Cannot access oracle APEX when turn on Cisco VPN

Posted on 2014-09-03
Last Modified: 2014-09-05

I have installed Oracle XE (11g) and then installed Oracle APEX 4.2 on windows machine.

It had worked fine, I can access APEX via web browser, but after I connect to the VPN with Cisco Anyconnect, I cannot access the APEX page anymore. Error message is simply 'the webpage is not available'.  Then, I tried disconnected the VPN and then the page was accessible again.

Anyone has experienced something like this before?

Many thanks!
Question by:rapeepak
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
  • 2
LVL 77

Expert Comment

by:slightwv (䄆 Netminder)
ID: 40301310
What is the URL provided before the VPN is active?

My guess is the VPN changes the ip address of the machine thus, making the URL invalid.

Not done much with APEX of VPN's but can you use the loopback IP address while the VPN software is running?

If you are on windows, you might need to install the loopback adapter.

Author Comment

ID: 40301321
Oh sorry - I probably provided less information.

Let's say that I have windows box A installed both Oracle and APEX. I can access the APEX either from box A via localhost or from another machine (without VPN).

Then, from the box A, I connect to VPN for another purpose, retrieving data to oracle and that's why VPN needed.  With VPN on, I can't access to APEX anymore neither from the box A itself nor from another machine outside..

Do you think loopback adapter is required?

LVL 77

Expert Comment

by:slightwv (䄆 Netminder)
ID: 40301351
I think the VPN is changing machine A's networking information.

If the APEX URL without the VPN running is:

When you connect to the VPN 'myMachine' may not be reachable any more and you are bound by the domain controller of the Network.

You might be able to just add myMachine to the local hosts file but I'm not sure if that would over-ride the VPN information.
Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

LVL 74

Expert Comment

ID: 40301458
Changing the local hosts shouldn't work.  If it does, that would be a hole in the vpn client - but there are some clients that can allow limited local access though.  If you're using one of those I suppose it might be possible to edit your local hosts but that's not a normal feature.

That's what VPNs are for. It's even in the initials.

When you connect to a VPN you are in a new PRIVATE network.    It must, by necessity, run across your existing physical network, but the whole point of VPN is that once you are in, your old network is, in effect, gone.

Now, it still might be possible to get a route from your vpn network back to the apex server but that's going to be up to the network admins of whatever VPN you've connected to.

For example -
I can connect to from home, I can also connect to my own local apex apps.
When I vpn to work I can still connect to because my work network also provides access to the internet.
However, my work network does not extend back to my house, through my router and firewalls to get to my server running my apex app so even though it's sitting right next to me, I can't connect to it anymore.

And even if it did, my internal network name and my external name wouldn't be the same so the url would have to change anyway at least for my apps.

Author Comment

ID: 40302961
So basically I should prevent the VPN to pick up and reroute the loopback IP then?

Coz right now I still cannot hit the localhost with specific IP that APEX listening (but with port 80 and 443 that Apache is listening still be accessible).
LVL 77

Expert Comment

by:slightwv (䄆 Netminder)
ID: 40303294
Unfortunately my networking skills are really old and my VPN skills are pretty much non-existent.

I would work with your network staff to see if it is possible to access a local website once the VPN is active.

I tend to agree with sdstuber that this may not be possible due to what a VPN is designed to do, which is, make your machine part of another network that cuts ALL ties to any other network.  That way your machine cannot be used as a bridge between two worlds.

There may be some Cisco 'magic' that you might be able to set that will allow access to loopback but I don't know.

Author Comment

ID: 40303588
I would work with your network staff to see if it is possible to access a local website once the VPN is active.
Right now any local website, port 80 and 443 can be access via Apache but any port listening by APEX can't be reached...  

I am kind of confused now if this would be APEX's or network problem... :(
LVL 77

Assisted Solution

by:slightwv (䄆 Netminder)
slightwv (䄆 Netminder) earned 100 total points
ID: 40303615
>>I am kind of confused now if this would be APEX's or network problem... :(

Network people will tend to blame APEX, APEX people will tend to blame the network.  It is common for the issue to be with someone else.

APEX works without the VPN running.
Turn on the VPN and APEX stops.

Seems to me the VPN is interfering with your access to APEX at a network level.

My money is on the VPN blocking access.  but, I'm an Oracle person...  ;)
LVL 74

Accepted Solution

sdstuber earned 400 total points
ID: 40303656
My guess is you are using the embedded gateway (EPG) of XE which means your connections to the apex app have to go through the Oracle Listener and your vpn is blocking access to the listener.

The blocking is probably two-fold.  Explicitly by blocking the route back to your machine and implicitly by assigning a new machine name and domain so your listener doesn't recognize the machine it's running on.

For example, without the VPN if you run "lsnrctl status"  you'll probably see a line that looks something like this...


But once you start your VPN, your machine gets a new name

and now the listener doesn't think it's running on the correct machine and won't accept connections even if you somehow route the communication back to it.

Author Closing Comment

ID: 40304730
Thanks All! I've definitely found the solution.

When starting VPN, the machine gets a new name and the listener is running on the different domain which doesn't recognize the domain. I cannot do anything with the DNS in the VPN so I tried adding it to the hosts file (which had not been necessary before) and it did the trick.

Many thanks once again!

Featured Post

Is your NGFW recommended by NSS Labs?

Ours is! NSS Labs Next Generation Firewall Test gives the WatchGuard Firebox M4600 a "Recommended" rating! Curious where your NGFW landed on the  Security Value Map? See the map and download the full report today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Cursors in Oracle: A cursor is used to process individual rows returned by database system for a query. In oracle every SQL statement executed by the oracle server has a private area. This area contains information about the SQL statement and the…
Checking the Alert Log in AWS RDS Oracle can be a pain through their user interface.  I made a script to download the Alert Log, look for errors, and email me the trace files.  In this article I'll describe what I did and share my script.
This video shows how to set up a shell script to accept a positional parameter when called, pass that to a SQL script, accept the output from the statement back and then manipulate it in the Shell.
This video shows how to Export data from an Oracle database using the Datapump Export Utility.  The corresponding Datapump Import utility is also discussed and demonstrated.

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question