training-scraper

Fix WatchGuard SSL VPN Connection Failures in Double NAT Configuration

draft ยท network vpnwatchguarddouble-natremote-access

Generated by docuprocessor (prompt article/v3) ยท 2026-04-22 12:02

Source thread

thread_id: spaces/AAAA05BdS6s/threads/ixvzvt0W9Vk · 37 msgs · first 2024-10-28 · participants: Tech ATech BTech CTech DTech E

Tech A 2024-10-28 15:18
Hey guys, I have an office that installed Flex recently. They want to access Flex outside of the office, from another computers. I asked them about using LMI, but she told me that if she's working at home, probably the computer at the office will be being used. They access flex trough this website https://BerlinFamilyDental.myflex.app:45622 that points to a local IP (192.168.1.200). What's the best solution for this? forwarding ports at their WG?
Tech B 2024-10-28 15:22
no, its a security issue. VPN maybe
Tech A 2024-10-28 15:23
Yeah, I was thinking about a VPN too, I know that forwarding ports will be accessible for everyone, but takes less time,but for sure a VPN is much secure than that option
Tech A 2024-10-28 15:24
Should we configure a VPN at their WG then?
Tech B 2024-10-28 15:25
yes, setup VPN on the watchguard and see if that works https://docs.google.com/document/d/1WdLm7MSBrtdn2dveM3TS7HLueMDHHa-XW530M3ORgCg/edit#heading=h.wgrijvc1siw1
application/vnd.google-apps.document WatchGuard: Setup VPN using the Watchguard UI
Tech B 2024-10-28 15:26
just to be clear, we do NOT forward any ports for cases like that. THis is a big NONO
Tech A 2024-10-28 15:26
only for nvrs and related devices, right?
Tech B 2024-10-28 15:26
Correct, only NVRs. Anything else - plz discuss with @Joseph Caiazzo
Tech B 2024-10-28 15:30
also, in your case once you establish the VPN connection, you can edit the hosts file on the local PC to point that fqdn (https://BerlinFamilyDental.myflex.app:45622) to the IP (192.168.1.200) and it should work from her browser. In theory...
Tech A 2024-10-28 16:05
I configured the VPN as the guide says, but I'm not able to connect trough the WG vpn client / openvpn client. I already restarted the wg ๐Ÿซค
image/png image.png
**WatchGuard Mobile VPN with SSL** dialog box displaying three lines of text: *"(Failed to get domain name)"*, *"Could not download the configuration from the server."*, and *"Do you want to try to connect using the most recent configuration?"* Two response buttons are present: **Yes** and **No**.
Tech A 2024-10-28 16:06
There's a commcast device and then the WG
Tech B 2024-10-28 16:09
i dont think server/client setup requires ports forwarding but can u allow the public IP of the client into the WG? Do you know how to do it?
Tech A 2024-10-28 16:11
There's a rule already created
image/png image.png
**Fireware Web UI โ€” SSL-VPN Policy Settings** The screen displays an SSL-VPN policy configuration in WatchGuard Fireware Web UI (logged in as **admin**). The policy is set to **Connections are: Allowed**, with traffic flowing **FROM: Any-External** โ†’ **TO: Firebox**, on **Port 443 / TCP**. Checkboxes for "Enable Intrusion Prevention," "Enable bandwidth and time quotas," and "Auto-block sites that attempt to connect" are all **unchecked**; a custom idle timeout field shows **180 seconds** but the checkbox to enable it appears unchecked.
Tech A 2024-10-28 16:11
To allow all external connections trough port 443
Tech B 2024-10-28 16:13
is that rule on top of the list?
Tech A 2024-10-28 16:13
(no text)
image/png image.png
The image shows a WatchGuard firewall policy management interface with 11 ordered firewall rules visible. Policies include FTP-proxy (tcp:21), HTTP-proxy (tcp:80), SSL-VPN (tcp:443), HTTPS-proxy (tcp:443), WG-Cert-Portal (tcp:4126), WG-Fireware-XTM (tcp:8080), DNS (tcp:53/udp:53), Ping (ICMP type 8), WG-Firebox-Mgmt (tcp:4105/tcp:411x), Outgoing TCP-UDP (tcp:0/udp:0), and Allow SSLVPN (Any). The interface shows **Policy Auto-Order Mode is currently enabled** (indicated by the "Disable Policy Auto-Order Mode" button being present), with most policies sourced from "Any-Trusted" and destined for "Any-External" or "Firebox," with App Control and Geolocation set to "Global" on applicable rules.
Tech A 2024-10-28 16:13
N3
Tech B 2024-10-28 16:14
click Disable policy autoorder and bring it to the #1 position, save and test
Tech A 2024-10-28 16:17
I get the same error
Tech C 2024-10-28 16:17
also you mentioned there is a comcast device and then the WG ---> is there double NAT? Maybe VPN not working because theres double nat ?
Tech A 2024-10-28 16:19
I tried to disable the firewall of the comcast device before, didn't worked, and I see that this is checked at NAT
image/png image.png
**Comcast Business gateway admin interface โ€” Advanced > NAT page.** The "Disable All" checkbox is **checked**, disabling all 1-to-1 NAT rules; the NAT table shows **"No entries."** Status indicators in the top-right show **Internet: active (green)**, **Wi-Fi: error (red X)**, and **Low Security: flagged (red X)**; battery/power reads **0%**.
Tech B 2024-10-28 16:20
we have a bunch of clients that use server/client setup and did not need any extra settings in their routers/modems this is not a gateway to gateway VPN service. Lets ask the wizard @Alex Kaplun
Tech D 2024-10-28 16:20
tell us the IP of the comcast device
Tech A 2024-10-28 16:20
Bridge mode is disabled btw, not sure if it has something to do with this
image/png image.png
**Gateway > At a Glance** configuration page from a Comcast Business gateway admin interface. **Bridge Mode** is currently set to **Disable** (highlighted/active button); the **Enable** button is unselected. A note reads: *"Comcast Business SecurityEdge works only in Router Mode."* The Advanced/Basic radio buttons are grayed out/inactive, and two action buttons are present at the bottom: **SAVE CURRENT CONFIGURATION** and **RESTORE SAVED CONFIGURATION**.
Tech A 2024-10-28 16:21
(no text)
image/png image.png
The screenshot shows a Comcast Business gateway web UI (Gateway > Connection > Comcast Network) accessed via a local address of 10.1.10.1. The WAN IPv4 address **174.168.175.141** is highlighted in a red box, with Internet status shown as **Active**, WAN Mode as **DOCSIS**, and System Uptime of **9 days 7h: 20m: 11s**. WAN Static IP (IPv4) shows **Not Configured**, Default Gateway is **174.168.172.1**, and DNS servers are **75.75.75.75** (primary) and **75.75.76.76** (secondary).
Tech E 2024-10-28 16:22
double NAT - has everything to do with this
Tech E 2024-10-28 16:23
modem needs to be bridged for ssl-vpn to work
Tech B 2024-10-28 16:24
only if the modem has the routing capabilities, right?
Tech A 2024-10-28 16:24
Should I enable Bridge mode then?
Tech E 2024-10-28 16:25
watchguard WAN has to have public IP not private, if modem is not bridged wg will have private ip on the wan like 10.1.10.x
Tech A 2024-10-28 16:26
Yeah that's right, external IP at interfaces is showing as an IP of the modem dhcp
Tech A 2024-10-28 16:27
(no text)
image/png image.png
The image shows a network interface graph for **External (eth0)** displaying traffic over the past 20 minutes. Key readouts: **IP Address: 10.1.10.121**, **Gateway: 10.1.10.1**, **Netmask: 255.255.255.0**, **MAC: 00:01:21:2C:BB:2E**, **Sent: 22,574 KB**, **Received: 103,652 KB**. The graph shows a significant spike in **Received** (orange) traffic approaching the current time, peaking near **8 Mbps**, while **Sent** (blue) traffic remains near baseline throughout the displayed period.
Tech E 2024-10-28 16:28
switching bridge mode, will disconnect internet briefly make sure office is aware
Tech A 2024-10-28 16:29
Will do, let's try then
Tech A 2024-10-28 16:29
Thanks !
Tech A 2024-10-28 16:40
It's connecting now, thanks for the help ๐Ÿ™‚
Tech A 2024-10-28 18:16
All working now. Will leave this info at this topic just in case.. They are accessing flex trough a MAC and IPAD. They use OPENVPN client to connect to the vpn, both devices. I explained them how to connect the vpn and the user/password for that is at bitrix. When they connect the device to the VPN, they should access this website : https://BerlinFamilyDental.myflex.app:45622. They have it saved at bookmarks

Generated article

Unsaved edits.
draft