NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
xmaster2002
Jan 03, 2013Aspirant
VPN IPsec work fine but i cant see any other PC
hi ,
my Problem :
I connect my Notebook via VPN IPsec to my Netgear srx5308 !
I use IKE + Policies ( no modeConfig ).
The connecttion work fine but i cant ping any other PC and also it isnt possible to ping the SRX !
WAN1 217.xxx.xxx.xxx
VLan1
192.168.1.0 / 255.255.255.0
- SRX -> 192.168.1.1
VLan 2
192.168.21.0 / 255.255.255.0
- PC1 -> 192.168.21.100
- DS1812 -> 192.168.21.250
VPN-Client SHREW ( and also Netgear Client , same Situation)
- VPN-Client -> 172.xx.xx.2 (vodafone / iphone share )
( Active IPsec SA(s) .. )
( i can chnage it .. to self selcted IP 10.0.10.2 etc. but also no effect )
Why i cant ping any other device !?
any idea ... ?
PS:
more info
SRX - VPN Poilcies
Traffic Selection
192.168.1.1
255.255.255.0
Remote IP : ANY
FQDN : remote.com
my Problem :
I connect my Notebook via VPN IPsec to my Netgear srx5308 !
I use IKE + Policies ( no modeConfig ).
The connecttion work fine but i cant ping any other PC and also it isnt possible to ping the SRX !
WAN1 217.xxx.xxx.xxx
VLan1
192.168.1.0 / 255.255.255.0
- SRX -> 192.168.1.1
VLan 2
192.168.21.0 / 255.255.255.0
- PC1 -> 192.168.21.100
- DS1812 -> 192.168.21.250
VPN-Client SHREW ( and also Netgear Client , same Situation)
- VPN-Client -> 172.xx.xx.2 (vodafone / iphone share )
( Active IPsec SA(s) .. )
( i can chnage it .. to self selcted IP 10.0.10.2 etc. but also no effect )
Why i cant ping any other device !?
any idea ... ?
PS:
more info
SRX - VPN Poilcies
Traffic Selection
192.168.1.1
255.255.255.0
Remote IP : ANY
FQDN : remote.com
43 Replies
- jmizoguchiVirtuosoAhh... I couldn't see well earlier .... I'm on pc now probably some to do with your DNS. looks like you are using own DNS server Got to many of LAN DHCP SERVCER screenshot. you only need the one actually you are using confusing :)
- jmizoguchiVirtuosoMake network digaram I see router's IP is 192.168.21x and 192.168.100x so not sure 192.168.1.1 I seen as DNS server under DHCP setup
- xmaster2002AspirantSee ... The NAS are current not so important !
The most important thing are current that i am able to ping anything ...
First what i want are to ping the SXR 192.168.1.1 ... Than i am happy !
2. Step are to ping the NAS with ip 192.168.21.250
In case that it,must be i can change the ips but normally
I want that the SRX will use the 192.168.1.1
3. Step are to ping the ip 192.168.1.100
Curreny i have a stable VPN connection and all looks good but 0 chancr to reach anything with the VPN !
And i cant finde the,misstake why i am not able to ping the srx i thing normally all are fine for this min. Setup !
I cant understanf it !!!!
Send from my Lumia920 - xmaster2002AspirantOk ...
SRX are the DHCP for
Vlan 192.168.1.0
And
Vlan 192.168.21.0
The SRX use the ip 192.168.1.1
Also at the same Vlan are a DIR-855 with 192.168.1.100
( whats behind the DIR-855 are not intresst )
At the 2. Vlan are
A Server with ip 192.168.21.100
And the Synology DS1812 with ip 192.168.21.250
Thats more or less the topology ....
If i want that a special Server are availble to the VPN useres or public i bring him into the network 192.168.21.0
The DNS entries are only given by me ..,i dont config. A special one ! - jmizoguchiVirtuosoBoth end with 192.168.21x will not tunnel each other
- xmaster2002AspirantOk you mean : i cant reach 192.168.21.x
But why i cant reach 192.168.1.0 !? - jmizoguchiVirtuosoI saw both end has 192.168.21x in each side so you can not reach 192.168.21. From each side to other side of 192.168.21.x
All tunnel must have different lan subnet
Ex.
A-192.168.1.x, 192.168.21.x
B-192.168.2.x, 192.168.22.x
You now create multiple VPN rules to communicate however you want - xmaster2002AspirantOk !
And if i forget now 192.168.21.x
( we ignore this now totally )
( i can understand that 21.x creat me a problem and will need more config )
But why 192.168.1.x dosent work !?
Normally it should work ! Or i am totaly wrong and stupid ! ??
If i only want to reach via VPN
192.168.1.x
Why this dosent work !? - jmizoguchiVirtuosoThat should work fine between ex. 192.168.1.x (site a) and 192.168.2.x (site b)
- aditMentorDon't use remote.com and local.com in your setup. They are routable and not controlled by you. Use what is in the tutorial.
Related Content
- Feb 11, 2016Retired_Member
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!