This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VPN Internal Connectivity

So, just got the device setup. Things are going pretty well. Now I'm just working on my OpenVPN connection to it from an Android phone. 

 

I'm unable to reach anything from the VPN connected device to the internal network. What I get in the logs is this:

 

messageid="05201" log_type="Firewall" log_component="SSL VPN" log_subtype="Denied" status="Deny" con_duration="0" fw_rule_id="0" policy_type="0" user="" user_group="" web_policy_id="0" ips_policy_id="0" appfilter_policy_id="0" app_name="" app_risk="0" app_technology="" app_category="" in_interface="tun0" out_interface="" src_mac="" src_ip="10.81.234.8" src_country="" dst_ip="192.168.1.44" dst_country="" protocol="TCP" src_port="58188" dst_port="8112" packets_sent="0" packets_received="0" bytes_sent="0" bytes_received="0" src_trans_ip="" src_trans_port="0" dst_trans_ip="" dst_trans_port="0" src_zone_type="" src_zone="" dst_zone_type="" dst_zone="" con_direction="" con_id="" virt_con_id="" hb_status="No Heartbeat" message="" appresolvedby="Signature" app_is_cloud="0"

 

I'm not entirely clear how my in_interface is "tun0" (ok, that makes sense) but, but out_interface is "". I'm trying to hit 192.168.1.44, which is the directly connected LAN interface. 

My rules are as simple as can be:

 

 

I have noticed that I have a VPN zone, but I can't do anything to it:

 

So, I feel like I'm missing some basic concept here. Any suggestions?



This thread was automatically locked due to age.
Parents
  • Hi,

    Can you show us the VPN Config? 

    Do you have the LAN Network as permitted networks? 

  • VPN config is pretty minimal, really: 

     

     

    Following your advice to the other guy, I do the tcpdump and get this:

     

    10:48:37.510046 Port1, OUT: IP 192.168.1.1 > 192.168.1.67: ICMP echo reply, id 0
    , seq 0, length 24
    10:48:38.733885 Port1, IN: IP 192.168.1.122 > 192.168.1.1: ICMP echo request, id
    0, seq 0, length 24
    10:48:38.733932 Port1, OUT: IP 192.168.1.1 > 192.168.1.122: ICMP echo reply, id
    0, seq 0, length 24
    10:48:40.937763 tun0, IN: IP 10.81.234.6 > 192.168.1.44: ICMP echo request, id 7
    2, seq 1, length 64
    10:48:42.456905 Port1, IN: IP 192.168.1.123 > 192.168.1.1: ICMP echo request, id
    0, seq 0, length 24
    10:48:42.456991 Port1, OUT: IP 192.168.1.1 > 192.168.1.123: ICMP echo reply, id
    0, seq 0, length 24
    10:48:45.013543 tun0, IN: IP 10.81.234.6 > 192.168.1.44: ICMP echo request, id 7
    3, seq 1, length 64
    10:48:45.800501 Port1, IN: IP 192.168.1.125 > 192.168.1.1: ICMP echo request, id
    0, seq 0, length 24
    10:48:45.800551 Port1, OUT: IP 192.168.1.1 > 192.168.1.125: ICMP echo reply, id
    0, seq 0, length 24
    10:48:47.515220 Port1, IN: IP 192.168.1.67 > 192.168.1.1: ICMP echo request, id
    0, seq 0, length 24
    10:48:47.515264 Port1, OUT: IP 192.168.1.1 > 192.168.1.67: ICMP echo reply, id 0
    , seq 0, length 24
    10:48:48.737377 Port1, IN: IP 192.168.1.122 > 192.168.1.1: ICMP echo request, id
    0, seq 0, length 24
    10:48:48.737459 Port1, OUT: IP 192.168.1.1 > 192.168.1.122: ICMP echo reply, id
    0, seq 0, length 24
    10:48:49.061747 tun0, IN: IP 10.81.234.6 > 192.168.1.44: ICMP echo request, id 7
    4, seq 1, length 64
    10:48:52.461448 Port1, IN: IP 192.168.1.123 > 192.168.1.1: ICMP echo request, id
    0, seq 0, length 24
    10:48:52.461498 Port1, OUT: IP 192.168.1.1 > 192.168.1.123: ICMP echo reply, id
    0, seq 0, length 24

     

    The traffic of interest is the 10.81.234.6 to the 192.168.1.44. So, the requests are hitting the firewall. But I see no evidence of that traffic being processed by any firewall rules. I can see the phone talking to the internet through the VPN and firewall, but nothing inbound seems to even hit a rule. 

Reply
  • VPN config is pretty minimal, really: 

     

     

    Following your advice to the other guy, I do the tcpdump and get this:

     

    10:48:37.510046 Port1, OUT: IP 192.168.1.1 > 192.168.1.67: ICMP echo reply, id 0
    , seq 0, length 24
    10:48:38.733885 Port1, IN: IP 192.168.1.122 > 192.168.1.1: ICMP echo request, id
    0, seq 0, length 24
    10:48:38.733932 Port1, OUT: IP 192.168.1.1 > 192.168.1.122: ICMP echo reply, id
    0, seq 0, length 24
    10:48:40.937763 tun0, IN: IP 10.81.234.6 > 192.168.1.44: ICMP echo request, id 7
    2, seq 1, length 64
    10:48:42.456905 Port1, IN: IP 192.168.1.123 > 192.168.1.1: ICMP echo request, id
    0, seq 0, length 24
    10:48:42.456991 Port1, OUT: IP 192.168.1.1 > 192.168.1.123: ICMP echo reply, id
    0, seq 0, length 24
    10:48:45.013543 tun0, IN: IP 10.81.234.6 > 192.168.1.44: ICMP echo request, id 7
    3, seq 1, length 64
    10:48:45.800501 Port1, IN: IP 192.168.1.125 > 192.168.1.1: ICMP echo request, id
    0, seq 0, length 24
    10:48:45.800551 Port1, OUT: IP 192.168.1.1 > 192.168.1.125: ICMP echo reply, id
    0, seq 0, length 24
    10:48:47.515220 Port1, IN: IP 192.168.1.67 > 192.168.1.1: ICMP echo request, id
    0, seq 0, length 24
    10:48:47.515264 Port1, OUT: IP 192.168.1.1 > 192.168.1.67: ICMP echo reply, id 0
    , seq 0, length 24
    10:48:48.737377 Port1, IN: IP 192.168.1.122 > 192.168.1.1: ICMP echo request, id
    0, seq 0, length 24
    10:48:48.737459 Port1, OUT: IP 192.168.1.1 > 192.168.1.122: ICMP echo reply, id
    0, seq 0, length 24
    10:48:49.061747 tun0, IN: IP 10.81.234.6 > 192.168.1.44: ICMP echo request, id 7
    4, seq 1, length 64
    10:48:52.461448 Port1, IN: IP 192.168.1.123 > 192.168.1.1: ICMP echo request, id
    0, seq 0, length 24
    10:48:52.461498 Port1, OUT: IP 192.168.1.1 > 192.168.1.123: ICMP echo reply, id
    0, seq 0, length 24

     

    The traffic of interest is the 10.81.234.6 to the 192.168.1.44. So, the requests are hitting the firewall. But I see no evidence of that traffic being processed by any firewall rules. I can see the phone talking to the internet through the VPN and firewall, but nothing inbound seems to even hit a rule. 

Children