Jump to content

Recommended Posts

Dears,

I am trying to troubleshoot my issue with tunnel service on WS1 environment.

before I add it to AVI LB , the app take the certificate and just wait the rules as below

image.png.c574b83a26cfea17d720e2f9f5036230.png

but now when I add the environment on AVI , the certificate not configured for tunnel.

knowing that the profile installed successfully and 4 certificates from the environment installed on the device 2 of them appears on the console as unknown.

 

and the below from tunnel server ./vpnreport tool

image.thumb.png.96a52ef563dbb2e447698fddf0537290.png

 

any one can help please

 

image.png

 

image.png

Edited by Asma Alfayyad
Link to comment
Share on other sites

  • Replies 6
  • Created
  • Last Reply

Top Posters In This Topic

  • Employee

I would highly recommend you reach out to Broadcom support for AVI and troubleshoot it with them. My best guess based on what you're describing is this is an AVI issue.

Link to comment
Share on other sites

Hello @Jack ,, I tried to reach to AVI support team with no help from their side.

Hello @Sascha Warno ,, actually I followed the below documentation from AVI exactly

https://avinetworks.com/docs/latest/load-balancing-workspace-one-uem-with-avi-vantage/#load-balancing-vmware-tunnel-per-app-vpn

I configure it on port 8443.

in this L4 service, there is no option to add the SSL cert/profile on AVI.

is there any changes need to be on the AVI VS?

and if this is not the correct config, can you guide me please

 

Link to comment
Share on other sites

  • Employee
On 7/17/2024 at 2:20 AM, Asma Alfayyad said:

Hello @Jack ,, I tried to reach to AVI support team with no help from their side.

Hello @Sascha Warno ,, actually I followed the below documentation from AVI exactly

https://avinetworks.com/docs/latest/load-balancing-workspace-one-uem-with-avi-vantage/#load-balancing-vmware-tunnel-per-app-vpn

I configure it on port 8443.

in this L4 service, there is no option to add the SSL cert/profile on AVI.

is there any changes need to be on the AVI VS?

and if this is not the correct config, can you guide me please

 

Sorry to hear it's not working still and it does look like you're following the right docs. This will require troubleshooting that only support can provide - it isn't practical for me to do on our community forum, so I encourage you to open a support request and ask for some assistance troubleshooting your config.

Link to comment
Share on other sites

did you replace the certificate for tunnel? If yes you need to push a new version of the VPN profile.

Also hit a chicken egg situation before.. where tunnel is always on and pre logon enabled.. it could not connect so the new profile is not pushed..  try to test with a clean machine. sometimes the old certificate stays behind at it uses that one. 

does it work without the AVI? so direct NAT to UAG (if this is a valid scenario for you to test)? if it does you know it is the AVI config. As stated before.. no SSL offloading

shooting some "hail" here but hope it helps 😉

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...