The VPN connects, but an internal site is unreachable. How would you use these routes?

Instruction: Interpret the DNS and routing evidence, identify the next read-only check, and explain a safe escalation. Do not change tunnel policy or add routes without authorization.

Context:

A Windows 11 employee at home connects the approved corporate VPN. The application owner confirms that https://records.corp.example should resolve to 10.44.8.20. Fictional excerpts:

VPN status: Connected
Resolve-DnsName records.corp.example -Server 10.60.0.53 -DnsOnly
  A: 10.44.8.20
Selected Get-NetRoute -AddressFamily IPv4 rows:
  DestinationPrefix  InterfaceAlias  NextHop
  0.0.0.0/0          Wi-Fi           10.44.0.1
  10.44.0.0/16       Wi-Fi           0.0.0.0
  10.60.0.0/16       Corporate VPN   0.0.0.0
Test-NetConnection 10.44.8.20 -Port 443
  InterfaceAlias: Wi-Fi
  TcpTestSucceeded: False

These selected rows are not the entire routing table. The VPN/network team owns the approved route and access policies.

Updated

Official answer available

Read the opening below, then unlock the full answer and practical guidance.

I'd focus on why the resource test selects Wi-Fi even though the VPN says Connected. The explicit DNS response is useful, but it does not explain that path or prove the full connection works. I'd preserve the current configuration and compare route selection with the approved VPN design before asking its owner for a targeted correction...

Related Questions