Cannot access internet sites via VPN gateway even though IPSEC tunnel is up and active
search cancel

Cannot access internet sites via VPN gateway even though IPSEC tunnel is up and active

book

Article ID: 246252

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG

Issue/Introduction

Users access internet via WSS using IPSEC tunnels.

New IPSEC tunnel added for remote location where users cannot access internet - browser reporting connectivity errors to whatever site user accesses, and browser HAR file shows no responses to requests. 

IPSEC tunnel logs indicate tunnel is up and running.

PCAPs from host client show no HTTP requests go out.

 

Cause

DNS configured to go to internet DNS server but WSS does not have all VPN ports enabled.

Resolution

Changed DNS to point to a local DNS server and all worked fine.

Alternatively, could have enabled VPN all ports license to route DNS traffic to public DNS servers.