NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
thxbox1138
Mar 13, 2021Aspirant
Site to Site tunnel working (only ping)
I have 2 BR200 routers and 2 locations I set up site to site IPsec vpn Tunnel is green I can ping IP's from either site back and forth I cannot however map drives to my server from remote site ...
thxbox1138
Mar 15, 2021Aspirant
I am able to ping a machine from HQ to remote
I am able to ping a machine from remote to HQ
I am able to tracert from both locations and its 3 hops
HQ router
Remote router
machine
I just cant do anything else, my question is do I need to create any addtional traffic rules to allow the remote subnet machine to access the HQ network machine on the BC200 router or is that all taken care of once you create the IPSEC tunnel in the BC200's
meaning create the tunnel and done, no post rules or configuration?
I have no firewalls or anything in the way at this moment
MrJoshW
Mar 16, 2021NETGEAR Employee Retired
Hello,
The issue is, on the BR200/500 we have disabled NATloopback due to performance. We do have a firmware that does address the NATloopback and will allow you to connect to the remote resources but please note that there will be a performance hit due to this. Please let me know if you wish to install the firmware for testing and I can send it to you through a private message.
- thxbox1138Mar 16, 2021Aspirant
I guess I have a couple questions
why would you limit a site to site tunnel since the very reason why people setup a site to site tunnel is to connect to the remote resources? and then why would the only way to to connect to the remote resources would be I would have to settle for crappy performance? why cant I have the option to connect to the remote resources and have great performance?
what is the difference between setting up a site to site VPN tunnel like I have and doing it though the insight manager with a VPN group are they the same I was going to keep insight premiere pro if this is the case
honestly if you say the only way to access remote resources from one site to the other is with crappy performance I might rethink your solution all together, who buys site to site tunnel solutions to be able to use just ping? this makes absutely no sense?
- MrJoshWMar 17, 2021NETGEAR Employee Retired
Hello,
Other possible workarounds if you are unable to use the firmware and this should not interfere performance compared to using a lower firmware version with NATloopback fix:
- Configure the clients hosts file to map the domain name to a static local IP of the server.
- Use a separate DNS server that can handle accessing public resources from an internal network.
- thxbox1138Mar 17, 2021Aspirant
take DNS out of the mix I am not able to map drives by IP at all, I think I included that in my first post
If i were to apply firmware you are suggesting I would want to rollback if it did not work would that be possible?
And when you say perfomacne would not be as good can please explain what you mean by that?
also as I was asked prior should I be creating a VPN group within insight manager so these routers can talk to eachother instead of the site to site tunnel I have built locally? what is the difference between the two?
- thxbox1138Mar 28, 2021Aspirant
please send me the link to the 5.9 firmware thanks I opened up a ticket but dont want to sit on the phone for hours to simply get a link, not sure why support does not just handle requests by email and phone (not phone only)
- schumakuMar 28, 2021Guru - Experienced User
Head to https://my.netgear.com/ -> My Support (https://www.netgear.com/mynetgear/portal/mySupport.aspx) ... there you have "chat support" (not live) with Netgear's support organisation.
Not sure where the 5.9 reference does come from, however MrJoshW I would join the trial.
- MrJoshWMar 29, 2021NETGEAR Employee Retired
Hello,
Please send me a private message with your email so that I can forward you the firmware file.
- jj2021Apr 30, 2021Aspirant
I would also like the firmware
- hormy3dAug 18, 2021Aspirant
I have same /problem firmware V5.10.0.5
what can Ido?
- jj2021Aug 19, 2021AspirantThere was an older firmware to downgrade to, which worked for this particular bug, but it's still a junky router. Our best "solution" ended up being the purchase of a FortiGate. The BR200 was our company's first and last Netgear router, and now sits in a cabinet of the junkiest old spare hardware we hope never to be desparate enough to actually re-use. If we hadn't bought it so far in advance that the Amazon return policy expired before we installed it, it would have gone back.
- hormy3dAug 19, 2021Aspirant
hi
Thanks
What firmware I need to downgrade to?
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!