cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

VPN Tunnel up but getting the following error

I have multiple VPN tunnels up on my MFE running V8.  The tunnels show as active on the dashboard.

The other end of the tunnel is a Cisco switch with a laptop behind it.   I can ping from the laptop to everything behind the MFE at the other end of the tunnel.

So all looks good so far.

When I try and connect to a webserver behind the McAfee firewall (via IP address) I get the correct redirect URL from the Webserver, but the login page never comes up and I get the following errror from the MFE.

FieldValue
Areanil_are
Date2013-08-01
Dest Port80
Dst_geoCA
Dstip141.xxx.xxx.xxx
EventTCP netprobe
Facility

kernel

Hostnamemfe.company.com
Interface

1-0

Priorityminor
Protocol6
ReasonREceived a TCP connection attempt desinted for a service that the current policy does not support
Source Port1105
Source ZoneLaptop_VPN
Srcip192.168.xxx.xxx
Syslog4
SyslogWarnings (4)
Type Netprobe
Vpn_name

Laptop_VPN

Any thoughts.  I was pretty sure that once the tunnel was up, no ACLs were needed to connect to anything between the 2 ends of the tunnel.

Cheers,

3 Replies
Highlighted

Re: VPN Tunnel up but getting the following error

additional information:

The other tunnels are running fine with traffic passing thru as expected.

Level 13
Report Inappropriate Content
Message 3 of 4

Re: VPN Tunnel up but getting the following error

Hello,

According to the audit message, the source zone is Laptop_VPN, is this a virtual zone? If so, then policy is needed to pass traffic in and out of the tunnel. The netprobe tells me that the traffic just did not match a rule for the port 80 web traffic.

What might help is doing a route get to check the destination zone of the packet. Maybe a rule has a different destination zone.

route -n get 141.xxx.xxx.xxx

Hope this helps,

Matt

Highlighted

Re: VPN Tunnel up but getting the following error

thanks I will try...and no we are not using virtual zones... I'll post what I find...cheers,

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community