This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

INVALID_TRAFFIC on SSL VPN to LAN, cannot connect to HTTPS site

Hello,

We are having an issue with our SSL VPN clients not being able to connect to an HTTPS site that is hosted at a third party datacenter. We've been working with the 3rd party and it's looking like things are pointing back at the XG. I have VPN to LAN and LAN to VPN rules, and the third party network is in the permitted network resources section. That all looks good.

See diagram for an idea of how this is set up.

The XG packet capture states that there is a violation due to INVALID_TRAFFIC and the site never loads. However traceroute and ping go through OK.

If put Wireshark in between our DEFAULT GATEWAY and the THIRD PARTY ROUTER, I do not get any packets coming from the SSL VPN network, when I try to load the HTTPS site. None.
Again Traceroute and ping traffic show up.

Do you have any ideas?

Thank you!



This thread was automatically locked due to age.
Parents Reply
  • FormerMember
    0 FormerMember in reply to svk253

    The firewall rules generally in the XG are very difficult to understand. It would be helpful to simply have a checkbox that says use split tunnel or not and have it create the proper firewall rules.

Children
No Data