Monday, April 8, 2019

Troubleshooting "Always on VPN" passing trough PA firewall

Hi,

I've been troubleshooting VPN connectivity issues for a end-user on one of our clients shared-office locations. I understand they are attempting to connect the client to a remote access server using IKEv2, and the VPN server works fine when the client is connected to other networks.

We have two PA-820s in an active/passive HA setup. I'm still trying to wrap my head around how IKEv2 works with regards to NAT, MTU and etc., but I'm getting nowhere. Where should I begin to look to identify the issue from the FW?

Some screenshots from traffic monitor, packet capture and session browser:

https://imgur.com/a/E4GhvO6

The end user is reporting VPN error 809 on the Win10 client.



No comments:

Post a Comment