NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
xmaster2002
Jan 03, 2013Aspirant
VPN IPsec work fine but i cant see any other PC
hi ,
my Problem :
I connect my Notebook via VPN IPsec to my Netgear srx5308 !
I use IKE + Policies ( no modeConfig ).
The connecttion work fine but i cant ping any other PC and also it isnt possible to ping the SRX !
WAN1 217.xxx.xxx.xxx
VLan1
192.168.1.0 / 255.255.255.0
- SRX -> 192.168.1.1
VLan 2
192.168.21.0 / 255.255.255.0
- PC1 -> 192.168.21.100
- DS1812 -> 192.168.21.250
VPN-Client SHREW ( and also Netgear Client , same Situation)
- VPN-Client -> 172.xx.xx.2 (vodafone / iphone share )
( Active IPsec SA(s) .. )
( i can chnage it .. to self selcted IP 10.0.10.2 etc. but also no effect )
Why i cant ping any other device !?
any idea ... ?
PS:
more info
SRX - VPN Poilcies
Traffic Selection
192.168.1.1
255.255.255.0
Remote IP : ANY
FQDN : remote.com
my Problem :
I connect my Notebook via VPN IPsec to my Netgear srx5308 !
I use IKE + Policies ( no modeConfig ).
The connecttion work fine but i cant ping any other PC and also it isnt possible to ping the SRX !
WAN1 217.xxx.xxx.xxx
VLan1
192.168.1.0 / 255.255.255.0
- SRX -> 192.168.1.1
VLan 2
192.168.21.0 / 255.255.255.0
- PC1 -> 192.168.21.100
- DS1812 -> 192.168.21.250
VPN-Client SHREW ( and also Netgear Client , same Situation)
- VPN-Client -> 172.xx.xx.2 (vodafone / iphone share )
( Active IPsec SA(s) .. )
( i can chnage it .. to self selcted IP 10.0.10.2 etc. but also no effect )
Why i cant ping any other device !?
any idea ... ?
PS:
more info
SRX - VPN Poilcies
Traffic Selection
192.168.1.1
255.255.255.0
Remote IP : ANY
FQDN : remote.com
43 Replies
- xmaster2002Aspirantyes .. but i try it first with original config ( sug. of Netgear )
i tried it also with other config MC_remote.com etc.
today i tried it with ModeConfig ...
Same result !!
The VPN works 100% fine ... and stable but no connection to other devices ..
no connection to SRX5308 ( ip 192.168.1.1 ) or DIR-855 ( ip 192.168.1.100 )
and also not possible to DS1812 ( ip 192.168.21.250 ) and Server ( 192.168.21.100 )
no PING possible no devices aor folders shown at Explorer !
ahhrrrrr. .... - xmaster2002Aspirantyes .. but i try it first with original config ( sug. of Netgear )
i tried it also with other config MC_remote.com etc.
today i tried it with ModeConfig ...
Same result !!
The VPN works 100% fine ... and stable but no connection to other devices ..
no connection to SRX5308 ( ip 192.168.1.1 ) or DIR-855 ( ip 192.168.1.100 )
and also not possible to DS1812 ( ip 192.168.21.250 ) and Server ( 192.168.21.100 )
no PING possible no devices aor folders shown at Explorer !
ahhrrrrr. .... - jmizoguchiVirtuosoModeconfig muae use IP pool different from LAN subnet
- xmaster2002Aspiranti used ip pool 10.0.10.24 -49
- jmizoguchiVirtuosoif you setup exactly the same as shrew/fvs336G case study other than use IP scheme the should all work
SRX side 192.168.1.x , Modeconfig 10.0.10.24 -49
Remote- make sure 192.168.1.x or 10.0.10.x lan subnet does not exist anywhere
with basic setup above from remote location you should able to access any 192.168.1x.
NOTE> I always put on my case study on first page as well that you did NOT want to use 192.168.1.x, 192.168.0.1, 10.0.0.0 as your primary LAN subnet on main VPN router to prevent conflict.
Also make sure you are using shrew on broadband (DSL , cable, T1, etc) but not mobile for initial testing. Using Cell Data brings additional issues - xmaster2002Aspirantok i understand the cell problem !
but current i have only 2 Lines but from same Provider !
I will try to test again ... today / tomorrow and i will report !
PS:
at other external Networks we i use :
192.168.77.x
192.168.88.x
192.168.99.x
192.168.1.x are 100% unique for this SRX and all over 100% unique at my structure ! - jmizoguchiVirtuosoYou will find using VPN client outside of your network do should consider change it
- xmaster2002Aspiranti try it now from a client on Landline !
same result ! no pings no devices !
ping ping ping ....
Tx KB
1.75
Tx Packetes
16
the only thing i see - jmizoguchiVirtuosoAlso keep changing policy will fail to work
Delete and make new one with new policy name - xmaster2002AspirantSOLVED
SRX5308 no ping after VPN conection to any VLan behind SRX5308
SRX5308 ip 192.168.1.1
VLan 1 : 192.168.1.x
DNS : 192.168.1.1
SubN.: 255.255.255.0
InterLan Routing active
DNS Proxy active
VLan 2 : 192.168.21.x
DNS : 192.168.21.1
SubN.: 255.255.255.0
InterLan Routing active
DNS Proxy active
IKE
agressive
remote.com
local.com
AES-128
SHA-1
SA 28800
no auth.X
Group2
VPN Polic.
192.168.0.0
255.155.0.0
ANY ( remote )
Group2
SA 3600
This work fine !!!
IMPORTANT :
always shut down the SRX5308 ( full shutdown )
after changes !!!!
or in case that totaly nothing work = factory reset and start again !
or use a new firmeware !
That will help !
it work fine with shrew VPN and also netgear client ... current !
we will see its long time sable !
PS:
now .. i can have a look why i can ping and connect the devices but why i cant see and device at Windwos 7 Explorer -> Network overview !
( i think its a problem with the company, home and public network classes from Windows 7 )
I hope it will halp also others !!!
;)
Related Content
- Feb 11, 2016Retired_Member
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!