01-25-2020 09:36 AM - edited 01-27-2020 06:03 PM
hi,
I am using 2 rv340 routers on my 2 wan sites. i have 2 networks connected via a site-to-site vpn. 192.168.0.0 and 192.168.6.0.
I also have a l2tp vpn setup for remote users. network is 192.168.10.0 (this vpn is setup on the router for 192.168.0.0 network)
When a remote user is connected to router (ip 192.168.0.11), it can see the 192.168.0.0 network but it cannot see the subnet 192.168.6.0. I have added 192.168.10.0 to the both routers site to site vpn entries, but still nothing.
I used the router debug packet capture using http://routerip/debug/packet_capture.html and i found out that the traffic from the 192.168.10.0 network is going towards my ISP static ip address (wan address) but the traffic from my 192168.0.0 network is going directly to 192.168.6.0 network (probably over the site-to-site vpn).
Please help !!!
01-25-2020 10:43 AM
Hello,
what do you mean with 'remote users' ? Are these users connected to either router through a VPN connection ? What about local LAN users on each side, can they reach the respective remote LAN ?
01-26-2020 09:09 AM
01-26-2020 09:13 AM - edited 01-26-2020 09:15 AM
below is the diagram for the network: 2 sites. AAP site (192.168.0.0) is where i have the router with the l2tp vpn setup. And the GAP site is the remote subnet. The users logging in from home are able to see all devices on aapsite but not on gap site.
01-26-2020 12:01 PM
Hello,
is the AAP router the L2TP server, and if so, is the address pool added to the Local Traffic Selection in the Site-to-Site VPN configuration ?
01-26-2020 02:19 PM
The original poster tells us that " I have added 192.168.10.0 to the both routers site to site vpn entries". I assume that means that 192.168.10.0 has been added to the access lists used to identify interesting traffic for the site to site vpn. It might be nice to see the details of that part of the configuration so that we can verify that 192.168.10.0 is a source going to 192.168.6.0 and is a destination coming from 192.168.6.0 to 192.168.10.0.
Beyond that there are several things that might be causing this issue:
- can you verify that the GAP router has a route for 192.168.10.0 that sends the traffic through the vpn?
- if there is any address translation being done on either router can you verify that 192.168.10.0 to 192.168.6.0 and 192.168.6.0 to 192.168.10.0 is exempt from translation?
- we do not know anything about how l2tp vpn is configured. Can you verify that l2tp vpn includes 192.168.6.0 as a valid destination network and that traffic from the remote client to 192.168.6.0 is transported over the vpn?
HTH
Rick
01-27-2020 05:50 PM - edited 01-27-2020 06:06 PM
Hi rick,
on both routers, the firewall features are turn off. This is a small business router (rv340).
1. I have 192.168.10.0 network added as a static route on the gap router (192.168.6.11) and as part of the "ip address group" on both aap router and gap router site-to-site vpn configuration.
2. The routers on both sites are small business routers rv340. they don't allow any configuration through the console only thru the web interface.
3. for the l2tp vpn setup, there is not a lot of options on the web interface. i have added a picture to my post (See below).
01-28-2020 06:10 AM
Thanks for the additional information. It does seem that there are not many options for configuring L2TP.
Is the GAP router doing any address translation?
HTH
Rick
01-29-2020 09:29 AM
gap router is doing NAT for wan traffic in the local network (192.168.6.0). But i have 192.168.10.0 network added in the site-to-site vpn config.
01-29-2020 02:24 PM
Thanks for the additional information. Is it possible that traffic from 192.168.6.0 going to 192.168.10.0 is getting translated?
HTH
Rick
02-01-2020 03:59 AM
02-01-2020 08:52 AM
I do not have much experience with that model of router and do not know what tools it offers to verify what is being translated. Perhaps a start would be for you to show us the section where translation is specified.
HTH
Rick
01-27-2020 05:43 PM
01-26-2020 02:12 AM
Hello
can you post a topology diagram please to help to visualise your setup and the issue your experiencing
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide