Branch side unable to ping HQ side LAN segment

|
  • 149
  • 3

Issue Description

When configured Sangfor VPN, HQ side able to ping Branch side LAN segment, but Branch side unable to ping HQ LAN segment.

Error/Warning Information

When perform ping HQ side LAN segment from Branch side NGAF, it should unreachable.

Handling Process

1. Check both side configuration, there is no issue and the status is up.
2. Checked SNAT, application control policy, the configuration no issue, didn't block the traffic.
3. Perform packet capture from Branch side, find out the HQ side LAN segment didn't return packet. The source IP address has been changed, the IP address should be 192.168.x.x.

4. Check the Interfaces zone, the vpntun is located as WAN.

Root Cause

1. The root cause is the vpntun located as WAN zone, and it IP address has changed.

Solution

1. Create a now zone and change the vpntun location to the new zone for both side NGAF.
2. After changed the zone, the source IP has been changed to normal as below blue highlighted and it has return packet.
Muhammad Bilal Lv4Posted 06 Jan 2022 16:36
  
Nice Issue Description
Faisal Posted 10 Apr 2022 23:21
  
Raza Islam Lv3Posted 04 Jul 2022 19:43
  
Thanks for sharing.

I want to write a case
Doc ID: 5261
Author: EnN
Updated: 2022-01-05 18:24
Version: