This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Setup Question LAN/WAN VPN

Hi !

I'm quite new to XG Firewall. I've got the following Setup:

XG Softwarebased setup on 2 Lan Card PC

Port 1 LAN with Range from 192.168.1...

Port 2 WAN with Statik IP 192.168.3.... getting it from Router LAN

Router with static IP Adress 77.119 ... connected to WAN (Mobile Carrier). 

The Router forwards relevant Ports for RD Services and so on to Port 2 of XG

Everything works fine except SSL-VPN - this is set up properly to forward into LAN Zone.

I cannot seem to setup a connection from outside of the network. I forward Port 8443 for SSL-VPN from the router to Port 2 of XG with no effect.

The client seems to cannot setup a connection since it always tries to reach 192.168.3... and not the external router IP from the carrier.

Actually I have no idea where to set this up. Can anyone help here?

Regards

hinze



This thread was automatically locked due to age.
Parents
  • Hey Hinze,

    In order to properly specify that your clients attempt the SSL VPN connection via your upstream ISP router's WAN IP, please fill in the "Override Hostname" field with this IP.

    Configure > VPN > top right "Show VPN Settings" 

    Please note that updating the settings in this menu will require a re-download of the SSL VPN configuration from the user portal.

    Let me know if you run into any issues.

    Regards,

  • Thanks Flo! 

    works perfectly fine! 

    I'can get in the SSLVPN IP Range now, I've setup the vpn rules VPN to LAN - LAN to VPN and general network policiees LAN to all zones as suggested in the documentation but I'll always get an VPN Range IP for my remote device and not the one from the local subnet that I specified .

    Is there anything more I can do to be forwarded to the local subnet?

    I've studied several community articles on this matter but none seems to help.

    Strange...

  • "t I'll always get an VPN Range IP for my remote device and not the one from the local subnet that I specified ."

     

    That is how this works.

    Basically you get a IP from the Pool and for every other device attached to XG, you are just a other subnet. 

    The client does not get any IP of any Lan Client. Instead XG will just route the traffic to the correct network. 

    Can you post some screenshots of your VPN config? Maybe there is a mistake. 

  • Hm, but how can I get to my server, if the VPN does not forward me to the local subnet where the server is located.

    In the SSLVPN IP Range there is no device. This is why I set up a rule to define the source vpn and the target lan network... 

  • Try to disable Masquarding on the Policy. 

    As far as i can see, this should work even with masq on. 

    Can you show us what is in the Objects "Lan Netzwerk" and "SSLIPRANGE" ? 

  • If ve also tried masquarading... no effect.

    See the objects below... If've tried different settings now so images may vary a bit from the above

  • Here is the Port structure...

  • Can you shortly explain, where and what exactly fails in your setup?

    Show us your current live user tab after you connect one client via SSL VPN. It should shown there. 

    Then try to ping a client behind XG. You get a timeout? 

    What do you try to reach and how? 

    Do you use DNS or IP to ping? 

  • Hi!

    Here is the live user tab...

    I'm connected and the adapter gets an IP within the SSLVPN IPRange. 

    I've tried to ping the server from the client outside - and it works - i can also ping the nas and so on in the 192.168.1... range but I cannot open network drives or the servers folders since the vpn IP is in the 10.. range

  • I've got it!

    I've added the domain admin server as the dns server in the vpn settings - this helps getting all the things done!

    Kudos and many thanks to all that helped!

Reply Children