cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3146
Views
0
Helpful
3
Replies

Site-to-site IPSec VPN connected (2 - RV345's) but can't ping PC's in remote network

hlcons
Level 1
Level 1

Hi -

The IPSec VPN says it's UP and Connected.  I can ping router to router, but I am unable to ping a PC/Server on the remote network.  Any suggestions??

FYI. using static IP's.

Thanks in advance,

-h

1 Accepted Solution

Accepted Solutions

USER ERROR!

Finally got back to site A and checked configuration for static IP's (devices I was trying to ping) and realized the default gateway (192.168.1.10 - old def gw) hadn't been updated for the newly installed router (192.168.1.1)!  Everything else was using DHCP - so this slipped by me!

 

 

 

View solution in original post

3 Replies 3

hlcons
Level 1
Level 1

OK after doing a little more troubleshooting.  I discovered I can successfully ping (from remote router) a remote PC after disabling it's (the PC's MS Windows firewall) firewall (or adding 'ICMP Echo Request' rule to the firewall).

I was under the impression that the IPSec VPN would "allow a remote host to act as if it were on the same LAN.", so there would be no need to add rules to the firewall.  Is this an incorrect assumption?

 

Also, trying a traceroute from router on the same 'pingable' PC - just hangs!

 

 

Hello,
My name is Rozana and i am an engineer from the Small Business Team.

In the IPsec tunnels, the traffic is passed from 1 LAN to the other, but the IP addressing remains the same. Once you enter the remote LAN, the IP address is not being changed.

The connection between the 2 WANs is encrypted along the way, and the traffic from the remote network is being allowed to pass through the RVs firewall.

That is why you need to turn off the ICMP firewall rules in the machines, as you are in fact reaching the device from a different subnet, and the device firewall is blocking remote ICMP requests.

If you use other services, you can allow only them in the servers firewall - for example if you have a Web server, you can allow access from remote networks on the firewall, only for that service.

Regards.

USER ERROR!

Finally got back to site A and checked configuration for static IP's (devices I was trying to ping) and realized the default gateway (192.168.1.10 - old def gw) hadn't been updated for the newly installed router (192.168.1.1)!  Everything else was using DHCP - so this slipped by me!