Two tunnels - one customer - one tunnel doesn't let me rdp - other one does.

I have setup Cloudflare for a customer and it works beautiful. she has a windows 10 workstation in azure for $19 and she uses Cloudflare for a non public ip. her systems at her office have zero trust and connect to the domain and allow her to access the applications in azure. outstanding.

I now need to do the same thing for a small system that is at her office (not in azure). I setup a new tunnel and installed the agent on a 192x.x.x ip. I can see the tunnel is healthy but am not able to rdp to 192x.x.x ip. What am I missing? It appears when I do a tnc 192x.x.x while connected to zero trust, my system tries to stay inside the network and not use cloudflare.

Any ideas would help. Thank you in advance.
Was this page helpful?