Starlink and SSL VPN

Has anyone setup SSL VPN over Starlink yet? I am being told that StarLink, and / or Xplornet does not support watchguard vpn over satellite networks... ?

Comments

  • Hi @combat_keith
    As far as I'm aware there's no reason it shouldn't work. You may have trouble setting up a server if that ISP restricts inbound access to the firewall.

    WatchGuard's SSLVPN is based on OpenVPN, so if OpenVPN works, SSLVPN is likely to as well.

    Doing some cursory research on the internet suggests that it works for some users and does not work for others. For users having issues, It may be down to connection condition, load on their system, or something else.

    The firebox does offer SSLVPN, IPSec (IKEv1,) IKEv2, and L2TP VPN options, so if there's an issue with one, there's several others you can try with.

  • If I understand correctly, and that's open to debate, starlink provide us with a Non Routable IP address in the 100.64.0.0/10 range as such I believe we can initiate a VPN connection to somewhere else from a starlink connected client, but I don't see how someone else outside our network can connect to this non routable IP address.

    So if your VPN Client is on Starlink and the VPN Server is elsewhere on the internet then all should work. If the VPN Server is on the starlink connection and the clients are elsewhere then unless the connection is server side initiated I dont see how you could get it to work.

    From the Starlink networking FAQ's SSL based VPNS work, however VPNS that rely on GRE, ESP, AH, L2TP are dropped by the CGNAT that Starlink use

  • Are there special configurations for SSL VPN?

    My Watchguard FW & network is on Starlink, my mobile ssl clients are on fiber internet.

    When attempting to connect it seems to connect but never gets past "waiting for initial response from the server"

  • Read the post above yours.

    Your firewall is not accessible from the Internet since the Starlink CGNAT setup doesn't allow it - thus SSLVPN clients can't connect to it.

  • Thanks, that was four-years ago, wasn't sure if things changed…

    when i queried Starlink, i got this response:

    Starlink supports SSL VPNs like WatchGuard, as they typically use
    TCP/UDP protocols that work well with our CGNAT setup. If you're
    experiencing issues, ensure NAT traversal is enabled on your VPN
    configuration, and note that VPNs can sometimes impact
    performance—contact WatchGuard support for specific troubleshooting

    I don't understand the NAT traversal setting?

    thanks again

  • This explains NAT traversal for a BOVPN.

    https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/bovpn/manual/vpn_nat_c.html

    However, this doesn't help you since the firewall is not accessible from the Internet for your SSLVPN clients or any other VPN client.

    The Google AI answer:

    Accessing a device behind Starlink from the internet is difficult because Starlink uses CGNAT (Carrier-Grade NAT), meaning it does not assign a public, routable IPv4 address to your router and does not support traditional port forwarding.

  • One solution could be WatchGuard FireCloud and its private access.

    There was an error displaying this embed.

  • kimmo - how does Firecloud help with access to a firewall behind a Starlink connection and thus to resources behind that firewall?

    It isn't obvious to me.

    Thanks

  • There are cloud hosted connection services, such as remote access tools, which can allow connection to a PC or server behind a Starlink connected firewall because the PC or server makes a connection to the cloud service, and the remote user connects to the cloud service.

    One example is RealVNC Connect

  • Seems you haven't looked at the wonderful new word of SASE :-)


    Here both the clients and the gateway(s), that can be a Firebox, Virtual Gateway, or Gateway app you install to win server, connect to a FireCloud PoP. So, both the clients and the gateway can be behind the Starlink connection.

    https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/FireCloud/private_resources_add.html

  • Thanks - Acronym, not word :-)

    https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/FireCloud/gateway_firebox_configure.html

    Look like this is the concept I didn't know about from WG. Too many new things for us old timers to keep track of….

  • actually, i meant to say ”new world of SASE” 😆

  • Prior to today, SASE to me was Self Addressed Stamped Envelope, so yes it a new world