cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1411
Views
10
Helpful
3
Replies

RV160W with OpenVPN: same IP for different clients at the same time

I have prepared certificates and client ovpn files for an OpenVPN connection.

Clients can connect successfully. But when more clients connect concurrently, they got the same IP address, so connection goes wrong.

If I create a VLAN for VPN with DHCP server, client address pool gives the following error:  Subnet range error

Did I miss some additional setting?

Firmware: 1.0.01.01

Tunnel mode: Split tunnel

 

1 Accepted Solution

Accepted Solutions

Hi there,

 

You will need just one CA Certificate which you'll use to sign your server certificate. If you choose the end clients to authenticate with password and certificate for more secure connectivity then the client must have also a separate certificate. 

 

Regards,

Martin

View solution in original post

3 Replies 3

Martin Aleksandrov
Cisco Employee
Cisco Employee

Hello,

 

You should get your multiple VPN clients assigned different IP addresses from the client IP address pool on your RV160 Open VPN server. Make sure you have chosen the right size of the network and respectively the subnet mask. You must choose a network subnet that isn’t used anywhere else in your network. You also don't need to create VLAN for the VPN with a DHCP server. Have you followed the configuration steps of this following guide: https://www.cisco.com/c/en/us/support/docs/smb/routers/cisco-rv-series-small-business-routers/smb5879-openvpn-on-rv160-rv260.html ?

 

 

Regards,

Martin

 

Thank you, Martin.

Yes, I have followed the above mentioned guide. It was useful!

But does your answer mean, that I should create as many certificates first as many users I want to supply with ovpn clients file?

Hi there,

 

You will need just one CA Certificate which you'll use to sign your server certificate. If you choose the end clients to authenticate with password and certificate for more secure connectivity then the client must have also a separate certificate. 

 

Regards,

Martin