NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

lgfz71's avatar
lgfz71
Aspirant
Mar 23, 2020
Solved

XR500 OpenVPN Configuration

Hello,

I recently bought a new XR500 (Nighthawk AC3200 died) and I'm trying to configure OpenVPN on it. I'm a bit of a novice when it comes to OpenVPN as I've had no need to configure this until now. However, I'm having some issues with my VPN client unable to see my LAN devices.

Here's an image of my network:
https://imgur.com/a/elPJ2Yp


A written version:
I have an outward facing AT&T router/modem (fiber connection) with IP passthrough (DMZ Plus) disabled. Behind that sits my XR500 which hosts the OpenVPN server. I've configured the OpenVPN server (limited configuration) to allow clients to access LAN devices and internet.

My internal router's subnet is 192.168.1.0/255
OpenVPN assigns IP addresses from the 192.168.2.0/255 subnet.
VPN connections from iOS devices are always successful but I cannot see any other LAN device aside from my Synology NAS via a browser at 192.168.1.8:5000. I would assume this is a limitation on iOS from the research I have done. The goal here is to be able to use my iPad to a connect to my home network and access my local computers.

 

Here's the ovpn file my iOS devices use:

client
dev tun
proto udp
remote xxx.mynetgear.com  12973
resolv-retry infinite
nobind
persist-key
persist-tun
<ca>
...
</ca>
<cert>
...
</cert>
<key>
...
</key>
cipher AES-128-CBC
comp-lzo
verb 5


Is there any additional configuration options I need to apply to be able to see my other LAN devices? I've already attempted to enable IP passthrough on my AT&T router and place my XR500 in the DMZ Plus. This seems to cause additional non-related issues such as SSH broken pipes.

Perhaps someone has achieved this desired configuration with a similar network setup.


Thanks in advance.

  • Solution:

     

    I managed to get this finally working with VNC instead of RDP.

     

    Setup:

    - Screens installed on iOS device

    - OpenVPN Server installed on Synology (I believe this should also work for my router's OpenVPN Server, untested)

    - Manual configuration required to connect to LAN device using IP Address instead of host name defined my computer

    - Success

     

9 Replies

  • I notice on the diagram that you want to set up the XR500 with OpenVPN. The XR500 has two OpenVPN related features, so i'm wondering if you are referring to Hybrid-VPN (an OpenVPN client for your whole network) or the Netgear VPN feature (an OpenVPN server hosted on your router)

    • lgfz71's avatar
      lgfz71
      Aspirant

      I have setup the OpenVPN Server. Settings -> Advanced Settings -> VPN Service. I'll also note that perhaps the reason I can access my Synology while connected to VPN is because it is a hardwired connection to my router. My other LAN devices are wireless.

       

      Alternatively, I have also tried to setup OpenVPN on my Synology which has yielded the same results.

      • Netduma-Fraser's avatar
        Netduma-Fraser
        NetDuma Partner
        I'm a bit confused on why you need this feature, perhaps I'm not understanding correctly but the VPN service is for accessing your home network remotely i.e. when you're not at home, not for accessing your home network when you're already home which it sounds like what you're doing?

        If you are attempting to access it remotely anyway then you need to do so using your public IP address but as it seems your AT&T modem/router is running in router mode without a passthrough such as modem/bridge or DMZ enabled then you wouldn't be able to access it anyway.