Quick troubleshooting view
The tunnel is established, but the internal resources remain unattainable.
- no customer route
- policyGolden
- Internal DNS
- Add Split Route
- Correct policy
- Distribute internal DNS
Contextual technician plan
Control pool and received routes.
road print.The command should complete without an unexpected error and return data consistent with the intended service.
If the result is normal, keep this layer lower in the hypothesis ranking and continue with the next discriminating check.
If the result is abnormal, preserve the output and investigate this layer before making broader changes.
Distinguish routing and DNS.
tracet 192.168.1.1The command should complete without an unexpected error and return data consistent with the intended service.
If the result is normal, keep this layer lower in the hypothesis ranking and continue with the next discriminating check.
If the result is abnormal, preserve the output and investigate this layer before making broader changes.
Control VPN traffic to LAN.
The exact failing name should resolve through the expected DNS server to the expected record without timeout.
If the exact name resolves correctly, compare application cache, suffix/search domain and the client or network where the failure remains.
If resolution fails or returns the wrong record, keep the queried server and answer and correct the resolver, zone/record or DNS path that is actually wrong.
Repeat the same validation test after the correction and confirm the original symptom is gone. Validate stability before closing the incident.
Before changing configuration, record the current value and a way back.
Clam if several sub-networks or tunnels overlap.
The tunnel is established, but the internal resources remain unattainable.
Causes probables
- no customer route
- policyGolden
- Internal DNS
Diagnostic étape par étape
- 1
Check VPN IP
Control pool and received routes.
- 2
Test IP LAN
Distinguish routing and DNS.
- 3
Check policy
Control VPN traffic to LAN.
Commands utiles
road print.tracet 192.168.1.1Solutions possibles
- Add Split Route
- Correct policy
- Distribute internal DNS
Clam if several sub-networks or tunnels overlap.