Description
Adding additional IP addresses to an interface in the Firewall is described in the following KB:
https://kb.clavister.com/324735780/adding-an-additional-ip-address-to-an-ethernet-interface
It is recommended to use the “core” route method. And one of the reason for that recommendation is that non-core routed IP addresses that is to be used by the Firewall for a server function such as SSL-VPN, OneConnect, IPsec, WebUI, SSH etc. may not function properly unless the IP address is core routed.
In versions before 13.00.09 it was possible to configure and use the SSL-VPN server on a non-core routed IP address. But changes in 13.00.09 now aligns the SSL-VPN server with other server types which cause any existing configured SSL-VPN servers to stop working unless the IP address for the server is core routed.
Solution
The solution to the problem is to follow the above mentioned KB article and instead of using “ARP publish”, create and use a core route + ProxyARP to publish the additional IP address on the Firewall. Doing this change on existing Firewall configurations may require updates to any IP Policy (or rule) that is specifically configured towards a non-core interface used towards the additional IP address. An example on needed changes to IP polices/rules:
Before:
Allow Wan all-nets Wan IP_Wan_2 Service=HTTP SetDest=192.168.50.50
After:
Allow Wan all-nets Core IP_Wan_2 Service=HTTP SetDest=192.168.50.50
Related articles
15 Jan, 2024 dictionary troubleshoot core stream incontrol incenter oneconnect cloudservice
13 Jun, 2022 oneconnect macos ios windows android
3 Jun, 2022 oneconnect openconnect sslvpn
26 Mar, 2024 oneconnect sase cloud
5 Feb, 2024 oneconnect sase
28 Apr, 2023 openconnect oneconnect macos ios iphone
18 Mar, 2024 core certificate oneconnect ipsec vpn
28 Feb, 2024 oneconnect windows
23 Aug, 2022 sslvpn openconnect oneconnect android core
29 Oct, 2021 sslvpn openconnect oneconnect windows
13 Oct, 2021 oneconnect macos openconnect ios
9 Feb, 2024 core oneconnect windows splittunneling dns
18 Mar, 2024 core incontrol certificate oneconnect ipsec vpn
27 Oct, 2022 oneconnect log
5 Mar, 2021 sslvpn openconnect oneconnect linux core
18 Mar, 2024 onetouch sslvpn oneconnect troubleshoot certificate
25 Feb, 2022 oneconnect windows howto
10 Oct, 2024 sase oneconnect core userauth
27 Feb, 2024 oneconnect userbased core
23 Aug, 2022 core oneconnect
28 Nov, 2022 core configuration oneconnect
9 Oct, 2024 oneconnect sase cloud radius
29 Jun, 2021 core oneconnect
11 May, 2023 oneconnect certificate howto
27 Aug, 2024 oneconnect windows
8 Jun, 2022 openconnect oneconnect android
23 Aug, 2022 sslvpn openconnect oneconnect macos windows linux core