Incorrect Primary or Backup IP Address or Domain for Mobile VPN with SSL
Applies To: Cloud-managed Fireboxes, Locally-managed Fireboxes
When you configure Mobile VPN with SSL, you specify the primary IP address or domain name that the Mobile VPN with SSL client connects to by default. If your Firebox has more than one external address, you can specify one of those addresses as the backup address that the Mobile VPN with SSL client connects to if it cannot connect to the primary address. If the addresses configured are incorrect, outdated, or do not resolve as expected, Mobile VPN with SSL connections fail or reach the wrong destination.
Symptoms
When the primary or backup IP address or domain name is incorrect in the Mobile VPN with SSL configuration, you might notice these symptoms:
- Users experience timeouts and cannot connect to the VPN.
- Users connect to an unintended endpoint.
- No Allow or Deny log messages appear for the public IP address of the client device.
Diagnostic Steps
- In the Mobile VPN with SSL configuration, verify that the specified Primary and Backup IP addresses or FQDNs are correct and reflect the address that users must connect to.
- If you specified an FQDN, verify that the domain name resolves to the expected public IP address of the Firebox. If the Firebox has a dynamic public IP address, verify that dynamic IP address changes have propagated to DNS.
- If the resolved address does not match the current public IP address, the public DNS record is outdated or incorrect, and you must update it.
- If the resolved address does match the current public IP address, the issue might be with the client-side DNS cache or upstream mapping.
- Flush the local DNS cache on the user computer and restart the Mobile VPN with SSL client. Try to connect again.
- Review upstream firewalls or routers for routing or port forwarding issues. If the Firebox is behind another device, confirm that the device forwards the VPN traffic to the correct IP address of the Firebox.
- Verify that the public IP addresses are reachable on the Mobile VPN with SSL listener port (TCP 443 unless configured otherwise) from the Internet.
Possible Causes and Solutions
Common causes and solutions include:
| Possible Cause | Solution |
|---|---|
| A typo exists in the primary or backup IP address or FQDN. |
Update the addresses in the Mobile VPN with SSL configuration. Locally-Managed: Manually Configure the Firebox for Mobile VPN with SSL Cloud-Managed: Configure Mobile VPN with SSL for a Cloud-Managed Firebox |
| The user tries to connect to the backup IP address or FQDN. | Connect to the primary IP address or FQDN from the Mobile VPN with SSL client. The client connects to the backup address only when it cannot reach the primary address. |
| An FQDN resolves to an incorrect public IP address (for example, after a recent public IP address change at the ISP). |
Update the public DNS record at your DNS provider with the new public IP address and wait for the DNS time to live (TTL) to expire before you retest. Optionally, to speed up propagation, you can reduce the TTL temporarily.
If you use a dynamic DNS service, you might want to configure the Dynamic DNS feature on the Firebox. For more information, go to: |
| The user computer has an outdated DNS cache. | Flush the local DNS cache on the user computer and restart the Mobile VPN with SSL client. For more information, go to About Policies by Domain Name (FQDN). |
|
An upstream router or firewall sends Mobile VPN with SSL traffic to an incorrect public IP address. |
Update the upstream router or firewall configuration so that Mobile VPN with SSL traffic is forwarded to the public IP address in the Mobile VPN with SSL configuration. Make sure that any port forwarding or NAT rules point to the correct address. |
| The public IP address is not reachable from the Internet because it is blocked or filtered upstream. | Investigate and resolve issues with upstream devices or the ISP. |
About Mobile VPN with SSL Policies