Skip to main content
Gabana
New Member
February 1, 2018
Question

SSL VPN traffic and Virtual IP

  • February 1, 2018
  • 1 reply
  • 11865 views

Hi this is Payam and this is my first post here :) we have an issue and this is about SSL VPN and Virtual IPs when we connect to our network with SSL VPN we can not access Objects with their Virtual IP but that object is accessible with its local IP address. there is no same zone between SSL VPN interface and the interface that we use to access the object also the rule is from our source , from SSL VPN interface to All with service All   can anyone help to solve this issue ?

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    February 1, 2018

    First, Welcome!

    Then, does the route exist back from the objects toward the SSL VPN client IPs? Also if it's split tunnel, is the objects' subnet specified in the portal config as well as the other subnets they need to reach?

    Gabana
    GabanaAuthor
    New Member
    February 13, 2018

    yes the route exists

    the problem is we can not define VIP in the rule, only if i use any ad incoming interface then we can use VIP.

    Toshi_Esumi
    SuperUser
    SuperUser
    February 13, 2018

    I think the problem is extintf/extip of your VIP is bound to the external interface facing the internet. SSL VPN is coming past that interface and terminated inside. So can't access the outside of the external interface. The same thing would happen when you try accessing outside interface of VIP from a local device connected to internal interface.

    Why don't you use the local IP of the servers to access them via SSL VPN? That's the whole purpose of SSL VPN. VIP is for the access coming from Internet without a VPN.