Secure Web cannot access external websites

Secure Web cannot access external websites

book

Article ID: CTX227376

calendar_today

Updated On:

Description

Unable to browse external websites.
Error " http 1.1 gateway timeout" on Secure Web.
VPN mode : Full VPN

Internal websites work fine.

Resolution

  • Tried to access google from NetScaler which failed.
  • Able to ping the URL by IP address.
  • Name servers show as down, tried adding address record manually on NS which did not fix the issue.
  • Changed the Split DNS from both to local, no effect.
  • Checked the traces and Secure Logs, identified the issue with DNS resolution.
  • ICMP traffic was blocked on default gateway, which was allowed later on and DNS server started showing as UP.
  • Enabled ICMP for default gateway: This fixed the issue.
  • External website started working as expected.

Problem Cause

Name servers on NetScaler were showing as down.
DNS servers are external and ICMP traffic was blocked on default gateway.

 

Issue/Introduction

Unable to access external websites in Full VPN Mode.