cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1561
Views
0
Helpful
3
Replies

TeamViewer remote is not working properly when a remote user is connected via AnyConnect VPN

CarloSalvador
Level 1
Level 1

Hi Guys,

 

Just would like to ask for your advice about the issue I have.

 

We have a remote offices in the UK with IT Deskside guys onsite. These IT Deskside guys when inside the office network tries to remote a user who is working from home - connected via AnyConnect VPN, the IT Deskside guys can connect to the remote user via the TeamViewer, but when they are start navigating the IT Deskside cannot see what is happening. Though the remote user can see the actions navigated by the IT Deskside guys.

Here are my isolation did to test:

IT Deskside inside UK office to Anyconnect VPN user (UK Anyconnect server) = NOT OK - connected but not seeing the motions.
IT Deskside inside UK office to Anyconnect VPN user (US Anyconnect server)= NOT OK - connected but not seeing the motions.

IT Deskside inside UK office to User also inside the office = OK - working as expected
IT Deskside inside UK office to User connected to Public Internet = OK - working as expected

IT Deskside inside Non-UK office (Phillipines) to AnyConnect UK VPN user = OK - working as expected
IT Deskside connected to AnyConnect VPN to AnyConnect UK VPN user = OK - working as expected
IT Deskside connected to Public Internet to AnyConnect UK VPN user = OK - working as expected
IT Deskside connected to Public Internet to User connected to Public Internet = OK - working as expected

Note: We only have TeamViewer as standard remote tool for all our Country offices, so unfortunately we cannot test any other remote tool.

Note: The UK offices are behind Palo Alto for Internet outbound.

Note: We have Split-Tunnel ACL configured on UK VPN so I did try to add the teamviewer.com IP address to that ACL but still to no avail.

Hoping you could share some tips or how to resolve this very bizarre issue.


3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

First place to start capture logs where the VPN termniated, to see how this is behaving Accepted or denied ? how is the routing ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

hi @balaji.bandi thank you for your response to start the capture logs. I checked the logs on Palo Alto for the rule it is hitting, I can see it is allowed. Though it has a Session End Reason "unknown" this is to port 59310. The other traffic is to 55055 on the same rule hit with Session End Reason "aged-out"

I don't see much information when I explore the logs.

If the GUI not givng enough ifnormation you need to command level capture whole picture of the transaction to idea what is wrong.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help