TKWITS Community Legend ✭✭✭✭✭
Reactions
Comments
-
Firmware 7.1.2 is known to be pretty buggy, try downgrading. Note it is destructive. Otherwise open a support ticket.
-
Think of what layer your issue is. If you are not getting a link light from the Verizon connection than the physical connection is the issue. Considering you know that both ports on both devices work with other devices, what are some settings for physical connectivity? Relevant reading:
-
"I have access to only the firewall and no other network infrastructure so I cannot prove that a BYOD client might have accidentally ended up in a zone with DPI-SSL due to some network misconfiguration" Tough situation. I would request a screenshot from the device showing its IP address(es) and what SSID its connected to…
-
Update your firmware if you are on anything pre-7.0.1. Open a support ticket.
-
Open a support ticket if you have not done so already.
-
Try ordering your rules to be most restrictive first and least restrictive last.
-
"How can I work out if any given connection is inspected?" IIRC the UI doesnt provide any indicator of DPI SSL in the connection monitor or elsewhere unfortunately, so it really becomes a manual process. Work your way from the Zone setting, to access rules, to exclusions. Temporarily disable DPISSL at each step and verify…
-
You have given very little information. Please at least tell us what model and firmware you are running. "but the setting reverts back to not allowing it every couple days." If the rule / setting you are editing actually REVERTS to the previous setting than there is something likely going on with the hardware, the device…
-
Have you tried the options MS has had posted for years?
-
"when I go to active tunnels it shows two entries to both remote subnets but the local entry on each is only showing our domain network." Than you aren't using an Address Group that contains the appropriate 'local' subnets.
-
Does your source on the tunnel contain both subnets?…
-
"can I use the same subnet for the main office in both VPN channels? " You are essentially asking the same question. See my original response.
-
"will I have a problem if the Warehous subnet the same: 192.168.10.XXX?" Yes you will have a problem. You can use NAT to circumvent the subnet overlap though. "Or it is better to change it?" The forever question. Really it's up to you. If it's a small network with few devices than changing the subnet would be relatively…
-
Did you search the web?
-
Show us some sanitized tunnel configs and log messages, we may be able to help.