DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Difficulty with multiple VPNs
- yankeedave
- Topic Author
- Offline
- New Member
Less
More
- Posts: 3
- Thank you received: 0
01 Apr 2019 09:22 #94318
by yankeedave
Difficulty with multiple VPNs was created by yankeedave
Hi
I am working with several remote sites in a region remote to me. I have a local Draytek Vigor 2860 set up with an IPSEC VPN to a Draytek Vigor 2830 in our remote office. I also have several (about 20) IPSEC VPNs set up with 3G InHand routers at different remote locations for CCTV coverage. Is it possible to connect to the remote CCTV sites using my local IPSEC tunnel? I can see the back office machines attached directly to the 2830 but not the further CCTV devices. Any thoughts? Thanks for all your help in advance.
I am working with several remote sites in a region remote to me. I have a local Draytek Vigor 2860 set up with an IPSEC VPN to a Draytek Vigor 2830 in our remote office. I also have several (about 20) IPSEC VPNs set up with 3G InHand routers at different remote locations for CCTV coverage. Is it possible to connect to the remote CCTV sites using my local IPSEC tunnel? I can see the back office machines attached directly to the 2830 but not the further CCTV devices. Any thoughts? Thanks for all your help in advance.
Please Log in or Create an account to join the conversation.
- admin
- Offline
- Site Admin
Less
More
- Posts: 1723
- Thank you received: 0
02 Apr 2019 17:00 #94321
by admin
Forum Administrator
Replied by admin on topic Re: Difficulty with multiple VPNs
Topology unclear... how are these inhand routers connected.... to another WAN connection?
Forum Administrator
Please Log in or Create an account to join the conversation.
- yankeedave
- Topic Author
- Offline
- New Member
Less
More
- Posts: 3
- Thank you received: 0
11 Apr 2019 10:20 #94364
by yankeedave
Replied by yankeedave on topic Re: Difficulty with multiple VPNs
Please Log in or Create an account to join the conversation.
- admin
- Offline
- Site Admin
Less
More
- Posts: 1723
- Thank you received: 0
14 Apr 2019 08:59 #94376
by admin
Forum Administrator
Replied by admin on topic Re: Difficulty with multiple VPNs
So the inhand routers are at each site and are terminating the VPNs? I'd check that each tunnel profile at the remote ends is set correctly to know the subnet and mask at your LAN end. Then use ping for further diagnostic (see if you can ping the cameras).
Forum Administrator
Please Log in or Create an account to join the conversation.
- yankeedave
- Topic Author
- Offline
- New Member
Less
More
- Posts: 3
- Thank you received: 0
24 Apr 2019 11:55 #94413
by yankeedave
Yes, they are the far end of the tunnels. I can ping the router and server in the middle but not any further. If I log into the server, I can ping the remote sites. I am just unsure of how to connect to the CCTV camera at the far end.
Replied by yankeedave on topic Re: Difficulty with multiple VPNs
So the inhand routers are at each site and are terminating the VPNs? I'd check that each tunnel profile at the remote ends is set correctly to know the subnet and mask at your LAN end. Then use ping for further diagnostic (see if you can ping the cameras).admin wrote:
Yes, they are the far end of the tunnels. I can ping the router and server in the middle but not any further. If I log into the server, I can ping the remote sites. I am just unsure of how to connect to the CCTV camera at the far end.
Please Log in or Create an account to join the conversation.
- admin3
- Offline
- Site Admin
Less
More
- Posts: 604
- Thank you received: 0
25 Apr 2019 09:33 #94423
by admin3
Forum Administrator
Replied by admin3 on topic Re: Difficulty with multiple VPNs
If there's an IPsec LAN to LAN VPN between the 2860 and the 2830 - one way to get that working would be to switch the tunnel type from Routing mode to "NAT" mode, so the 2860 and devices connecting through it, would appear to be a device on the 2830's network.
The reason it doesn't work is that the remote sites aren't aware of the 2860's LAN IP range being available through their VPN tunnel - that would need to be set up on the "More" ip settings of each LAN to LAN VPN on each of the 3G sites, with the 2860 having all of those IP ranges in the "More" section of its own VPN.
The reason it doesn't work is that the remote sites aren't aware of the 2860's LAN IP range being available through their VPN tunnel - that would need to be set up on the "More" ip settings of each LAN to LAN VPN on each of the 3G sites, with the 2860 having all of those IP ranges in the "More" section of its own VPN.
Forum Administrator
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek