11-22-2018 06:10 AM - edited 11-22-2018 08:03 AM
Hello all,
Here is the technical situation :
Everything is working as intended except routing VLAN 2 subnets through the VPN tunnel :
- I cannot reach 172.31.173.0 subnet from site A
- I cannot reach 172.31.172.0 subnet from site B
Please note :
- Reaching 172.31.172.0 network hosts from Cisco RV320 on site A is working
- Reaching 172.31.173.0 network hosts from Cisco RV320 on site B is working
- L3 switches are the default gateway for all hosts on their respective subnets
So I don't succeed to route 172.31.172.0 and 172.31.173.0 subnets through VPN tunnels.
What am I missing ?
In advance, a big thank to those who will spend some time on this problem :-)
Denis
Solved! Go to Solution.
12-03-2018 11:01 AM
Hello Georg,
I finally found the solution by myself.
The keypoint is that RV320 seems to be unable to route trafic for a VLAN of which is not a member of.
So on each RV320 :
The working configuration schema becomes then :
Thanks again for your assistance.
Best regards,
Denis
11-24-2018 01:11 PM
Hello,
what does your Local and Remote Group setup look like (page 83 thru 85 in the attached guide) ?
https://www.cisco.com/c/dam/en/us/td/docs/routers/csbr/rv320/administration/guide/en/rv32x_ag_en.pdf
11-26-2018 01:20 AM
Hello Georg,
Here they are with details (sorry for bad quality pictures).
Site A :
Site B :
One thing I would like to point out is the different traceroute results between site A and site B. It seems that the RV320 in site A does not forward packets to VLAN 2 of site B through its VPN tunnel but I cannot find the culprit in the GUI :
From site A (VLAN 1) to site B (VLAN 2) :
From site B (VLAN 1) to Site A (VLAN 2) :
Thanks for your help. Very much appreciated :-)
Denis
11-26-2018 01:35 AM
Hello,
stupid question maybe, but I assume both devices are in gateway mode ?
Can you try and enable RIPv2 and check the routing table (page 41 of the attached guide) ?
Your traceroute show the public IP address, which should not be visible at all. How is your NAT setup ?
11-26-2018 02:26 AM
Re,
No stupid questions, only stupid answers ;-)
So yes indeed, both RV320 are in GW mode.
Site A :
Site B :
As suggested I tried to enable RIPv2 but that did not solve the problem...
==> So I revert back to RIP disabled.
Thanks,
Denis
11-26-2018 03:26 AM - edited 11-26-2018 03:44 AM
Should I redo the RV320 config of Site A from scratch ?
11-26-2018 04:36 AM
Hello,
I cannot tell from your screenshoys what the tunnel endpoints are. Do the static routes have the other end of the tunnel as the next hop, on both sides ?
11-26-2018 04:45 AM
Yes, they have both the RV320 LAN IP from other site as the next hop.
Site A :
Site B :
If you need more informations or value hidden in a picture, I can send it to you in PV ...
Best regards,
Denis
11-26-2018 04:55 AM
Hello Denis,
I am looking at some other posts. Can you check your Dual WAN setting (System Management --> Dual WAN, page 56 of the guide) ? Make sure you select Smart Link Backup (Load Balance is the default, so you have to manually change that)...
11-26-2018 05:13 AM
Georg,
Again, many thanks for the time you are spending on this case. This is very much apreciated !
So as asked, I switched Dual Wan Load Balance Mode to Smart Link Backup on both sites :
Unfortunately that did not solve the problem. However I kept this setting as it because you advised me to do so.
Denis
11-26-2018 05:18 AM
Hello Denis,
below is the link to the post that suggested to change the Dual WAN setting. There are some other suggestions, you might want to read through that and see if it helps...
11-27-2018 05:14 AM
Hello Georg,
Unfortunately the problem remains : unable to route 172.31.x.x trafic between both sites.
By the way, what I pointed out before, regarding the different results in the traceroute tests between site A and B is not revelant (actually this is coming from the different behavior of equipments beyond the FW because of different provider). It is now cleary appearing to me that both routers RV320 do not forward 172.31.x.x trafic through the VPN tunnel but route it through the internet connection...
I am really wondering what's wrong in my setup... RV320 should normally be able to handle that without any problem.
Any further help would be really appreciated :-)
Denis
12-03-2018 11:01 AM
Hello Georg,
I finally found the solution by myself.
The keypoint is that RV320 seems to be unable to route trafic for a VLAN of which is not a member of.
So on each RV320 :
The working configuration schema becomes then :
Thanks again for your assistance.
Best regards,
Denis
12-03-2018 11:07 AM
Hello Denis,
good stuff, glad that you found the solution, I will definitely keep it on file.
10-28-2019 02:57 AM
Hi Georg, the link you share is remove or something else, i can't find the guide in this. Can you check again!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide