SSL VPN traffic being block by the policy

|
  • 288
  • 2

Issue Description

The ping test from the SSL endpoint is failed. Verify on the NGAF backend identify that the traffic ICMP traffic has been sent to server but the server does not response to the ICMP request.

Verify from the traffic analaysis identify that the SSL VPN traffic is being block by the policy.

Handling Process

Verify the policy that block the SSL traffic. The destination and the source zone is selected Any, which result the policy is matched the SSL VPN traffic.

Solution

The solution for this issue is finetune the policy by only select the zone being used on the environment.
ArsalanAli Lv3Posted 08 Dec 2023 13:43
  
There must the application control policy which is blocking this traffic
Enrico Vanzetto Lv3Posted 08 Dec 2023 16:10
  
hi, if we need to allow icmp traffic, simply create a dedicated rule before the rule that deny all traffic.

I want to write a case
Doc ID: 9351
Author: Ted3
Updated: 2023-10-06 11:13
Version: