NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
xmaster2002
Jan 03, 2013Aspirant
VPN IPsec work fine but i cant see any other PC
hi ,
my Problem :
I connect my Notebook via VPN IPsec to my Netgear srx5308 !
I use IKE + Policies ( no modeConfig ).
The connecttion work fine but i cant ping any other PC and also it isnt possible to ping the SRX !
WAN1 217.xxx.xxx.xxx
VLan1
192.168.1.0 / 255.255.255.0
- SRX -> 192.168.1.1
VLan 2
192.168.21.0 / 255.255.255.0
- PC1 -> 192.168.21.100
- DS1812 -> 192.168.21.250
VPN-Client SHREW ( and also Netgear Client , same Situation)
- VPN-Client -> 172.xx.xx.2 (vodafone / iphone share )
( Active IPsec SA(s) .. )
( i can chnage it .. to self selcted IP 10.0.10.2 etc. but also no effect )
Why i cant ping any other device !?
any idea ... ?
PS:
more info
SRX - VPN Poilcies
Traffic Selection
192.168.1.1
255.255.255.0
Remote IP : ANY
FQDN : remote.com
my Problem :
I connect my Notebook via VPN IPsec to my Netgear srx5308 !
I use IKE + Policies ( no modeConfig ).
The connecttion work fine but i cant ping any other PC and also it isnt possible to ping the SRX !
WAN1 217.xxx.xxx.xxx
VLan1
192.168.1.0 / 255.255.255.0
- SRX -> 192.168.1.1
VLan 2
192.168.21.0 / 255.255.255.0
- PC1 -> 192.168.21.100
- DS1812 -> 192.168.21.250
VPN-Client SHREW ( and also Netgear Client , same Situation)
- VPN-Client -> 172.xx.xx.2 (vodafone / iphone share )
( Active IPsec SA(s) .. )
( i can chnage it .. to self selcted IP 10.0.10.2 etc. but also no effect )
Why i cant ping any other device !?
any idea ... ?
PS:
more info
SRX - VPN Poilcies
Traffic Selection
192.168.1.1
255.255.255.0
Remote IP : ANY
FQDN : remote.com
43 Replies
- jmizoguchiVirtuosoLAN ,WAN ping feature not need it VPN.
WAN ping will flood the router from any outsiders
Gateway for NAS is point to router? - xmaster2002Aspiranthi ...
any option here to post screeners !?
( plz dont tell me : use Skydrive or things like this ! ;) .. ) - jmizoguchiVirtuosoCommon way to post to use imageshack.us
- xmaster2002Aspirant
- jmizoguchiVirtuosoMode config IP pool can NOT me same as you LAN subnet
- xmaster2002Aspirant?? ModeConfig !?!?
i dont use ModeConfig !
i post IKE Polic. and VPN Polic. ! - jmizoguchiVirtuosoLink showed 12 imageschack
- xmaster2002Aspiranthmm .. i cant see any pic with ModeConfig !!!
i dont use it ! thats why normally it isnt possible that i post a ModeConfig screener !!!
PS:
mayb this helps also
Fri Jan 04 09:39:07 2013 (GMT +0100): [SRX5308] [IKE] INFO: IPsec-SA established: ESP/Tunnel
217.xxx.xx.xxx->109.xxx.xxx.xxx with spi=3320127859(0xc5e52173)
Fri Jan 04 09:39:07 2013 (GMT +0100): [SRX5308] [IKE] INFO: IPsec-SA established: ESP/Tunnel
109.xxx.xxx.xxx->217.xxx.xxx.xxx with spi=226577000(0xd814a68)
Fri Jan 04 09:39:07 2013 (GMT +0100): [SRX5308] [IKE] INFO: No policy found, generating the policy :
172.xxx.xxx.xxx/32[0] 192.168.21.0/24[0] proto=any dir=in
Fri Jan 04 09:39:07 2013 (GMT +0100): [SRX5308] [IKE] INFO: Using IPsec SA configuration:
192.168.21.0/24<->0.0.0.0/0 from remote.com
Fri Jan 04 09:39:07 2013 (GMT +0100): [SRX5308] [IKE] INFO: Responding to new phase 2
negotiation: 217.xxx.xxx.xxx[0]<=>109.xxx.xxx.xxx[0]
Fri Jan 04 09:39:07 2013 (GMT +0100): [SRX5308] [IKE] INFO: Sending Informational Exchange: notify
payload[INITIAL-CONTACT]
Fri Jan 04 09:39:07 2013 (GMT +0100): [SRX5308] [IKE] INFO: ISAKMP-SA established for
217.xxx.xxx.xxx[500]-109.xxx.xxx.xxx[39120] with spi:5fc2131788210d2d:7d8804eeca0e4747
Fri Jan 04 09:39:06 2013 (GMT +0100): [SRX5308] [IKE] INFO: Received unknown Vendor ID
Fri Jan 04 09:39:06 2013 (GMT +0100): [SRX5308] [IKE] INFO: Received unknown Vendor ID
Fri Jan 04 09:39:06 2013 (GMT +0100): [SRX5308] [IKE] INFO: Received unknown Vendor ID
Fri Jan 04 09:39:06 2013 (GMT +0100): [SRX5308] [IKE] INFO: Received Vendor ID: DPD
Fri Jan 04 09:39:06 2013 (GMT +0100): [SRX5308] [IKE] INFO: Received Vendor ID: DPD
Fri Jan 04 09:39:06 2013 (GMT +0100): [SRX5308] [IKE] INFO: Received unknown Vendor ID - jmizoguchiVirtuosoI was on my iPad so possible not showing what you posted.
It will be a whe to use PC but NAS has correct gateway ip?
I'm going to assume that
VPN policy is like
Ex.
Local 192.168.70.0/255.255.255.0
Remote Any - xmaster2002AspirantSee ... The NAS are current not so important !
The most important thing are current that i am able to ping anything ...
First what i want are to ping the SXR 192.168.1.1 ... Than i am happy !
2. Step are to ping the NAS with ip 192.168.21.250
In case that it,must be i can change the ips but normally
I want that the SRX will use the 192.168.1.1
3. Step are to ping the ip 192.168.1.100
Curreny i have a stable VPN connection and all looks good but 0 chancr to reach anything with the VPN !
And i cant finde the,misstake why i am not able to ping the srx i thing normally all are fine for this min. Setup !
I cant understanf it !!!!
Send from my Lumia920
Related Content
- Feb 11, 2016Retired_Member
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!