Orbi WiFi 7 RBE973
Reply

Netgear Nighthawk x8 R8500 problems with ssh on company VPN

welshRSM
Follower

Netgear Nighthawk x8 R8500 problems with ssh on company VPN

The model is correct in subject, the model i have was not available on the list and i had to select one. Netgear need to update it.

There seem to be others have had similar issues with Netgear routers. I work from home and connect to the company network via a CISCO Anyconnect VPN Mobilty Client (V3.1). This worked fine when i was using the BT Smarthub6 router and previous routers but there are some strange things with the Netgear router.

VPN connects fine and connection does not drop at all. But i had some issues accessing some Linux servers via ssh/putty in that after login, any command issuing a reasoanble amount of data to stdout (ps -ef, ls -l, cat xxx.log) would crash the putty session, some Linux servers i could not even ssh to, which is even stranger. netgear support suggested lowering router MTU to 1300, which still did not fix it. A workaround i found was to set the Linux server to MTU 576 and all was fine after that, so it's related to MTU somehow, but not sure why the netgear should be any different to the BT router. These problems are not related to Windows PC's as i tried ssh from a macbook over VPN and had same problem. I raised it all with Netgear who have escalated, but nothing so far. It's been nearly a week now. I will have to swap out this week if no resolution.

Another issue over VPN is that i cannot access a Mainfarme Hardware Management Console via the web browser, just never connects. I have raised this also with Netgear.  I am unable to change teh MTU of this server, so this is a show stopper. This all very disappointing as i like the speed and features of the Nighthawk, but if i unable to work over VPN it will have to be returned to Amazon and an unfavourable review will have to follow. 

I have latest firmware installed.

Model: D7000|Nighthawk AC1900 VDSL/ADSL Modem Router
Message 1 of 2
TheEther
Guru

Re: Netgear Nighthawk x8 R8500 problems with ssh on company VPN

While the problem may indeed be related to MTU, the router's MTU should generally be left set to a value appropriate for your native Internet connection.  Generally, it should be left at 1500 unless your ISP uses PPPoE, PPPoA, L2TP, etc., in which case it should be lowered to account for the extra headroom required by those protocols.

 

Your VPN software should internally set and use its own MTU after further accounting for extra headroom required for VPN headers (likely to be IPSec, but could be something else, too).

 

At this point, it's hard to provide you with any other meaningful help without more information.  Try looking at your VPN client's logs for clues.  Or ask your company's IT department to help you.  If they are any good, they can troubleshoot it at their end or look at your VPN client's logs.  Since you sound like you might be knowledgable, you could try a ping sweep test to determine if MTU is really a factor.  Use Wireshark to see what's going on at the packet level.  Check the routing table on your computers (i.e. netstat -rn) to determine if the VPN software is installing the correct routes for your company's network.

Message 2 of 2
Top Contributors
Discussion stats
  • 1 reply
  • 2567 views
  • 0 kudos
  • 2 in conversation
Announcements

Orbi WiFi 7