Troubleshooting / symptôme

VPN connected but no access to the internal network

The VPN tunnel is established correctly but internal resources remain inaccessible. The problem is usually after the authentication: routing, DNS, policies19 or conflict of address.

⌚ About 4 min read
View my favorites
Real-world problem · V2

Quick troubleshooting view

What you are seeing

The VPN tunnel is established correctly but internal resources remain inaccessible. The problem is usually after the authentication: routing, DNS, policies19 or conflict of address.

Likely causes
  1. route of the network of the remote or uninstalled network
  2. missing 1966 politics between VPN and the LAN
  3. Internal DNS not provided to client
First checks
  1. Check the VPN address
  2. Testing an internal IP.
  3. Control the routing table
Recommended actions
  1. correcting the routes pushed by the VPN
  2. add or correct policy
  3. provide internal DNS to VPN client
Start Symptom → Cause →
Network / VPNIntermediate.

The VPN tunnel is established correctly but internal resources remain inaccessible. The problem is usually after the authentication: routing, DNS, policies19 or conflict of address.

Important: relevez toujours le message d’erreur exact et l’heure du problème avant de modifier la configuration. Les actions proposées doivent être adaptées à votre environnement.

Causes probables

  • route of the network of the remote or uninstalled network
  • missing 1966 politics between VPN and the LAN
  • Internal DNS not provided to client
  • overlap between the customer's local network and the company's network

Diagnostic étape par étape

  1. 1

    Check the VPN address

    Take up the IP address, the gateway and the routes obtained after connection.

  2. 2

    Testing an internal IP.

    Test first an internal IP address known to separate routing problem and DNS problem.

  3. 3

    Control the routing table

    Check that a route to the internal sub-network exists on the client side and on the Burden side.

  4. 4

    Test the internal DNS

    Solve an internal DQF and compare with the expected response.

  5. 5

    Checking policies

    Confirm that VPN traffic → LAN and return LAN → VPN are allowed.

Commands utiles

road print.
ipconfig /all.
ns Outlookup server.domain.local

Solutions possibles

  • correcting the routes pushed by the VPN
  • add or correct policy
  • provide internal DNS to VPN client
  • change plan of address if client network overlaps the network
Quand escalader ?

Escalader if the tunnel is established but no flow crosses despite correct roads and policies, or if the problem concerns several sites/tunnels simultaneously.

♡ 0