I can't get SSL VPN to work on Azure NSAv. It is a simple setup: SSL VPN uses RADIUS with Duo for authentication and that portion works. Users get correct routes/DNS servers etc. The problem is when they connect, they can't reach anything. SSL VPN policy to LAN shows 0 hits and that is one of my problems. I can't get the the policy with SSLVPN as the source to produce any hits. The packet capture looks like this:
Ethernet Header
Ether Type: IP(0x800), Src=[00:11:22:33:44:55], Dst=[70:a8:a5:3e:96:1d]
IP Packet Header
IP Type: ICMP(0x1), Src=[10.254.X.1], Dst=[10.1.X.4]
ICMP Packet Header
ICMP Type = 8(ECHO_REQUEST), ICMP Code = 0, ICMP Checksum = 11759
Value:[0]
DROPPED, Drop Code: 108(Enforced firewall rule(#1)), Module Id: 25(network), (Ref.Id: _8412_txGsIboemfJqQlu) 1:1)
———————————————————————————————–
This tells me that for some reason the SSL VPN traffic is hitting implicit deny policy because it didn't get the match on SSLVPN policy. I spent good portion of the day troubleshooting it, but did not get anywhere.
Source: r/sonicwall · by /u/interweb_gangsta