NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

david42's avatar
david42
Aspirant
Mar 06, 2022

VPN server does not work when Guest Network is enabled

Model: RBR850

 

Problem: Clients connected to the VPN are unable to access devices on the LAN when the Guest WiFi network is enabled.

 

Configuration:

  • LAN IP range: 192.168.1.X (my choice)
  • Guest Network range: 192.168.2.X (router choses)
  • VPN client IP range: 192.168.254.X (router choses)

 

What I suspect is happening:

Because I have the Guest WiFi network configured to provide internet access only, the router puts a firewall rule in blocking access to 192.168.1.X from anything outside 192.168.1.X, therefore the guest network devices cannot reach the LAN devices (which is correct). However, because the VPN clients also get IPs outside of the LAN range, this firewall rule also blocks access from the VPN client devices to the LAN devices (which is incorrect).

 

Scenario A: Guest WiFi Network, no VPN

If I were just using a guest WiFi network, but no VPN server, then the router would be functioning properly, as it would block access from Guest network devices to LAN devices, which is correct.

 

Scenario B: VPN server, not guest WiFi network

If I were just using the VPN server, and not a guest WiFi network, then the router wouldn't have put the firewall rule in place, so everything would be able to access everything, which is correct.

 

The problem ONLY comes because I'm running Scenario A+B, where I have both the VPN server and the Guest WiFi network enabled. It seems like a simple bug in the Netgear Orbi router firmware, just because no one in the "VPN" team talked to the "Guest Network" team. But its a serious problem, in fact a serious fellany, because Netgear Orbi advertises both of these features and does not state anywhere that they will not work at the same time.

 

Has anyone experienced this before? Has anyone investigated further to prove what I suspect is happending?

Better yet does anyone have a solution to this? Or a workaround?

 

The only idea I can think of would require knowing EXACTLY how the orbi picks its guest network range and vpn client range based on the user-defined LAN range. Maybe there is a certain LAN range which causes the orbi to pick a ranges for guest network and VPN which DON'T overlap in the firewall rule?

 

Any suggestions are welcome, because unfortunately both of these features are vital to my network and I'll have to buy a different router if I can't fix this in the medium-long term.

7 Replies