Results 1 to 7 of 7
  1. #1
    Master Untangler
    Join Date
    Oct 2007
    Posts
    247

    Default Can't access web when enabling site to site VPN

    Hello

    I can't access to server site web console when site to site VPN enabled.

    Thanks !

  2. #2
    Master Untangler
    Join Date
    Oct 2007
    Posts
    247

    Default

    I just checked VPN site can ping VPN server internal IP address, but cannot access any of them, firewall already selected pass action.

    If I use Client to VPN server that client can access VPN server internal IP address like file server, DNS, VPN server web console.

    1. Two method is using same Address Pools.

    2. VPN site Network Address is one of the usable within VPN site subnet.

    Thanks !
    Last edited by leiw; 02-20-2010 at 08:12 AM.

  3. #3
    Master Untangler
    Join Date
    Oct 2007
    Posts
    247

    Default

    Here is the information:

    Server site:
    Internal subnet: 172.16.0.0 / 23
    Exiternal IP: 210.0.x.x (static IP)
    Internal IP: 172.16.0.1 / 23

    VPN site:
    Internal subnet: 10.0.0.0 / 24
    Exiternal IP: Dynamic IP
    Internal IP: 10.0.0.254 / 24
    Address Pool: site01
    Network Address: 10.0.0.253

    Client:
    IP Address: 172.18.0.0 / 24 (site01)
    Virtual Address: 172.18.0.5

    Now site to site and client to site are working, but Server site can't access network resource of VPN site:

    Client 172.16.0.5 > Server site 172.16.0.x (can)

    Server site 172.16.0.x > Client 172.16.0.5 (can)

    VPN site 10.0.0.x > Server site 172.16.0.x (can)

    Server site 172.16.0.x > VPN site 10.0.0.x (can't)

    The Exported Hosts and Networks already have 172.16.0.1 / 23. I had add 10.0.0.254 / 24 or 10.0.0.0 / 24 or to Exported Hosts and Networks:

    If use 10.0.0.254 / 24 that 172.16.0.x cam ping to 10.0.0.x, but can't acces network resource.

    If use 10.0.0.0 / 24 that 172.16.0.x cam ping to 10.0.0.x, but can't acces network resource.

    Thanks !
    Last edited by leiw; 02-21-2010 at 07:00 AM.

  4. #4
    Master Untangler
    Join Date
    Oct 2007
    Posts
    247

    Default

    Could someone can help?

    Thanks !

  5. #5
    SMR
    SMR is offline
    Master Untangler SMR's Avatar
    Join Date
    Feb 2010
    Location
    Iowa, United States
    Posts
    205

    Default

    Did you try https://internaladdressofuntanglebox ?? (note: httpS)...
    Sam Reeves
    Disclaimer: I know nothing.. There, that should satisfy any doubt you had!
    "on the outside, I was an honest man, straight as an arrow. I had to come to prison to be a crook." - Shawshank Redemption (1994 film - Andy Dufresne)

  6. #6
    Master Untangler
    Join Date
    Oct 2007
    Posts
    247

    Default

    Quote Originally Posted by SMR View Post
    Did you try https://internaladdressofuntanglebox ?? (note: httpS)...
    It work .... why?

  7. #7
    Master Untangler
    Join Date
    Oct 2007
    Posts
    247

    Default

    Now Server site can access to Remote site resource without to add 10.0.0.254 / 24 in Exported.

    Thanks !

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2