Juniper VPN issues

David Woodhouse dwmw2 at infradead.org
Mon May 9 01:35:47 PDT 2016


On Mon, 2016-05-09 at 17:57 +0930, O'Connor, Daniel wrote:
> 
> The default route is definitely set to the VPN, and I do see traffic
> flowing over to it but no reply.

What services? Do you even get a SYNACK in response to outgoing SYN
packets? If so, and it's just *data* that fails, try reducing the MTU
on the 'tun0' interface?

It sounds like a firewall or something is preventing your traffic. Are
you connecting to the *same* services that work with the NC client? 

Do you definitely end up with actual IP routing? Can you do a similar
capture with that client and see what's different? 

Or are you perhaps using it in its application proxy mode, when you do
it through the web browser?


-- 
dwmw2

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 5760 bytes
Desc: not available
URL: <http://lists.infradead.org/pipermail/openconnect-devel/attachments/20160509/06790086/attachment.bin>


More information about the openconnect-devel mailing list