DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Access site 2 host via LAN to LAN from Dial-in VPN to Site 1
- waynek
- Topic Author
- Offline
- Banned
Less
More
- Posts: 6
- Thank you received: 0
09 Aug 2017 07:08 #89416
by waynek
Access site 2 host via LAN to LAN from Dial-in VPN to Site 1 was created by waynek
Hi,
I'm having trouble setting up (and finding the search terms sweet spot when googling) this VPN scenario:
Dial in VPN user (192.168.1.x) ---> Site 1 (VIgor 2860/VDSL) ---> LAN to LAN VPN ---> Site 2 (VIgor 2860/LTE) ---> Host on Site 2 LAN (192.168.2.x)
The LAN to LAN VPN is setup and working OK, I'm able to SSH to hosts to/from both subnets.
The Dial-In VPN works.
It's just once I'm VPN'ed into Site 1 i'm not able to contact any host (by IP) in the site 2 subnet from the dial-in VPN client (clients tested so far are iOS and Mac).
If anyone can help, that would be great.
Thanks
Wayne
I'm having trouble setting up (and finding the search terms sweet spot when googling) this VPN scenario:
Dial in VPN user (192.168.1.x) ---> Site 1 (VIgor 2860/VDSL) ---> LAN to LAN VPN ---> Site 2 (VIgor 2860/LTE) ---> Host on Site 2 LAN (192.168.2.x)
The LAN to LAN VPN is setup and working OK, I'm able to SSH to hosts to/from both subnets.
The Dial-In VPN works.
It's just once I'm VPN'ed into Site 1 i'm not able to contact any host (by IP) in the site 2 subnet from the dial-in VPN client (clients tested so far are iOS and Mac).
If anyone can help, that would be great.
Thanks
Wayne
Please Log in or Create an account to join the conversation.
- waynek
- Topic Author
- Offline
- Banned
Less
More
- Posts: 6
- Thank you received: 0
10 Aug 2017 10:00 #89421
by waynek
Replied by waynek on topic Re: Access site 2 host via LAN to LAN from Dial-in VPN to Si
Draytek support simply replied to my ticket with the one liner: 'Disable the Firewall on the clients', not really an option!
If anyone has any sensible solution I'm all ears, thanks.
If anyone has any sensible solution I'm all ears, thanks.
Please Log in or Create an account to join the conversation.
- admin
- Offline
- Site Admin
Less
More
- Posts: 1723
- Thank you received: 0
10 Aug 2017 20:05 #89425
by admin
Forum Administrator
Replied by admin on topic Re: Access site 2 host via LAN to LAN from Dial-in VPN to Si
Why isn't that sensible or an option; software/device firewalls do often block routing to reserved subnets...
Forum Administrator
Please Log in or Create an account to join the conversation.
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank you received: 0
11 Aug 2017 01:06 #89427
by hornbyp
Replied by hornbyp on topic Re: Access site 2 host via LAN to LAN from Dial-in VPN to Si
Adding rules to a firewall to allow required traffic through is a valid option. Just turning a firewall off isn't (other than as a quick test).
I know nowt at all about IOS and Mac, so I can't offer any help though.
I know nowt at all about IOS and Mac, so I can't offer any help though.
Please Log in or Create an account to join the conversation.
- waynek
- Topic Author
- Offline
- Banned
Less
More
- Posts: 6
- Thank you received: 0
21 Aug 2017 11:28 #89458
by waynek
As 'hornybyp' wrote: "Just turning a firewall off isn't [sensible] (other than as a quick test)"
There is no option in iOS to turn of the firewall, AFAIK on a non-jailbroken iOS.
Replied by waynek on topic Re: Access site 2 host via LAN to LAN from Dial-in VPN to Si
Why isn't that sensible or an option; software/device firewalls do often block routing to reserved subnets...admin wrote:
As 'hornybyp' wrote: "Just turning a firewall off isn't [sensible] (other than as a quick test)"
There is no option in iOS to turn of the firewall, AFAIK on a non-jailbroken iOS.
Please Log in or Create an account to join the conversation.
- sircles
- Offline
- New Member
Less
More
- Posts: 2
- Thank you received: 0
24 Aug 2017 12:23 #89473
by sircles
http://sircl.es Website and app development
http://www.TopOnGoogle.com SEO and Internet Marketing
http://store.sircles.net Computing On-line Store
Replied by sircles on topic Re: Access site 2 host via LAN to LAN from Dial-in VPN to Si
So is this an IOS or OSX client? Did you tick the box for 'send all traffic through connection' or similar?
Is the other subnet listed in the DrayTek VPN LAN as a secondary subnet so that the device knows to route to it internally?
Is the other subnet listed in the DrayTek VPN LAN as a secondary subnet so that the device knows to route to it internally?
http://sircl.es Website and app development
http://www.TopOnGoogle.com SEO and Internet Marketing
http://store.sircles.net Computing On-line Store
Please Log in or Create an account to join the conversation.
Moderators: Sami
Copyright © 2024 DrayTek