site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
767
Share Topic
Posting?
Post a:
Post a:
AuthorAll Replies


Sanary

@50.115.104.x

I can VPN to my office but I can not ping any machines

I setup a “Remote Access (Sever Role)” VPN using the info from »L2TP VPN on USG - quick how-to

I can VPN to my Win7 machine but I cannot ping anything on my home network (the machines are not on a domain).

As per the info from Brano, I setup my LAN_L2TP on a different subnet than the lan1, lan2 and wlan but I wonder how my Win7 machine knows how to use the VPN tunnel when I try to access any of my machines on my lan1 (192.168.11.0/24) or wlan (50.59.1.1/24).
(I did setup the routing rule and the firewall rules as per the doc above. I even try to set all the firewall rules to "any" just in case that was the problem).

Note: I changed the subnet of lan1 to 192.168.11.0/24 in case there was a conflict with my Comcast modem.

Here is what I get when I do a tracert print:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 172.16.11.1 172.16.11.104 20
0.0.0.0 0.0.0.0 172.16.11.1 172.16.11.110 25
255.255.255.255 172.16.11.1 172.16.11.104 21
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
172.16.11.0 255.255.255.0 On-link 172.16.11.104 276
172.16.11.0 255.255.255.0 On-link 172.16.11.110 281
172.16.11.104 255.255.255.255 On-link 172.16.11.104 276
172.16.11.110 255.255.255.255 On-link 172.16.11.110 281
172.16.11.255 255.255.255.255 On-link 172.16.11.104 276
172.16.11.255 255.255.255.255 On-link 172.16.11.110 281
192.168.250.0 255.255.255.0 On-link 192.168.250.1 21
192.168.250.1 255.255.255.255 On-link 192.168.250.1 276
192.168.250.255 255.255.255.255 On-link 192.168.250.1 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 172.16.11.104 276
224.0.0.0 240.0.0.0 On-link 172.16.11.110 281
224.0.0.0 240.0.0.0 On-link 192.168.250.1 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 172.16.11.104 276
255.255.255.255 255.255.255.255 On-link 172.16.11.110 281
255.255.255.255 255.255.255.255 On-link 192.168.250.1 276

What am I missing?

Thanks for your help


Brano
I hate Vogons
Premium,MVM
join:2002-06-25
Burlington, ON
kudos:6
Reviews:
·Bell Fibe

Once your VPN is successfully connected, then the rest is just matter of routing and firewalling.

1) Make sure you have firewall open from VPN LAN to home LAN(s) and vice versa.
2) Make sure you have appropriate policy routes in place to route your VPN traffic to LAN and vice versa.
3) Make sure that LAN PCs don't have any local firewalls (i.e. Windows firewall) blocking your connections.


sanary

join:2012-12-06

1 edit

Thanks Brano for the quick answer

Couple of things I forgot to mention:
a - In you info, you are blocking the intra zone

I am not blocking the intra zones since I want the VPN users to access the whole network. Here is what I have


Note: I am using IPSec_VPN for the VPN Zone

b - your info shows L2TP as a service wen building the tunnel:


L2TP does not exist in my configuration but L2TP_UDP does

Now regarding your answers:
1) Make sure you have firewall open from VPN LAN to home LAN(s) and vice versa.
I think I did configure it as per your info but since I was not going anywhere I also try to set every rules to “any” so nothing gets blocked (remember that my VPN zone is IPSec_VPN).
Would the following work (this is the default config):


2) Make sure you have appropriate policy routes in place to route your VPN traffic to LAN and vice versa.
Here is what I have


3) Make sure that LAN PCs don't have any local firewalls (i.e. Windows firewall) blocking your connections.
I turned off the Windows firewalls to make sure that was not the problem

One thing that I discovered (bear with me as I am new to this USG 20w product) is that when I am in the office (not connected through VPN but on the WLAN), I can ping any other computers on the wireless network but I cannot ping the wired computer on lan1 (I even have a laptop which is on the wireless network and the wired network > I can ping the wireless IP address (i.e. 10.59.1.33) but not the wired IP (192.168.1.33). This seems to indicate that intrazones are blocked (including the VPN one). I want everybody in the office been able to access all the machines regardless if they are on lan1, lan2, wlan or vpn.

What do I need to do?

Thanks for your help


sanary

join:2012-12-06

Still struggling with my VPN connections

I am assuming that it must be a routing issue because two clients connected through VPN cannot ping each other (the IPSec_VPN zone is not blocking Intra-zone).
Can anybody see something incorrect in my settings?

Note: my issue related to the wireless clients not been able to ping the servers on lan1 was due to a firewall entry missing


sanary

join:2012-12-06

Issue resolved. I had to upgrade to the latest firmware. The one that I had was buggy it seems.


hyde1

join:2012-11-16

said by sanary:

Issue resolved. I had to upgrade to the latest firmware. The one that I had was buggy it seems.

Could you please check your PM?

Tuesday, 21-May 16:39:33 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.
Most commented news this week
Hot Topics