Mar 12 2018
12:49 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Mar 12 2018
12:49 PM
Client access VPN can't access site-to-site VPN resources
I have a site-to-site vpn configured between MX and Amazon AWS. I can access everything in both directions. However, if I am remote and connected to the client access vpn, I can access everything attached to MX, but I can't access anything on AWS. AWS can't ping my remote machine either. I verified all routes are there and firewall is good. anyone face this issue?
Solved! Go to solution.
1 Accepted Solution
Mar 12 2018
1:19 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Mar 12 2018
1:19 PM
Is the vpn-subnet in the "in VPN" configuration? And is the S2S tunnel configured to include this?
Is there any group policies applied on the traffic?
How does a traceroute behave?
If you do a packet capture on the MX and in the AWS resource, what do you see?
Is there any group policies applied on the traffic?
How does a traceroute behave?
If you do a packet capture on the MX and in the AWS resource, what do you see?
2 Replies 2
Mar 12 2018
1:19 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Mar 12 2018
1:19 PM
Is the vpn-subnet in the "in VPN" configuration? And is the S2S tunnel configured to include this?
Is there any group policies applied on the traffic?
How does a traceroute behave?
If you do a packet capture on the MX and in the AWS resource, what do you see?
Is there any group policies applied on the traffic?
How does a traceroute behave?
If you do a packet capture on the MX and in the AWS resource, what do you see?
Mar 12 2018
1:30 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Mar 12 2018
1:30 PM
first suggestion fixed it. the client vpn subnet was not enable for the vpn.

Get notified when there are additional replies to this discussion.