This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Client VPN Software - Connecting China to Canada

Morning,

I am in need of some serious help. I have not been very successful getting our staff connected back to AD thru VPN when they visit China. When I first installed the XG product back in Oct 2017, trying to save money I decided to move away from IPSec VPN for client access to SSL-VPN. Overall this has been very successful, reliable. If you are not aware China has been tightening a lot of its network through the Great China Wall so it has had many adverse effects on business trying to communicate outside the country. When one of our staff went to China and tried to connect using SSL-VPN, it was completely unsuccessful, so upon returning back to Canada I then setup IPSec as well. Now keep in mind both SSL-VPN and IPSec VPN configurations work everywhere we have visited with the exception of China, almost. When a second staff recently went to China we had both SSL and IPSec to test, the first night the staff were able to use their new IPSec client software to connect back to AD in Canada, after that , it no longer worked. It doesn't even get to the point of bringing up the login authentication window. 

Here is the caveat, our clients who visit at our same location are successfully connecting using their IPSec client software, also back to Canada. I just got off the phone with the client's IT department and they didn't give me too much information on their setup but they said there VPN setup includes the client software connecting to a cloud authentication and from there it makes its connection back to Canada, without much detail I'm a bit lost because I have never used this type of setup and wondering if anyone could possibly point me in the right direction to hopefully get our staff back online when in China. So basically my VPN setup is direct but our clients is using a middleman, that I am not familiar with at all.

Sorry for the winded explanation. Thank you.



This thread was automatically locked due to age.
  • I'm not sure how your client was able to bypass it but you can change ssl vpn port from tcp to udp and check.Your staff should download the config file again after changing from tcp to udp.

  • Interesting you said that, I changed our VPN setting to UDP, 2 days ago because of speed issues. Our client isn't using their IPSec VPN direct back to their network, as we do, but through a cloud authenticating mechanism ( or middleman as they called it ) I think what they are referring to is Two-Factor authentication.