Thursday, May 6, 2021

Routing, firewall and VPN restrictions

Hi all

Can I get some clarification on the following ?

We have a small site that is running a Cisco router with its firewall turned on, no IPSec VPN is configured - its WAN is configured for straight fiber internet.

I've since created a few firewall rules to restrict all outbound traffic from the local LAN to our VPN IP - so that when users are plugged into the LAN, the only way to get access to the internet or internal resources is to generate and connect to our client VPN.

During testing - I can browse direct to the VPN portal via IP and log in - DNS fails ( assuming this is because the firewall rules are specific to IP )

However when I attempt to connect using the GlobalProtect app - it establishes connection but fails to authenticate

I was wondering if Global Protect or any client VPN for that matter requires or needs to detect an active internet connection to work ?



No comments:

Post a Comment