NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
wispman
Feb 01, 2022Aspirant
Connecting two FVS318v2 VPN Servers each running under a gateway routers - VPN tunnel between them
I am trying to create a VPN connection between two FVS318v2 routers both running firmware V2.4 (July. 19 2004). Each FVS318 router is connected under the main gateway router that connects to the Internet. ie. the WAN ports of the FVS318's are connected to a LAN port on the gateway router above it. The gateway routers each connect to the Internet with a fixed IP address. I port forward through each of the Gateway routers in order to remotely administer each of the FVS318 routers. I can remote administer each router from anywhere on the Internet but I can not create a VPN tunnel between the pair of FVS318 routers. Alternately nor can I create a VPN tunnel between a remote PC running Netgear Prosafe VPN Client Lite 5.5 on the remote network tunneling to the main FVS318 VPN This software VPN client configuration is an alternate senario to having a remote FVS318. I put the main FVS318 behind a DMZ and that does not seem to be of any help. I find no information regarding having to port forward a specfic port to the FVS318 routers for VPN operability other than for remote adminstration of the FVS318. I find no information on how to do this or even if such a network configuration is even possible. All documentation I see has the VPN router as the top level router connecting directly to the Internet. At this point I don't want to get into the specific VPN configurations in each of the FVS318 routers as I need to know if I can even do what I have diagrammed. I hope the attached image helps. I desingned, built, and operated a 12 node WISP spanning 5 miles of difficult terrain with a dozen Ubiquiti radios and a dozen routers coneected over multiple hops with less work than I have put into this VPN problem. I have 40 hours into this VPN problem so I don't just willy nilly jump on forums for answers with a poorly documented question. I have done a lot of searching and research prior to getting to this point. I have accumulated every Netgear document from the past 15 years and I can't find the answer.
I might add I want to continue using my Slingbox to placeshift my OTA TV to a remote location after the Slingbox server is shut down in November 2022. That will render my remote TV viewing inoperative. Slingbox claims that Slingboxs will continue to work locally within the LANwhere they are connected. Rather than sling my OTA TV from living room to the bedroom I want to sling from living room to a remote household location. Not just me, but thousands of Slingbox owners will be out of service in November 2022. If I can solve this problem with a VPN then many others might well be interested.
4 Replies
- DaneANETGEAR Employee Retired
You will need to consider having the 2 FVS18v2 be configured as the main router then afterwards configure a box-to-box VPN tunnel between the 2 FVS318v2.
Regards,
DaneA
NETGEAR Community Team
- wispmanAspirant
I am informed that my router behind router VPN will not work. I have read elsewhere the port forwarding IPsec port 500 and L2TP port 1701 to the VPN routers may allow it to work. Yes, No?
- SamirDProdigy
I have attempted to create site to sites like this before and the only way I have gotten it to work is to place the netgear in the dmz of the gateway router--this way everything is passed to the netgear. Sometimes this will work and other times it will not.
And because site to site tunnels can also fail for just small configuration errors on one or both sides, I would first take both 318s and bring them to one site and create a working tunnel between them. You basically connect both of them to the lan the same way you have already and then each one has a 'public' ip that's on the same lan. Then you can get a tunnel working between them (and even test throughput if you want as that's what I've used this for). Once you have a working tunnel, you only need to move one unit and change only what you need to so it's easier to catch a mistake.
Hope this helps!
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!