Quick troubleshooting view
The VPN tunnel is established correctly but internal resources remain inaccessible. The problem is usually after the authentication: routing, DNS, policies19 or conflict of address.
- route of the network of the remote or uninstalled network
- missing 1966 politics between VPN and the LAN
- Internal DNS not provided to client
- Check the VPN address
- Testing an internal IP.
- Control the routing table
- correcting the routes pushed by the VPN
- add or correct policy
- provide internal DNS to VPN client
Contextual technician plan
Take up the IP address, the gateway and the routes obtained after connection.
road print.The command should complete without an unexpected error and return data consistent with the intended service.
If the result is normal, keep this layer lower in the hypothesis ranking and continue with the next discriminating check.
If the result is abnormal, preserve the output and investigate this layer before making broader changes.
Test first an internal IP address known to separate routing problem and DNS problem.
ipconfig /all.A valid non-APIPA address, expected gateway and DNS servers should be present.
The local IP configuration is coherent; test the next network layer.
Investigate DHCP
Check that a route to the internal sub-network exists on the client side and on the Burden side.
ns Outlookup server.domain.localThe command should complete without an unexpected error and return data consistent with the intended service.
If the result is normal, keep this layer lower in the hypothesis ranking and continue with the next discriminating check.
If the result is abnormal, preserve the output and investigate this layer before making broader changes.
Solve an internal DQF and compare with the expected response.
The exact failing name should resolve through the expected DNS server to the expected record without timeout.
If the exact name resolves correctly, compare application cache, suffix/search domain and the client or network where the failure remains.
If resolution fails or returns the wrong record, keep the queried server and answer and correct the resolver, zone/record or DNS path that is actually wrong.
Confirm that VPN traffic → LAN and return LAN → VPN are allowed.
The exact failing name should resolve through the expected DNS server to the expected record without timeout.
If the exact name resolves correctly, compare application cache, suffix/search domain and the client or network where the failure remains.
If resolution fails or returns the wrong record, keep the queried server and answer and correct the resolver, zone/record or DNS path that is actually wrong.
Repeat the same validation test after the correction and confirm the original symptom is gone. Validate stability before closing the incident.
Before changing configuration, record the current value and a way back.
Escalader if the tunnel is established but no flow crosses despite correct roads and policies, or if the problem concerns several sites/tunnels simultaneously.
The VPN tunnel is established correctly but internal resources remain inaccessible. The problem is usually after the authentication: routing, DNS, policies19 or conflict of address.
Causes probables
- route of the network of the remote or uninstalled network
- missing 1966 politics between VPN and the LAN
- Internal DNS not provided to client
- overlap between the customer's local network and the company's network
Diagnostic étape par étape
- 1
Check the VPN address
Take up the IP address, the gateway and the routes obtained after connection.
- 2
Testing an internal IP.
Test first an internal IP address known to separate routing problem and DNS problem.
- 3
Control the routing table
Check that a route to the internal sub-network exists on the client side and on the Burden side.
- 4
Test the internal DNS
Solve an internal DQF and compare with the expected response.
- 5
Checking policies
Confirm that VPN traffic → LAN and return LAN → VPN are allowed.
Commands utiles
road print.ipconfig /all.ns Outlookup server.domain.localSolutions possibles
- correcting the routes pushed by the VPN
- add or correct policy
- provide internal DNS to VPN client
- change plan of address if client network overlaps the network
Escalader if the tunnel is established but no flow crosses despite correct roads and policies, or if the problem concerns several sites/tunnels simultaneously.