客户端能够正常登陆并获取地址,但是无法访问内网,各种ping不通,请大神给排查一下配置问题。
object-group service 4433
0 service tcp destination eq 4433
#
interface SSLVPN-AC1
ip address 10.168.21.253 255.255.255.192
#
security-zone name Local
#
security-zone name Trust
import interface Ten-GigabitEthernet1/0/20
import interface Vlan-interface231
import vlan 16 18 21 211 to 214 231 to 234
#
security-zone name DMZ
#
security-zone name SSLVPN
import interface SSLVPN-AC1
#
#
ip route-static 0.0.0.0 0 83.237.62.157
ip route-static 10.168.16.0 21 192.168.99.2
#
acl advanced 3999
rule 0 permit ip
#
ldap server svpn
login-dn cn=h3c-ad-reader,ou=services,ou=it-management,dc=eur,dc=gwm,dc=com
search-base-dn ou=haval,dc=eur,dc=gwm,dc=com
ip 10.168.22.10
login-password cipher $c$3$w5LIBWj+bjIIhc/RelvbwoncRSW1q5MGk86rf1Csrg==
user-parameters user-name-attribute samaccountname
#
ldap scheme svpn
authentication-server svpn
authorization-server svpn
#
domain svpn
authorization-attribute user-group svpn
authentication sslvpn ldap-scheme svpn
authorization sslvpn ldap-scheme svpn
accounting sslvpn none
#
user-group svpn
authorization-attribute sslvpn-policy-group SSLVPNRESOURCE
#
user-group system
#
sslvpn ip address-pool SSLPOOL 10.168.21.193 10.168.21.252
#
sslvpn gateway sslvpngw
ip address 83.237.62.158 port 4433
service enable
#
sslvpn context SSLVPN
gateway sslvpngw
ip-tunnel interface SSLVPN-AC1
ip-tunnel address-pool SSLPOOL mask 255.255.255.192
ip-tunnel dns-server primary 10.168.22.10
ip-tunnel dns-server secondary 10.168.22.11
ip-route-list intranet
include 10.168.16.0 255.255.248.0
include 10.168.21.192 255.255.255.192
policy-group SSLVPNRESOURCE
filter ip-tunnel acl 3999
ip-tunnel access-route ip-route-list intranet
aaa domain svpn
service enable
#
security-policy ip
rule 2 name GuideSecPolicy
action pass
source-zone Trust
source-zone Local
source-zone DMZ
source-zone Untrust
destination-zone Untrust
destination-zone DMZ
destination-zone Local
destination-zone Trust
rule 14 name Untrst-Local
action pass
source-zone Untrust
destination-zone local
service 4433
rule 15 name SSLVPN-Trust
action pass
source-zone SSLVPN
destination-zone Trust
destination-zone Local
destination-zone LDAP
rule 20 name DMZ-local
action pass
source-zone DMZ
source-zone local
destination-zone DMZ
destination-zone local
看下防火墙本身带原地址是ssl vpn地址池网关,目的是需要访问的内网能通吗?网关在核心的话看下有没有路由
在PC上追踪路由,可以到SSLvpn地址池网关10.168.21.253,后面就没有了。这是什么情况?
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
在PC上追踪路由,可以到SSLvpn地址池网关10.168.21.253,后面就没有了。这是什么情况?