在防火墙设置的SSLVPN,成功接入了,但无法获取到网关地址,无法互联互通
(0)
您好,当您在防火墙配置的SSLVPN成功接入后,无法获取到网关地址或无法互联互通时,可以按照以下步骤进行排查和解决:
[H3C] sslvpn gateway
[H3C-sslvpn-gateway-SSLVPNGW] ip address 222.1.1.100 port 4433
[H3C-sslvpn-gateway-SSLVPNGW] service enable
[H3C-sslvpn-gateway-SSLVPNGW] quit
[H3C] interface SSLVPN-AC 1
[H3C-SSLVPN-AC1] ip address 10.10.10.1 255.255.255.0
[H3C-SSLVPN-AC1] quit
[H3C] acl advanced 3999
[H3C-acl-ipv4-adv-3999] rule permit ip destination 192.168.10.0 0.0.0.255
[H3C-acl-ipv4-adv-3999] quit
[H3C] sslvpn context SSLVPN
[H3C-sslvpn-context-SSLVPN] gateway SSLVPNGW
[H3C-sslvpn-context-SSLVPN] ip-tunnel interface SSLVPN-AC1
[H3C-sslvpn-context-SSLVPN] ip-tunnel address-pool SSLPOOL mask 255.255.255.0
[H3C-sslvpn-context-SSLVPN] ip-tunnel dns-server primary 114.114.114.114
[H3C-sslvpn-context-SSLVPN] ip-route-list NEIWANG
[H3C-sslvpn-context-SSLVPN-route-list-NEIWANG] include 192.168.10.0 255.255.255.0
[H3C-sslvpn-context-SSLVPN] policy-group SSLVPNZIYUAN
[H3C-sslvpn-context-SSLVPN-policy-group-SSLVPNZIYUAN] filter ip-tunnel acl 3999
[H3C-sslvpn-context-SSLVPN-policy-group-SSLVPNZIYUAN] ip-tunnel access-route ip-route-list NEIWANG
[H3C-sslvpn-context-SSLVPN-policy-group-SSLVPNZIYUAN] quit
[H3C-sslvpn-context-SSLVPN] service enable
[H3C-sslvpn-context-SSLVPN] quit
[H3C] security-policy ip
[H3C-security-policy-ip] rule 5 name Untrst-Local
[H3C-security-policy-ip-5-Untrst-Local] action pass
[H3C-security-policy-ip-5-Untrst-Local] source-zone Untrust
[H3C-security-policy-ip-5-Untrst-Local] destination-zone Local
[H3C-security-policy-ip-5-Untrst-Local] service 4433
[H3C-security-policy-ip-5-Untrst-Local] quit
[H3C-security-policy-ip] rule 10 name SSLVPN-Trust
[H3C-security-policy-ip-10-SSLVPN-Trust] action pass
[H3C-security-policy-ip-10-SSLVPN-Trust] source-zone SSLVPN
[H3C-security-policy-ip-10-SSLVPN-Trust] destination-zone Trust
[H3C-security-policy-ip-10-SSLVPN-Trust] quit
[H3C] local-user user1 class network
[H3C-luser-network-user1] password simple user1
[H3C-luser-network-user1] service-type sslvpn
[H3C-luser-network-user1] authorization-attribute sslvpn-policy-group SSLVPNZIYUAN
[H3C-luser-network-user1] quit
(0)
暂无评论
是不获取的,如果获取的话,电脑会出现两条默认理由,有可能上网会走vpn出去了,反而有问题,vpn会给电脑下发静态路由。
互联不通,先检查电脑上的路由表:cmd上route print可以看到获取的静态路由,静态路由就是你配的ip-route-list xxx里面的那几条,如果你要访问的的网段的路由,检查防火墙的安全策略,有没有允许vpn网段访问特定网段
(0)
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论