View Full Version : Open VPN
pvcrisp
12-31-2007, 04:20 PM
I know I have been asking a lot of questions lately, but I'm learning as I go. I succeeded in getting remote access to the UT box, so now I can reach the configuration client from home. I also can reach a connection with OpenVPN but that is it.
When OpenVPN connects, it gives me an IP 172.16.16.x, where my home and office are both 192.168.1.x. Also, when I get the connection running, I loe connection to the internet, but instant messenger still works as well as the remote admin if I am connected to that.
My questions are:
1) Why do I lose my internet?
2) How do I access the shared resources via the VPN?
Thanks everyone for their help! I continue to be impressed with Untangle!
You're learning. That's a good thing!
The short answer to your questions are:
1. You lose connection to the internet because you likely changed your 172.16.16.x addresses to ones that match your home/office. The 172 addresses are used to make sure that there is no interference.
2. You need to EXPORT addresses of resources you want to be shared across the VPN.
I'm sending you a link to a long thread, but there's a lot of VPN wizardry in it. It makes good reading when there's no football games on.
http://forums.untangle.com/showthread.php?t=825
There's a test on Friday. The question is whether we'll be testing you, or the other way around. Happy New Year!
pvcrisp
12-31-2007, 04:52 PM
Thank you for the link, I did a search for OpenVPN, but I did not see this one!
pvcrisp
12-31-2007, 05:09 PM
From looking at the other forum, I do not feel I know where to change things, but here are details of my set up:
Untangle is in bridge mode and OpenVPN is configured as a server
Home IP: 192.168.1.x
Work IP: 192.168.1.x
Untangle Server 192.168.1.110
VPN Address Pool: 172.16.16.0
External IP 72.X.X.X
Exported IP is 192.168.1.0 (I want to export the whole thin, at least for now)
server's hostname is NOT set to "Resolves Publicly"
"Allow Untangle Support" is checked in Config -> Support
My firewall is currently passing everything
Does anyone see what could be wrong here?
The problem it looks like is that your internal home network and your internal work network have the same IP addressing scheme. So traffic is routed, but doesn't know which 192.168.1.x network to send it to....
I would suggest changing that around if you can, I think that would fix it.....
pvcrisp
12-31-2007, 05:26 PM
I can do this if it will fix it, but aren't most networks set up as 192.168.1.x? It seems this is fairly common.
Does this mean i need a different addressing scheme at work? If I change my home addressing, then it still wont work anywhere I'm at that has the same 192.168.1.x . Am I following you correctly?
This still doesn't solve the internet issue does it?
amac is right there. Which 192.168.1.x is the right one for you to use? In my IT days, I always made sure that the people used 192.168.1.x at home, because we used 192.168.0.x at work and they were dead in the water if home matched work.
Silver Bullet
12-31-2007, 05:40 PM
I'll have to throw in my "agree" here as well. Connecting both networks with the same addressing scheme is the problem. And it is probably the cause of your loss of internet connectivity upon connection problem as well.
pvcrisp
12-31-2007, 05:40 PM
I can see how that makes sense. But do you know why it stops my internet connection when I am connected?
** edit:
Thanks Silver Bullet! Answered the question same time I asked it!
pvcrisp
12-31-2007, 05:49 PM
Thanks for the info! It might take me some time to do that, but I will certainly try it.
You guys are all extremely friendly and helpful! I will definitely recommend UT to others, for its usefulness and support!
** That was easy! I cannot believe that I got all the remote connections and VPN set up in as little time as I did!!! I'm ecstatic!!!!!!!!!
pvcrisp
12-31-2007, 06:12 PM
Update!
It wasn't as hard as I thought to change the addressing here at home, so I have it set to 2.x just because it was the easiest change. I can now reach certain machines by their IP address, but I still can't map a network drive, I know I saw that in the forums, so I will go look for it now.
Thank you amac, mdh, and Silver Bullet!