Quick troubleshooting view
The VPN client indicates connected, but internal resources do not respond….
- VPN routes absent.
- Incorrect Split Tunnel.
- Missing RuleGarten.
- Control the VPN Client Address.
- Testing an internal IP.
- Test an internal name.
- Add/correct roads or tunnel split.
- Allow VPN traffic to the right networks
- Distribute internal DNS
Contextual technician plan
Check the address received and the roads installed.
ipconfig /all.A valid non-APIPA address, expected gateway and DNS servers should be present.
The local IP configuration is coherent; test the next network layer.
Test a resource directly by IP.
road print.The command should complete without an unexpected error and return data consistent with the intended service.
If the result is normal, keep this layer lower in the hypothesis ranking and continue with the next discriminating check.
If the result is abnormal, preserve the output and investigate this layer before making broader changes.
If the IP works but not the name, focus on the DNS.
Test-Net-Gonnegion 192.166.10.10 -Port 443The command should complete without an unexpected error and return data consistent with the intended service.
If the result is normal, keep this layer lower in the hypothesis ranking and continue with the next discriminating check.
If the result is abnormal, preserve the output and investigate this layer before making broader changes.
Compare the customer's local network with the company's networks.
The exact failing name should resolve through the expected DNS server to the expected record without timeout.
If the exact name resolves correctly, compare application cache, suffix/search domain and the client or network where the failure remains.
If resolution fails or returns the wrong record, keep the queried server and answer and correct the resolver, zone/record or DNS path that is actually wrong.
Repeat the same validation test after the correction and confirm the original symptom is gone. Validate stability before closing the incident.
Before changing configuration, record the current value and a way back.
Escalad if the tunnel is established but no traffic crosses the19th century despite correct roads and policies.
The VPN client indicates connected, but internal resources do not respond.
Causes probables
- VPN routes absent.
- Incorrect Split Tunnel.
- Missing RuleGarten.
- Internal DNS not provided.
- Local sub-network in conflict with the network.
Diagnostic étape par étape
- 1
Control the VPN Client Address.
Check the address received and the roads installed.
- 2
Testing an internal IP.
Test a resource directly by IP.
- 3
Test an internal name.
If the IP works but not the name, focus on the DNS.
- 4
Control conflict of address.
Compare the customer's local network with the company's networks.
Commands utiles
ipconfig /all.road print.Test-Net-Gonnegion 192.166.10.10 -Port 443Solutions possibles
- Add/correct roads or tunnel split.
- Allow VPN traffic to the right networks
- Distribute internal DNS
- Change a plan of address in case of lasting conflict
Escalad if the tunnel is established but no traffic crosses the19th century despite correct roads and policies.