN IP of the NGAF. All other connection is normal but when user want to use the LAN IP to manage the NGAF, he found that he not able to access the web UI.

Handling Process

  • Try direct access from the LAN, it able to access to the web UI as usual.
  • Try ping to the LAN IP through SSL VPN, ping is successful.
  • Try telnet to the 80 and 443 port, found that it unable to telnet 443 port.
  • Check on the SSL VPN resources configuration, it configured as L3VPN with all port.
  • Try to enable troubleshooting pass-through, found that it able to access web UI after enable pass-through.


Root Cause

Found that it has packer drop by zone service, check on the zone configuration and found that the Allow address to the zone is not include the VPN virtual ip segment.

Solution

You can change the Allow IP Address to All or you can add an IP group for the SSL virtual IP.
bramtorvalds Lv4Posted 25 Feb 2020 13:19
  
thanks for sharing this solution
marlissn Lv2Posted 05 Mar 2020 09:29
  
Great information
Johannes Lv4Posted 10 Mar 2020 12:04
  
great  sharing   
Apriyanto Lv5Posted 10 Mar 2020 16:24
  
thanks for explain
Bewok Lv3Posted 11 Mar 2020 18:16
  
great explain
amdhan Lv3Posted 17 Mar 2020 10:59
  
Great information
Yanto Peong Lv3Posted 18 Mar 2020 18:15
  
very helpful
adam_ssc Lv3Posted 18 Mar 2020 18:29
  
great and detailed knowledge
Rickysut Lv3Posted 18 Mar 2020 18:40
  
thank you for share

I want to write a case
Doc ID: 3062
Author: Newbie280530
Updated: 2020-02-24 10:43
Version: