NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
franck_martin2
May 29, 2013Aspirant
IPSec VPN with SRX5308
Hi everyone,
I bought recently a SRX5308 firewall. I want to achieve a Client to Gateway IPSec VPN with this device. I used the VPN Wizard to configure the Gateway and I installed the Netgear VPN Prosafe client on a Windows 7 computer. I can open the tunnel but I get two issues :
* When the tunnel is open, I can't go on Internet (DNS fails)
* I can't ping any host in the remote LAN, even the VPN gateway.
I made some tests and I found that the client ping packets reach the LAN host I want to ping, the LAN host send its reply to gateway, but gateway doesn't arrive to send packets to the client.
What should I do to solve my problem ?
Thanks for your help.
I bought recently a SRX5308 firewall. I want to achieve a Client to Gateway IPSec VPN with this device. I used the VPN Wizard to configure the Gateway and I installed the Netgear VPN Prosafe client on a Windows 7 computer. I can open the tunnel but I get two issues :
* When the tunnel is open, I can't go on Internet (DNS fails)
* I can't ping any host in the remote LAN, even the VPN gateway.
I made some tests and I found that the client ping packets reach the LAN host I want to ping, the LAN host send its reply to gateway, but gateway doesn't arrive to send packets to the client.
What should I do to solve my problem ?
Thanks for your help.
49 Replies
- jmizoguchiVirtuosoFirewall on each destination pc is not responding
Third party firewall or MS firewall must trust opposite LAN subnet - franck_martin2AspirantI disabled the MS firewall and I retried to ping the LAN host but the problem is not solved, I have the same issue : ping packets can't go from gateway to client.
- franck_martin2AspirantThe LAN host is a Linux PC and it send a reply to the client. So the problem is between the gateway and the Windows 7 client. If the windows 7's firewall is not responsible of the packet loss, who is the troublemaker? A static route?
- jmizoguchiVirtuosoWhat is LAN subnet for both side?
- franck_martin2AspirantThe LAN subnet is the same for the remote LAN and for the client. The remote LAN mask is /25, like the tunnel interface of the client. The mask for the client physical ethernet interface is /24.
- jmizoguchiVirtuosoDetail the IP
- franck_martin2AspirantLANs IP address is 192.168.x.x. I can't tell more.
- jmizoguchiVirtuosoPrivate IP.
hiding is useless - franck_martin2AspirantOK. How can I solve my problem? Can you give me some advices or test to do to help me?
- aditMentorYou can play this game for the next 2 weeks and get no where. Like I said, there are no static routes needed, and post screenshots of the settings.
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!