04-10-2019 12:46 AM
I setup a site to site vpn by 2 rv340 router. One side use static IP and other side use dynamic IP. After vpn established, I can ping 2 routers(192.168.0.8 and 192.168.0.2) in HQ site from remote site (192.168.25.1), but the server (192.168.0.36) can't be ping. I don't know what's wrong. Anybody can help?
Thanks,
Nicholas
04-10-2019 12:48 AM
Hi,
What is default gateway on server? Is ICMP allowed on system firewall? Are you able to ping remote site ip from the server itself?
04-10-2019 01:05 AM
I can ping 192.168.0.8 and 192.168.0.2 from remote site computer 192.168.25.11. I set ip router 192.168.25.0 255.255.255.0 192.168.0.17 on 192.168.0.8 (netscreen router)and 192.168.0.2(cisco router). The gateway for the 192.168.0.36 is 192.168.0.2. The gateway for 192.168.25.11 is 192.168.25.1. 192.168.0.36 can ping 192.168.25.11.I setup the site to site vpn follow the manual of Cisco. no additional settings.
04-10-2019 12:59 AM
Hi there,
Assuming ICMP is permitted on the server, check that the rule will permit a response to non-local subnets (ie, not 192.168.0.0/24)
cheers,
Seb.
04-10-2019 01:09 AM
04-10-2019 11:53 AM
192.168.25.1-->192.168.0.17
This proves either you have some policies dropping at FW side.
From 192.168.0.17 can you able to ping 192.168.0.36 ?
how about ping from 192.168.0.36 to other side ?
04-10-2019 07:50 PM
Yes, 192.168.0.36 and 192.168.0.17 can ping each other.
192.168.0.2 is a cisco router. 192.168.0.8 is a netscreen router. The computer set 192.168.0.8 as gateway can be ping by subnet 192.168.25.0. others can't be ping if the gateway set to 192.168.0.2. I think this issue is caused by the cisco. I just investigating that router but don't know why. Will post the result if I got it.
Regards,
Nicholas
04-10-2019 08:33 PM
this case can you able to ping from(192.168.0.2 is a cisco router) ? if yes post 192.168.0.2 is a cisco router config.
04-10-2019 11:15 PM
04-10-2019 11:21 PM - edited 04-10-2019 11:25 PM
in 192.168.0.2, if I set ip route 192.168.25.0 255.255.255.0 192.168.0.8, I can't ping the 192.168.0.2 from remote site. change to ip route 192.168.25.0 255.255.255.0 192.168.0.2. then I can ping these 2 routers. all PC/server set gateway to 192.168.0.2 can't be ping from remote site. gateway set to 192.168.0.8 is ok.
04-10-2019 12:41 PM - edited 04-10-2019 10:28 PM
There will be two reasons. 1. Anything blocking on the firewall so can you any ACL applied on the router or inspection also may drop the ICMP.
2. Did you disable the windows firewall and tested it?
One question:- why both routers having default gateway as server address? Is there anything special service on the server which not mentioned in this diagram?
04-10-2019 11:58 AM
Is there a switch between your rv340 and the other endpoints? It is not depicted on your diagram and I don't want to assume.
04-10-2019 11:14 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide