× We are experiencing an outage with Chat Support, Knowledgebase Articles and guided assistance.
× Sept. 1st 12AM to 3AM PT Self-Service Online Portal and Support Phone Lines unavailable for scheduled maintenance.
× NETGEAR Insight 5.5 Now Available
× Tell us your NETGEAR Switch Story and Win $500!

This topic has been marked solved and closed to new posts due to inactivity. We hope you'll join the conversation by posting to an open topic or starting a new one.

NETGEAR ® COMMUNITY
  • Downloads
  • MyNETGEAR
  • Community
  • Support
  • Netgear
  • United States
    • 中国 (汉语)
    • Deutschland (Deutsch)
    • España (Español)
    • France (Français)
    • Italia (Italiano)
    • 日本 (日本語)
    • United States (English)
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • English
  • /
  • NETGEAR Forum
  • /
  • Business Solutions
  • /
  • Firewalls and VPN Routers
  • /
  • Hardware VPN Firewalls and Business Routers
  • /
  • Re: FVS318N VPN Tunnel from Single Endpoint to 2 V...
Log In
Join Now
  • Community Home
  • Community Browser:
  • NETGEAR Website
  • Support
  • Downloads
  • MyNETGEAR
Log In
  • English
  • /
  • NETGEAR Forum
  • /
  • Business Solutions
  • /
  • Firewalls and VPN Routers
  • /
  • Hardware VPN Firewalls and Business Routers
  • /
  • Re: FVS318N VPN Tunnel from Single Endpoint to 2 V...
  • Join Now
  • |
  • Log In
  • |
  • Help
Discussion stats
  • 8 replies
  • ‎2017-02-15 06:07 AM
  • 1883 views
  • 0 kudos
  • 3 in conversation
    • SamirD
    • train_wreck
    • JohnRo
Announcements

Tell us your NETGEAR Switch Story and Win $500!

Insight 5.5 Now Available

What's New @Netgear - #NetgearCES2019 Coverage!

Extend your NETGEAR Business Products Warranties & Support - Learn More

NETGEAR Service Status Page - LIVE

World's First Mesh WiFi System with Amazon Alexa Built-in and Harman Kardon Audio - Orbi Voice

NETGEAR Insight Pro Network Management System enables higher profitability for Resellers

The NEW Nighthawk Pro Gaming Router & Nighthawk Pro Gaming Switch - Power To Win!

Top Contributors
User Count
AirSkeeter
AirSkeeter Initiate
1
Augello
Augello Tutor
1
ComputerMikes
ComputerMikes Guide
1
jcdole
jcdole Tutor
1
See All
Reply
Topic Options
  • Subscribe to RSS Feed
  • Mark Topic as New
  • Mark Topic as Read
  • Float this Topic for Current User
  • Bookmark
  • Subscribe
  • Printer Friendly Page
  • All forum topics
  • Previous Topic
  • Next Topic
SamirD
SamirD Virtuoso
Virtuoso
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2017-02-15 06:07 AM
‎2017-02-15 06:07 AM

FVS318N VPN Tunnel from Single Endpoint to 2 VLANS

I think I know how to do this, but wanted to confirm before attempting to make the configuration changes.

 

I currently have 1 VLAN on the 318N.  This is connected to another VPN router via a site-to-site VPN tunnel.  All works well.

 

I am neededing to add a second VLAN on the 318N.  And I also want this second VLAN to be connected to the same VPN router via site-to-site VPN tunnel.

 

Because the endpoint will be the same, I should be able to use the same IKE policy on the 318N, correct?  And then the only thing I need to do is create a new VPN policy for the new VLAN, right?

 

And on the VPN endpoint it would be the same--reusing the IKE and adding a new VPN policy for the new VLAN?

 

Any assistance appreciated.  I just want to make sure I have the theories right before I get in and start breaking things.

 

 

Solved! Go to Solution.

Model: FVS318N|ProSafe Wireless N 8 port gigabit VPN firewall
Message 1 of 9
Labels:
  • Installation
  • Solutions
  • Troubleshooting
0 Kudos
Reply

Accepted Solutions
train_wreck
train_wreck Luminary
Luminary
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2017-02-26 01:26 AM
‎2017-02-26 01:26 AM

Re: FVS318N VPN Tunnel from Single Endpoint to 2 VLANS

Correct, if what you're doing is looking to add a second subnet to an existing IKE, just add another VPN policy, and select the same IKE policy. I had 4 subnets configured with the same IKE policy from the Netgear to a Cisco ASA5506 with no issues.

 

EDIT surprised at the response delay here , this is a pretty simple VPN configuration. It's just a single phase 1 installation with multiple phase 2s.....

Message 6 of 9
0 Kudos
Reply

All Replies
Highlighted
JohnRo
JohnRo
NETGEAR Employee Retired
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2017-02-16 12:54 PM
‎2017-02-16 12:54 PM

Re: FVS318N VPN Tunnel from Single Endpoint to 2 VLANS

Hello SamirD, 

 

I cannot confirm since I have not tested it myself (Will probably try on a later time). In theory, this setup should work since they have the same endpoint. The IKE policies will be the same for both VLANs however, I'm thinking this would only use one connection at a time. I'll inquire this one just to make sure. 

 

Thanks, 

JohnRo
NETGEAR® Community Team
Message 2 of 9
0 Kudos
Reply
SamirD
SamirD Virtuoso
Virtuoso
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2017-02-16 01:08 PM
‎2017-02-16 01:08 PM

Re: FVS318N VPN Tunnel from Single Endpoint to 2 VLANS

Yikes!  Only one tunnel at a time would be a problem.  Let me know what you find out and what a workaround would be (new IKE policy?).

Message 3 of 9
0 Kudos
Reply
SamirD
SamirD Virtuoso
Virtuoso
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2017-02-21 09:00 PM
‎2017-02-21 09:00 PM

Re: FVS318N VPN Tunnel from Single Endpoint to 2 VLANS

Any news on this?  I have to go live this week and would like to know what I need to do before I have to do it.

Message 4 of 9
0 Kudos
Reply
SamirD
SamirD Virtuoso
Virtuoso
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2017-02-25 08:58 PM
‎2017-02-25 08:58 PM

Re: FVS318N VPN Tunnel from Single Endpoint to 2 VLANS

Still looking for news.  Gotta get this up and running and don't want surprises!

Message 5 of 9
0 Kudos
Reply
train_wreck
train_wreck Luminary
Luminary
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2017-02-26 01:26 AM
‎2017-02-26 01:26 AM

Re: FVS318N VPN Tunnel from Single Endpoint to 2 VLANS

Correct, if what you're doing is looking to add a second subnet to an existing IKE, just add another VPN policy, and select the same IKE policy. I had 4 subnets configured with the same IKE policy from the Netgear to a Cisco ASA5506 with no issues.

 

EDIT surprised at the response delay here , this is a pretty simple VPN configuration. It's just a single phase 1 installation with multiple phase 2s.....

Message 6 of 9
0 Kudos
Reply
SamirD
SamirD Virtuoso
Virtuoso
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2017-02-26 08:43 AM
‎2017-02-26 08:43 AM

Re: FVS318N VPN Tunnel from Single Endpoint to 2 VLANS

Thank you so much for the reply!  Yeah, I didn't think this was too complicated, but definitely didn't want to waste time 'testing' on the day of implementation.

Message 7 of 9
0 Kudos
Reply
SamirD
SamirD Virtuoso
Virtuoso
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2017-03-14 06:34 AM
‎2017-03-14 06:34 AM

Re: FVS318N VPN Tunnel from Single Endpoint to 2 VLANS

So I just ran into a problem with this configuration after my ISP changed my endpoint IPs without telling me. >Smiley Indifferent

 

I am not able to update the endpoint IPs on either of the VPN policies to the new IP.  It gives me the error of 'Can't share IKE policy with different remote/local endpoint'.  I've tried disabling the VPN policies and that doesn't help.  I don't want to delete the policy and have to rebuild it from scratch.  There has to be another way to update this simple bit of information.  Any ideas?

Message 8 of 9
0 Kudos
Reply
SamirD
SamirD Virtuoso
Virtuoso
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2017-03-14 08:23 AM
‎2017-03-14 08:23 AM

Re: FVS318N VPN Tunnel from Single Endpoint to 2 VLANS

Scratch this.  I had the IP off one digit on one of the vpn profiles.  Everything worked fine after it was changed to the correct IP. Smiley Very Happy

Message 9 of 9
0 Kudos
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
Need More Help?
  • Contact Support
  • About Us
  • Investor Relations
  • Contact us
  • Careers
  • Sign Up
  • United States
    • 中国 (汉语)
    • Deutschland (Deutsch)
    • España (Español)
    • France (Français)
    • Italia (Italiano)
    • 日本 (日本語)
    • United States (English)

© 1996-2019 NETGEAR®