Forum Discussion
Unable to connect any resources after establishing VPN connection
I am currently setting up the BIG-IP APM to provide secure VPN connections for the users in my company. After the VPN connection is established, I cannot access any external or internal resources and the lower network adapter icon in Windows says "no internet access". I checked the ipconfig, an IP has been assigned but the default gateway is marking as 0.0.0.0. And the route table shows a "On-link" gateway for destination 0.0.0.0.
I tried to traceroute some external IPs and found the request being forwarded to the Virtual IP of the BIG-IP APM. I suspect the issue is due to the gateway settings but I could not find any setting related to default gateway on the console. (I saw some online videos showing an option to input "default gateway configuration" in the wizard page, but mine do not have this option.)
Thank you for your help.
Hello meowmeow 😺
Better see your network design as if you are using full vpn with no split tunnel (Network Access - Split Tunnel configuration) but full VPN (Article Detail) and maybe you are using Overview of BIG-IP Edge Client Always Connected mode (you mentioned that you can't connect even to the local network with the VPN on) then after the user traffic reaches the F5 device (by the way you can do tcpdump inside the tunnel Overview of packet tracing a BIG-IP APM Network Access tunnel with the tcpdump utility ) the F5 device should have appropriate routing in place to reach an external gateway for Internet and internal one for the Internal apps. Also check your Configuring Lease Pools as this ip addresses need to be routable in your environments.
I encourage you to take the F5 APM training if you have not done so or at least to read the F5 operations guides for tmos , apm and edge client as F5 is a complex system that has soo many options:
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com