SSL VPN some traffic through VPN
Hello,
wer're running an M200. Mobile Users connecting via SSL VPN. Split tunneling is activate.
We have a request that traffic to a certain IP has to be route through the Fireboc.
I put the remote IP in the SSL VPN settings.
In traffic monitor I can see traffic ti this IP. However the website does not open.
Putting a policy to allow traffic from Any to the VPN network doesn't help either.
Only traffic to a single remote IP over a single Port is neccessary.
What do I have to configure?
Thank you.
Gemini
Best Answer
-
Turn on Logging on any policies which you think will allow this access so that you see access attempts in Traffic Monitor.
You can test this access using the SSLVPN client from behind the firewall.
Make sure that the Dynamic NAT settings still have the 3 private supernets and that one of them includes the SSLVPN virtual IP subnet.
5
Answers
-
It seems to work. We can test more tomorrow. Thank you!
The SSLVPN net was not in the DNAT settings.0 -
Rarely is there a need to remove/modify the 3 default Dynamic NAT settings.
And, as you have seen, doing so can cause issues.0 -
I just add our SSLVPN 192.168.113.0/24 even the range is already include in 192.168.0.0/16.0
-
If prior to adding this entry, you only have the 3 default entries, then I don't see how adding this entry really helped here.
0 -
Bruce, you're absolutely right.
Got wrong IP from the Service Provider
Now it works like a charm.0
