
Personal aXsGUARD - 7.7.1
© VASCO Data Security 2013
30
Chapter 7. Troubleshooting
The PAX cannot establish a VPN connection to the corporate aXsGUARD Gatekeeper.
• Ensure that traffic towards port 1194 is allowed on the Internet interface of the corporate aXsGUARD
Gatekeeper for the selected VPN protocol (TCP or UDP). This is required to initialize the SSL tunnel.
• Ensure that you have selected the correct VPN protocol on the PAX. For example: if the aXsGUARD
Gatekeeper VPN server has been configured to only accept UDP connections on port 1194, either UDP
or Auto must be configured on the PAX (see
Section 3.7, “TCP or UDP?”
and
Section 5.4, “Installation
Instructions”
).
• Ensure that the correct client certificate has been installed on the PAX. (Especially if you have several sites
to which the PAX can connect). Client certificates are derived from server certificates; trying to establish a
connection with the wrong certificate is impossible.
• Verify if the installed PAX certificate isn’t expired.
• Verify if you exported the right type of certificate (PKCS12).
• Verify the IP address or the FQDN of the aXsGUARD Gatekeeper you are trying to connect to.
I cannot connect to the PAX web-based Administrator Tool.
• Verify the proxy server settings of your Internet browser. If a proxy server is configured, you may not
be able to access the PAX Administrator Tool. Clear the settings and try again. Consult your browser’s
documentation, if necessary.
• Verify whether your client PC is in the same network range as the PAX. The PAX downloads its settings from
the aXsGUARD Gatekeeper VPN server. Once the PAX has successfully established a VPN connection
with the corporate aXsGUARD Gatekeeper VPN server, the LAN IP address and other configuration settings
of the PAX are updated according to the configuration on the aXsGUARD Gatekeeper (after a reboot). This
problem is most likely to occur if you changed the PAX default LAN range.
I cannot connect to the corporate LAN, even though the VPN connection is up.
• Ensure that the correct routing entries have been added (see
Section 4.6, “Network Settings”
).
• Verify the Firewall settings (see
Section 4.9, “Firewall Settings”
).
I cannot connect to the Internet after establishing a VPN connection.
If you have selected the route all traffic through tunnel option (see
Section 4.6, “Network Settings”
), verify if the
correct routes and Firewall Policies are added so that Internet traffic is allowed to pass through the VPN tunnel.
My VPN Tunnel disconnects and reconnects frequently
• Check the load averages of the PAX, as explained in
Section 6.4, “Using the Diagnostic Tool”
and reboot it.
• If the high load persists after rebooting, contact VASCO Support.