cancel
Showing results for 
Search instead for 
Did you mean: 

Odd Routing Issue

CharlesP
Occasional Contributor

Odd Routing Issue

We have a Pulse Connect Secure appliance which we use for client VPN, as well as hosting some external websites.

 

We have an odd issue where, while a user is connected to Pulse VPN (no split tunneling), they are unable to access any web pages which are hosted by an external virtual port which is also on the same Pulse appliance. However, they are still able to load other websites from the same external IP range which are not hosted on the Pulse appliance.

 

Doing a traceroute to the external virtual port on the Pulse appliance from the VPN client just times out. The traffic doesn't go to the default gateway, but just appears to get eaten by the appliance.

 

Oddly, if I do a simultaneous packet capture from both the Pulse appliance and the VPN client, here is what I observe:

- From the client on VPN, the traffic goes out, but no response comes back.

- From the Pulse appliance (monitoring all interfaces), I see the appliance responding to the clients requests, but I don't actually see the initial requests show up within the packet capture.

 

It's as if the Pulse appliance is just internally routing the connection to itself, but then externally responding out the external interface to the private VPN IP, which obviously isn't going to go anywhere.

 

Does anyone know why this behavior is such and if there is a resolution to it?

3 REPLIES 3
zanyterp
Moderator

Re: Odd Routing Issue

yes, you cannot access items hosted on the appliance while connected over vpn to that appliance.
can you confirm that you are not logging in to the web interface (to use bookmarks, which should work) but solely connecting over the vpn (at which point, logging in to the web should disconnect your vpn session)
CharlesP
Occasional Contributor

Re: Odd Routing Issue

Hello. I've been on leave so I apologize for the late follow-up.

 

So this is by design that you can't access sign-in pages hosted on the Pulse appliance while connected to VPN? Is there any work-around?

zanyterp
Moderator

Re: Odd Routing Issue

yes, that is by design
not that i am aware of