Ask
Reply
Solution
23-10-2023 02:02 PM
Hi All
Recently we started having issues using our Cisco 4g/LTE Routers where we are struggling to enroll onto a VPN because the certificate fails to be retrieved for the trustpoint (Headend) - feels like an intermediate cert is invalid or failing or similar
This has started suddenly as our router configs have not changes and we've been using vodafone for years
On deeper troubleshooting it seems the issue is the DNS server assigned from Vodafone - in situations when this works, the DNS servers appear to be 10.203.128.1
95% of the times, however, the DNS issues is 192.168.253.1 and this results in failed enrolment although the internet connectivity does seem to work on 80 and some 443
Is there something that may have changed Vodafone side in the last few months that could be causing this behaviour or has there been a change that would've have affected the DHCP details Vodafone side?
M
23-10-2023 07:03 PM
23-10-2023 07:52 PM
This looks awfully like a CGNAT issue. Both the DNS IP addresses you list are within private networks, so it's likely that your own IP address is not unique to but actually shared with other users. You probably need to speak to whoever administers your VPN about working around CGNAT issues.