Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PulseSecure VPN client - can't connect to company VPN - are special firewall settings needed in pfsense?

    Scheduled Pinned Locked Moved Firewalling
    12 Posts 3 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad @Rico
      last edited by

      I use Pulse secure when working for home, nothing needed configuring on the router to get it to work.

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      1 Reply Last reply Reply Quote 0
      • M
        mrneutron
        last edited by

        My connection path at home goes through this path:
        Netgate SG-1100, Arris Surfboard SB6141 cable modem, then Comcast, for Internet.
        Something in this chain is preventing connection, to all the Windows pcs I've tried with PulseSecure's client.

        I tried the experiment of connecting my Dell laptop (Windows 10 64-bit) to my Sprint cell phone's wifi hotspot to the Sprint 4G network. The laptop was able to connect to the company VPN with PulseSecure, through that connection path.
        The same Dell laptop cannot connect through the Netgate SG-1100, Arris Surfboard SB6141, and Comcast.

        1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad
          last edited by NogBadTheBad

          Is the WAN IP address on your pfSense router a RFC1918 address?

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          M 1 Reply Last reply Reply Quote 0
          • M
            mrneutron @NogBadTheBad
            last edited by

            @NogBadTheBad said in PulseSecure VPN client - can't connect to company VPN - are special firewall settings needed in pfsense?:

            RFC1918

            No. The WAN address of the SG-1100 is a Comcast DHCP-assigned address in the block 73.37.x.x.
            The cable modem is in pass-through mode, with no controls to change.

            1 Reply Last reply Reply Quote 0
            • M
              mrneutron
              last edited by

              I just disabled the "firewall scrub" option in pfsense, and was ABLE to connect to the office vpn with PulseSecure client.

              "Disable Firewall Scrub
              When set, the scrubbing option in pf is disabled. The scrub action in pf can interfere with NFS, and in rare cases, with VoIP traffic as well. By default, pfSense uses the fragment reassemble option which reassembles fragmented packets before sending them on to their destination, when possible. More information on the scrub feature of pf can be found in the OpenBSD PF Scrub"

              See:
              https://docs.netgate.com/pfsense/en/latest/book/config/advanced-firewall-nat.html

              1 Reply Last reply Reply Quote 0
              • M
                mrneutron
                last edited by

                I guess PulseSecure uses NFS?

                This says:
                One reason not to scrub on an interface is if one is passing NFS through PF. Some non-OpenBSD platforms send (and expect) strange packets -- fragmented packets with the "do not fragment" bit set, which are (properly) rejected by scrub. This can be resolved by use of the no-df option. Another reason is some multi-player games have connection problems passing through PF with scrub enabled. Other than these somewhat unusual cases, scrubbing all packets is a highly recommended practice.

                http://web.archive.org/web/20101223090933/http://www.openbsd.org/faq/pf/scrub.html

                1 Reply Last reply Reply Quote 0
                • NogBadTheBadN
                  NogBadTheBad
                  last edited by

                  I don't disable pf scrubbing.

                  Why do you think Pulse uses NFS, NFS is used to mount remote filesystems locally.

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    mrneutron @NogBadTheBad
                    last edited by mrneutron

                    @NogBadTheBad , I was just venturing a guess based on those guide sections I quoted. The first thing the guide mentions is NFS. I didn't look up what NFS stands for. Since it's a file system thing, I agree with you. It doesn't seem related.

                    Based on the evidence of being able to connect to my company vpn after turning off scrub, isn't it logical to conclude that something scrub is doing is preventing PulseSecure from connecting to my company vpn?

                    1 Reply Last reply Reply Quote 0
                    • NogBadTheBadN
                      NogBadTheBad
                      last edited by

                      If it works for you great ☺

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      1 Reply Last reply Reply Quote 0
                      • M
                        mrneutron
                        last edited by

                        I am very frustrated to report that the PulseSecure client has been fooling me!
                        It appears PulseSecure connects even with the pfSense firewall scrub option enabled.

                        After I successfully connected to my company VPN, I noted:

                        1. I still got an error box popping up, after every login attempt.
                          Pulse Secure failed.jpg
                        2. The Pulse Secure window continues to say Securing Connection, even after a successful connection! It never changes from Securing Connection, to Connected!
                          Puse Secure Connection window redacted.jpg

                        It appears my trust in the feedback messages from Pulse Secure was misplaced.
                        PulseSecure appears to be a buggy, piece of crap, that has been misleading me!!

                        I'm sorry for wasting your time with this!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.