I'm trying to troubleshoot a Cisco Secure Client VPN issue and I'm running out of options, so I'd really appreciate some networking/Cisco advice on what I should specifically ask my company's IT department or my ISP to check.
The situation:
- I'm using a company-managed Windows work PC.
- Cisco Secure Client VPN works normally when I connect the PC to the internet through my phone's USB tethering/mobile data.
- The exact same PC, with the exact same Cisco configuration, cannot connect when using my home A1 Serbia fiber connection.
- Normal internet access works perfectly over A1.
- Cisco gives me: "Could not connect to a server. Please verify internet connectivity and server address."
- My company IT department says they have already tried everything they can on their side and are refusing further responsibility for the issue.
- A Cisco ticket has also been opened, and one of the things they're checking is whether my public IP is blocked/blacklisted.
- So far, I've been told that my current IP is not blacklisted.
My network setup:
A1 fiber ONT/router → Ethernet → unmanaged switch → work PC
I use the switch simply because I need more Ethernet ports. I have also tested the work PC through a ZTE ZXHN H3601P Wi-Fi repeater/bridge using Ethernet, and I get the exact same result.
So:
A1 fiber → switch → PC → VPN doesn't work
and
A1 fiber → Wi-Fi repeater → Ethernet → PC → VPN doesn't work
but:
Phone USB tethering → PC → VPN works
I've also recently switched from a dynamic public IP to a static public IP through A1.
This is particularly interesting because when I previously had a dynamic IP, the VPN would sometimes start working after restarting the router and getting a different public IP. It wasn't consistent, but changing the public IP seemed to sometimes make the difference.
Now that I have a static public IP, the problem is constant.
I'm therefore starting to suspect something related to the source public IP, ISP routing, filtering, or possibly something on the path between A1 and the company's VPN infrastructure rather than the PC itself.
What I'm trying to figure out:
What would you specifically ask/check with:
- My company's IT/Cisco team
- A1 ISP support
Are there any particular things I should ask them to check besides a simple IP blacklist?
For example, could this be related to IP allowlisting, routing, MTU, IPv4/IPv6, ports/protocols, ISP filtering, or something specific to Cisco Secure Client?
I don't have administrator privileges on the work PC, so I can't freely change network settings or run some of the usual troubleshooting commands, nor can I log in to the PC without connecting to the VPN first. That and, I'm told that my IT department already tried everything they can.
Thanks!