This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DNS issue when I connect to SSL VPN via tunnelblick

I am trying to connect via VPN to a remote site  that has Sophos Firewall installed. 

For this am using this tutorial on configuring VPN for Mac OS X (here)

Am using a MacBook pro with Catalina OS. 

The connection happens, but I get an alert that DNS is not working and the internet also stops working. 

How should I fix this. 



This thread was automatically locked due to age.
  • Hello T Kab,

    Thank you for contacting the Sophos Community!

    How are you configuring the SSL VPN tunnel, it is a full tunnel or split tunnel?

    What did you enter under Local Networks? If you entered All IPv4 or Manually 0.0.0.0/0 Then it is a Full tunnel, all traffic including the internet traffic will be routed via the UTM and be sent out via the UTM, if this is the case you need to create a Masquerading Rule to allow the VPN Pool (SSL) to be NAT to your WAN address.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • Good question, I have looked up full and split tunnel. I believe what I want is the split tunnel. But I did not enter a thing under local networks.

    The goal is to access the company VPN websites and internal resources. My browsing should continue through local network. 

    How am I doing it, as shown in the URL I shared,

    1, I log on to the Sophos User Portal, download the OVPN Client which has the certificate and some settings

    2. Open this OVPN via tunnel blick. 

    3. Click connect, enter sophos VPN username and password. 

    4. Connect. 

    I tried to tweak with the Tunnelblick settings for IPv6, setting name server, dns flushing, setting dns before and after connection. 

    But nothing seems to be working. 

    Here are the Tunnel blick settings, There is no option to enter all IPv4. 

    1. Default settings: Image 1

    2. Advanced Settings. Image 2 and 3