[TSHOOT] Troubleshot Client VPN in Cisco Meraki MX Security Appliances

แชร์
ฝัง
  • เผยแพร่เมื่อ 26 ส.ค. 2024
  • - Are you having issues connecting through client VPN to the Security Appliance?
    - You do not know where the problem is?
    - Do you want to understand the traffic flow of the client VPN process?
    _______________________________________________________________________________________
    Cisco Meraki Training
    • Cisco Meraki training:...
    _______________________________________________________________________________________
    In this opportunity, we will go through the Client VPN traffic flow, the expected behavior and the most common scenarios that you will encounter when you are having issues with client VPN. This video will help you to have a complete understanding of the traffic between the client VPN and the Security Appliance as well as the event logs in order to understand in a fast and reliable way what is the root cause of your problem.
    I encourage you to go through the whole video to examine the different scenarios including the last one with the expected traffic flow in a normal and healthy interaction.
    Troubleshooting scenarios:
    -Client not reaching the MX 1:23
    -Wrong client configuration 7:00
    -Wrong authentication 12:54
    -Client VPN traffic flow 17:20
    _________________________________________________________________________________________
    Additional videos
    - Client VPN configuration
    • [HOW] to configure Cli...
    _________________________________________________________________________________________
    Cisco Meraki Documentation
    - Configuration of client devices
    documentation....
    - Troubleshooting client VPN
    documentation....
    If you encounter any issues during the troubleshooting, feel free to post a comment with the information and I will help you to move forward.
    ________________________________________________________________________________________
    If you would like to know more about similar topics, feel free to check the following videos:
    Content Filtering
    • [HOW] to configure Con...
    Layer 3 and 7 Firewall Rules
    • [HOW] to configure Lay...
    Client VPN
    • [HOW] to configure Cli...
    Traffic shaping rules
    • [HOW] to configure Tra...
    Wireless Settings
    • [HOW] to configure Wir...
    Cisco Umbrella Integration
    • [HOW] to integrate Cis...
    Flow Preferences
    • [HOW] to configure Flo...
    Appliance Status Page
    • Overview of the Applia...
    Creating VPN tunnels
    • [HOW] to configure a N...
    DHCP configuration
    • [HOW] to configure a D...
    Addressing and VLANs
    • [HOW] to configure Add...

ความคิดเห็น • 18

  • @brassard1111
    @brassard1111 4 ปีที่แล้ว +2

    Very Useful I was stuck for hours!!!
    As I was building it from home, I did not realize that I had to use the private IP of the server!
    Second mistake I added port forwarding for 500 and 4500 and I should not do it in my case as I believe it is a local network!

    • @TheITWay
      @TheITWay  4 ปีที่แล้ว +1

      Hello @RedaMalaga.
      I am glad that the video helped you!. Let me know if you need any additional help.

  • @bjornonthisday9691
    @bjornonthisday9691 ปีที่แล้ว +1

    I love your videos and very clear on how the troubleshooting client VPN. Do they have a book on Meraki Dashboard? Also interested in getting CMSS certified, what books would helpful? Thanks

  • @flipcard7sins
    @flipcard7sins 3 ปีที่แล้ว

    Great tutorial! Although I can't seem to have my client VPN to work at all, used public DNS, no WINS servers, Meraki Cloud, even the most basic settings, can't get it to work.

  • @salvadorviveros3858
    @salvadorviveros3858 2 ปีที่แล้ว

    thank you for the information, Graat information
    I'm running in to an issue with Macs Connecting to the VPN, the Connection will Stablish fine and I'm able to access network resources for about a minute and then all of a sudden i lose the Access to network resource ( in my case to the RDP server I usually connect to ) then I do a ping test and I'm not able to ping the server, the VPN connection on the Mac shows Connected but when I look at the MX logs it shows the Connection and I see wen the Client connected and a minute later i see the Client disconnect ???? ( it seem to disconnect it self but the Mac Shows is connected ) Any ideas.

  • @khurramshahzad-st6ut
    @khurramshahzad-st6ut 3 ปีที่แล้ว

    If we are not on the Native VLAN then what IP we put in server address?

  • @gregoryderwon3133
    @gregoryderwon3133 2 ปีที่แล้ว

    please give a turorial with client vpn using Radius and windows 10 default vpn clientside.

  • @gregorypierson9801
    @gregorypierson9801 2 ปีที่แล้ว

    Hello, what about 628 error on a windows 10 PC?

  • @elijahbrylleflorenosos6098
    @elijahbrylleflorenosos6098 4 ปีที่แล้ว +1

    Hi nice tutorial ! Just a question i experience an issue for the client vpn today do I need to do a pcap on the Internet instead of the Client vpn? Hope to hear from you thank you,

    • @jincyjoseph3118
      @jincyjoseph3118 4 ปีที่แล้ว +1

      If you are unable to connect to VPN, you should be taking packet capture on the internet interface of the MX.

    • @TheITWay
      @TheITWay  4 ปีที่แล้ว

      Hello @Elijah,
      If the client VPN is not connecting, you should take pcaps in the internet interface to ensure the traffic from your client is reaching the MX. If it does, you can take a look at the video to understand the traffic flow and how to troubleshoot.
      If the Client VPN is connected and your issue is accessing local resources, you should take pcaps in the Client VPN and the LAN interfaces to ensure the client is sending the traffic through the VPN tunnel and the MX is forwarding that traffic to the LAN.

  • @TheAnaden
    @TheAnaden 3 ปีที่แล้ว

    What do you mean by reaching from the outside or inside?

    • @khurramshahzad-st6ut
      @khurramshahzad-st6ut 3 ปีที่แล้ว

      He means he was already inside the LAN and was getting IP from the same DHCP and if you need to access office LAN from home you need WAN IP

  • @mangoman692
    @mangoman692 4 ปีที่แล้ว

    Thanks for a great walkthrough & setup!
    I've got my client vpn to connect properly, but I cannot see devices (for example, printers) on my internal network.
    What I can see via packet captures is the proper authentication and even DNS resolution (to google as that is how my MX is set to use Google DNS), so I know my traffic is passing through the MX.... I think I'm missing maybe a route on the inside for the VPN subnet to see the internal subnet. How do I get those two networks to talk? (I've not seen that in any of your videos).

    • @TheITWay
      @TheITWay  4 ปีที่แล้ว +1

      Hello @Tim,
      For the VPN clients talk to the internal networks, you do not need to make any changes in the MX. They would behave like another subnet inside the network. Unless you have a firewall rule in the MX or any Layer 3 devices blocking that traffic or the host you are trying to access has a firewall enabled blocking unknown traffic, all the subnets should be able to talk to each other.
      To ensure the traffic is passing from your client VPN to the internal host, you can take packet captures in the LAN interface of the MX and filter the traffic for both IP addresses. If you see the traffic going out the MX, it means that something in the LAN or the host is blocking the reply.
      If you take pcaps in the VPN and the LAN interface and you do not see the traffic, it means that the client VPN is not even sending the packets through the VPN tunnel.
      To ensure you have reachability to the internal resources of your MX, I would recommend you to troubleshot using pings if the device supports it.

    • @mangoman692
      @mangoman692 4 ปีที่แล้ว

      @@TheITWay thanks for the advice... but... something just not right...i've done packet captures on the internet, LAN & Client VPN interfaces on the MX and still the same. I can ping google.com and that gets a reply through the VPN, but I cannot ping anything internal. When on the internal network (not via the VPN), I can ping stuff all day and get a reply.
      I'm using a Single LAN as the LAN configuration (192.168.1.1/24 w/ the MX at .250.) No static routes. Firewall: Layer 3 are the meraki defaults: Allow any for outbound rules, ICMP ping - allow any remote IPs. Layer 7 rules are denied for all P2P, Gaming & Advertising. No port forwarding, 1:1 or 1:Many NAT.
      Client VPN is set up and I can see where an appropriate dhcp'd client vpn address is given (192.168.10.x) in the event log. Meraki cloud authentication is being used. Only default traffic shaping rules in effect.
      I don't see the client vpn address in the LAN interface. (I'm guessing I should, right?)
      In the client VPN.pcap, there are DNS queries between the client VPN & openDNS (208.67.222.222) when pinging google.com.
      The Internet.pcap doesn't seem to tell me anything as I don't seen any IP addresses (client vpn or the external aircard through which I'm connected. (I've reset the 'internal' address of the aircard to be 172.16.x.x to avoid NAT conflicts already).
      I'm stuck. While the VPN traffic does all route through the MX, which is fine, I need to be able to reach stuff on the inside of my network.
      Any suggestions?

    • @darcyhellier8519
      @darcyhellier8519 2 ปีที่แล้ว

      @@mangoman692 How did you end up solving the issue with the VPN connecting to the internal network (e.g accessing the printer). Thanks

    • @mangoman692
      @mangoman692 2 ปีที่แล้ว

      @@darcyhellier8519 I never was able to get it sorted out.