Cannot connect to Client VPN

etw
Comes here often

Cannot connect to Client VPN

hi,

 

I have a problem to use client vpn connect to one new site of my company. I did many testings and found:

 

1. my iPhone can connect to Site A client VPN and can connect to site B client VPN when I am using 5G cellular.

2. my iPhone can connect to site A client VPN but can NOT connect to site B client when I am using WIFI.

3. my windows computer has same issue, I cannot connect to site B when I am using Wi-Fi, I only can connect to site B when I am using iphone's hotspot. My windows can connect to site A without any problem whatever was using any network.

4. Site B is not behind NAT network, I had configured Public IP to WAN directly. 

5. Site A, B are using same radius server.

6. I already capture packages; MX already got the UDP 500 package from my iPhone/windows pc when I am using Wi-Fi. but I cannot find UDP 4500 packages or other UDP data.

 

Any suggestion? thanks!

 

7 Replies 7
Brash
Kind of a big deal
Kind of a big deal

It sounds likely that either your WiFi router or your ISP is blocking port 4500. I would either try a different WiFi router or contact the ISP.

 

You've done a fair bit do troubleshooting already but in case it provides further assistance, Meraki has a troubleshooting doc:

https://documentation.meraki.com/MX/Client_VPN/Guided_Client_VPN_Troubleshooting#Resolving_NetBIOS_n...

DarrenOC
Kind of a big deal
Kind of a big deal

Hi @etw , I applaud you on the troubleshooting you’ve done so far and appreciate that you’re probably under pressure to get this up and running but all I can advise here is to focus on a particular site first.

 

What clients and OS will your users be connecting to site A?  What VPN client will they be using?  Hone in on those use cases and troubleshoot just using those otherwise you’re going to end up down a rabbit warren.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
Shubh3738
Building a reputation

Are you check it the same with your ISP Team , is that not blocking.

Or raised a complaint with ISP Team?

PhilipDAth
Kind of a big deal
Kind of a big deal

If you are using the Windows client VPN - make sure the local subnet in use does not overlap with the remote subnet you are trying to access - otherwise it won't work.

 

Also consider buying some Cisco Secure Client AnyConnect licences.  AnyConnect is WAY more robust and works in a lot more cases.  It also supports SAML you can can authenticate using things like Entra ID and use the MFA that it provides.

https://documentation.meraki.com/MX/Client_VPN/AnyConnect_on_the_MX_Appliance

 

henrry81
Here to help

 Perhaps one should use another router or contact the company and ask whether they configure port 4500 to be closed. Other benefits that came to the mind included the fact that working on one site at a time could minimize on complications.

from_afar
Building a reputation

I have had issues before when trying to connect to VPN when multiple people were trying to connect from the same network. I.e. the first connection would work fine, but then when someone else tried to connect from the same WiFi network, that connection would fail. These were Mac's, but it happened on iOS as well. I think Meraki does some magic that doesn't work well when multiple connections are coming from the same location. They probably don't expect that to be normal behavior or something. The only solution I found was to move over to Cisco Secure Client AnyConnect app.

etw
Comes here often

Thanks for all of yours advise. I did lot of testing ad found my ISP blocked UDP 4500 port for some special reason. It is not related with MX settings.

 

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels