Recommended Posts

Hi all,

I've create a new incoming connection which allows a friend to connect to my pc by using the new VPN connection from his side. He can log in just fine and it shows he's connected on my side. Next step: How on earth do I get filesharing working over this connection?

Many thanks,

Alex

Link to comment
https://www.neowin.net/forum/topic/1023508-filesharing-over-windows-vpn/
Share on other sites

Hi all,

I've create a new incoming connection which allows a friend to connect to my pc by using the new VPN connection from his side. He can log in just fine and it shows he's connected on my side. Next step: How on earth do I get filesharing working over this connection?

Many thanks,

Alex

What O/S either side?

You would do file sharing the same way you would if he was local on your network. A VPN is just a connection into your network. Not you might have some issues with name resolution, and are you wanting to allow him to access shares on other boxes on your network?

And you could have issues with same network on both ends, what is his local network compared to yours, ie if your both say on a 192.168.1.0/24 then you could have problems.

EDIT: NO you do not need to do anything with homegroups, and I would not suggest that at all!

We are both indeed setup on 192.168.0.1 etc. He seems to have been assigned the IP 192.168.0.8 on my network but he still can't see any of my shared items appear in his network places. Should he theoretically just be able to type in \\computer-name and access it? I also ensured we were both on the same workgroup incase that was an issue.

your going to want to change one of your networks for starters.. Because he has an interface on the 192.168.0.0/24 network - so why should traffic go down the tunnel to talk to something on 192.168.0.0/24??

And yes in theory you can do \\computername -- but how is he going to resolve that, do you have wins running? It can broadcast for it, but normally broadcasts do not go down a vpn tunnel. So no you would not be able to resolve it.

What I would suggest is have him change his network to say 192.168.1.0/24 vs the 192.168.0.0/24 -- and then have him ping your boxes IP once he gets logged into your vpn. Then he could try \\ipaddress of your machine to access shares.

So for example I am connected to my home network currently via openvpn

Windows IP Configuration

Ethernet adapter Local:

Connection-specific DNS Suffix . : snipped

IP Address. . . . . . . . . . . . : 10.56.41.89

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 10.56.41.1

Ethernet adapter Wireless:

Media State . . . . . . . . . . . : Media disconnected

Ethernet adapter ovpn:

Connection-specific DNS Suffix . :

IP Address. . . . . . . . . . . . : 10.0.200.6

Subnet Mask . . . . . . . . . . . : 255.255.255.252

Default Gateway . . . . . . . . . :

See that 10.0.200.6 -- that is my IP for the vpn tunnel

then look at my route table

Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0       10.56.41.1     10.56.41.89       10
       10.0.200.1  255.255.255.255       10.0.200.5      10.0.200.6       1
       10.0.200.4  255.255.255.252       10.0.200.6      10.0.200.6       30
       10.0.200.6  255.255.255.255        127.0.0.1       127.0.0.1       30
       10.56.41.0    255.255.255.0      10.56.41.89     10.56.41.89       10
      10.56.41.89  255.255.255.255        127.0.0.1       127.0.0.1       10
   10.255.255.255  255.255.255.255       10.0.200.6      10.0.200.6       30
   10.255.255.255  255.255.255.255      10.56.41.89     10.56.41.89       10
        127.0.0.0        255.0.0.0        127.0.0.1       127.0.0.1       1
      192.168.1.0    255.255.255.0       10.0.200.5      10.0.200.6       1
        224.0.0.0        240.0.0.0       10.0.200.6      10.0.200.6       30
        224.0.0.0        240.0.0.0      10.56.41.89     10.56.41.89       10
  255.255.255.255  255.255.255.255       10.0.200.6               8       1
  255.255.255.255  255.255.255.255       10.0.200.6               6       1
  255.255.255.255  255.255.255.255       10.0.200.6               7       1
  255.255.255.255  255.255.255.255       10.0.200.6               4       1
  255.255.255.255  255.255.255.255       10.0.200.6      10.0.200.6       1
  255.255.255.255  255.255.255.255       10.0.200.6               2       1
  255.255.255.255  255.255.255.255      10.56.41.89     10.56.41.89       1
Default Gateway:        10.56.41.1

Notice the route to the 192.168.1.0/24 network, says to use the 10.0.200 connection.

now see I can ping a box on my home network, but notice name resolution for its name quad-w7 fails for net view, but works with IP

D:\>ping 192.168.1.100

Pinging 192.168.1.100 with 32 bytes of data:

Reply from 192.168.1.100: bytes=32 time=141ms TTL=63
Reply from 192.168.1.100: bytes=32 time=134ms TTL=63
Reply from 192.168.1.100: bytes=32 time=138ms TTL=63
Reply from 192.168.1.100: bytes=32 time=136ms TTL=63

Ping statistics for 192.168.1.100:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 134ms, Maximum = 141ms, Average = 137ms

D:\>tracert 192.168.1.100

Tracing route to quad-w7.local.lan [192.168.1.100]
over a maximum of 30 hops:

  1   162 ms   160 ms   189 ms  10.0.200.1
  2   185 ms   177 ms   201 ms  quad-w7.local.lan [192.168.1.100]

Trace complete.

D:\>net view \\quad-w7
System error 53 has occurred.

The network path was not found.

D:\>net view \\192.168.1.100
Shared resources at \\192.168.1.100

Share name  Type   Used as  Comment
-------------------------------------------------------------------------------
HPDeskjet   Print           HP Deskjet 6500 Series
pchshare    Disk
The command completed successfully.

Or I can use dns, because I have that setup

D:\>net view \\quad-w7.local.lan
Shared resources at \\quad-w7.local.lan

Share name  Type   Used as  Comment
-------------------------------------------------------------------------------
HPDeskjet   Print           HP Deskjet 6500 Series
pchshare    Disk
The command completed successfully.

See where dns is setup to talk to my home dns

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : TAP-Win32 Adapter V9

Physical Address. . . . . . . . . : 00-FF-79-1A-85-63

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

IP Address. . . . . . . . . . . . : 10.0.200.6

Subnet Mask . . . . . . . . . . . : 255.255.255.252

Default Gateway . . . . . . . . . :

DHCP Server . . . . . . . . . . . : 10.0.200.5

DNS Servers . . . . . . . . . . . : 192.168.1.253

Lease Obtained. . . . . . . . . . : Tuesday, September 06, 2011 10:10:15 AM

Lease Expires . . . . . . . . . . : Wednesday, September 05, 2012 10:10:15 AM

File sharing works just fine over a vpn connection, once you understand how it works and some of the limitations, etc.

Thanks budman. Okay I can now access his files after changing the addresses but he can't access mine. He also can't seem to access the internet whilst connected to my VPN!

I can access his pc by typing \\192.168.0.8 but if he types my network IP (192.168.1.2) he cannot.

on your vpn settings did you allow for access to other machines on your network, or just the vpn machine. Also your prob not going to want to connect through your network for internet from his network, so you would want to turn off default gateway on the vpn setting.

I believe its here to allow him full access when you create the incoming

post-14624-0-13947600-1315341529.jpg

Then on his vpn connection, he is most likely going to want to uncheck using your connection as his default gateway (internet)

post-14624-0-68228300-1315341568.jpg

As to file sharing for him and pinging your network.. Your firewalls would have to be setup to allow access - so that could be a problem?

Can he ping you? What is the output of his route print when he is connected to you.

Thanks for all your help budman! I'll report back tomorrow when we've tried this as my partner in crime has had to slip off.

Actually, one more query whilst I get the opportunity. I assume that once we've got this set up we'll be able to access each others computers, but the his files a broadly shared through his internal network. If I wanted to access more of his network computers we'd need to set up a router to router VPN?

yeah your computer should be able to talk to his, and his should be able to talk to computers on your network. But sure if you want full network to network access it would be better to do via routers.

Hello,

I am the other half in this attempt at trying to bridge our networks from both our houses... Given Up using a Client based software becuase lets be honest we know windows can do this...

This is making me feel like an idiot...

I be honest i dont understand fully your route table above..

We have:

- Made incomming and outgoing connections on the respective computers.

- The computer with the incomming connection has: The Tickbox enabled for Sharing Network

- The Outgoing computer: The tickboxes for the Default Gateway has been removed.

At this time we have solved the rerouted internet issue..

We have Changed our Network IP's so that they are not the same.

He can access my PC and other computers and NAS on my Network.

1/ I cant see or access him, is a VPN only one way?

2/ post-412302-0-01464200-1315567774.jpg

The attachment above is my system try - This all seems to be working at his end but i get a big ugly Red X. - I am connected to the internet and can access my own network

What we have worked out that on my local network i am (192.168.0.2)

and when the VPN is connected i am also 192.168.0.24

The outgoing pc is 192.168.0.23 - but i cant access that...(on the outgoing pc it shows itself as 192.168.0.23

post-412302-0-37312800-1315568388.jpg

Any ideas, going out of my mind...

From that you're both still on the 192.160.0.1/24 which won't work, as you're seeing. If he is 192.168.0.1/24 change your ip range to 192.168.1.1/24 - which budman suggested...

What I would suggest is have him change his network to say 192.168.1.0/24 vs the 192.168.0.0/24 -- and then have him ping your boxes IP once he gets logged into your vpn. Then he could try \\ipaddress of your machine to access shares.

From that you're both still on the 192.160.0.1/24 which won't work, as you're seeing. If he is 192.168.0.1/24 change your ip range to 192.168.1.1/24 - which budman suggested...

[/color]

My network IP range from my router is set to dish out 192.168.1.X whereas his is set to dish out 192.168.0.X so we've done this unless I am misunderstanding.

It's the Server side of the VPN that is giving my the IP address 192.168.0.23 (according to ipconfig).

post-33944-0-68571100-1315570733.png

Could this even be a firewall issue?

that shows your ip as being 192.168.0.x not .1.x

Unless you're getting confused with the command prompt names as the we're both called Alex! (Users\Alex in cmd prompt title)

It's showing me IP as 0.x on his network and 1.x on my local network. Is that not the IP that his network has just assigned me?

Okay we've somehow managed to make this work by putting a HOST and CLIENT connection on both machines. I didn't think this would be necessary. It appears that we couldn't achieve a single two-way connection (which is what we would like) but we can achieve two one-way connections!

EDIT: OOPS I LIED! Apparently we can only have one connection running at a time rather than two simultaneously as initially thought. i.e. he can access my side but I cannot access his, or vice versa on the respective machines. This solution is not ideal as we were expecting two-way access.

For you to share access both ways your going to need to setup a site to site vpn on your routers. Your box server (host) has no router to the 192.168.1.0/24 network (client side) You could try adding it by hand, but I don't think his box will act as actual gateway.

The incoming built in vpn is more of a road warrior setup, I do not believe it was ever meant to go both ways. Or that for the client connecting to it.

What routers do you have? And you can setup a site to site. Or I seem someone is running hamachi -- do believe you could use that for your site to site setup.

Site to site with machines on each network is a pain because no other boxes on the other networks will have routes for those other networks, which is why its better to do on the router, because all the clients on each network use that as their gateway anyway and talk to the router whenever they want to go to any network other than local, be it neowin.net or some other private network -- if the routers have connections between them then they will both route the traffic to the other networks.

Ah right I see, so in essentially we've been successful based on the limitations of the inbuilt windows vpn. We both have a 'BT Homehub 3' router which works fine but is fairly limited in functionality. Have been considering getting a dd-wrt buffalo router but will have to do more research into that.

We also did try hamachi but that would only allow me to access each machine hamachi was installed on and would not just give me full access to his network, unless we could somehow bridge them together. Reason I'd need full access would be due to filestorage his end on a Netgear ReadyNas Duo and there is not hamachi addon for that device.

hamachi can be used as full blown site to site if you want.

http://community.spiceworks.com/how_to/show/2299

All you need is devices that can get to each others network, and then the correct routing between them. Must easier if done at the gateway, but can be done on boxes inside - just need to let your other boxes know how to get to that network, can be done on your router if yours supports adding routes. If not you would have to put the routes on each box you wanted to be able to get to the other network, be it as a server or a client.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Build your own business with a Sellful lifetime plan now at 76% off by Steven Parker Today's deal from our Apps + Software section of the Neowin Deals store, lets you save 76% off Sellful: ERP Agency Plan lifetime deal. AI-Powered Software and Website Builder for Agencies Ever feel like a client’s needs simply can’t be met on a single platform? With Sellful, it’s all here, and all white labeled. Build anything from simple websites to complex workflows to automate your business in a few clicks. Manage everything from email & social media marketing, to payroll & invoicing. It’s got a white label website builder, online shop, CRM, ERP, marketing, memberships, invoicing, appointments, online courses, project manager, and point of sale functions. Sellful is the only white label platform in the world that is truly all in one, combining all aspects of your business in one place no matter the industry. What can you do with Sellful? Automatically generate amazing websites, funnels, & landing pages in seconds using AI Sell physical & digital products online Keep track of customers with native CRM Automate communication & outreach using AI Manage all aspects of your business in one place Collect emails & phone numbers via forms on your website, then send newsletters to customers with important updates, sales, and discounts Build membership programs with various levels of access for your customers Receive payments from your clients using any number of payment gateways including Paypal, Stripe, Authorize.net, Square & more Have your clients book appointments for services & meetings quickly Build powerful & robust online courses to sell to or instruct people Build communities on Sellful social networking sites with activity feeds, private messaging, & groups See & adjust a visual version of everything going on within your client projects Sync your online shop’s inventory with multiple offline store locations & registers Manage inventory, coupons, & sales through Sellful’s native POS app on your computer Manage employee recruitment, time clocks, payroll & leave requests Automate help desk tasks such as support ticket creation Communicate with your team on multiple chat channels Keep an accounting of your income & expenses Automate billing & website creation for your marketing agency What's in the ERP Agency Plan: White Label Unlimited 10 Sites/Sub Accounts Included 100% White Label For Your Brand Or Your Client's Brand Website Builder Sales Funnel Builder Online Shop Automation Builder CRM & Pipeline Management Email Marketing SMS Marketing Reputation Management 2 Way Communication (Email, SMS & Phone) Appointment Scheduler Memberships Subscriptions Forms, Surveys & Polls Client Portal AI Assistant & Chatbot Social Media Automation Legally Binding Contract Signing Project Management System Online Courses (LMS) Invoicing External CRM Connect Class Attendance & Event Booking Restaurant Builder Support Ticket System Team Chat AliExpress Drop Shipping Accounting Advanced Affiliate Program Community Builder Point Of Sale HR Suite (HR, Time Clock, Payroll & ATS) 5000+ App Integrations 20+ Payment Gateways (No Fees From Us) Custom Mobile App Agency Billing System Setup Wizard Builder Content Cloner Tool Digital Marketing Courses Actionable Marketing PDF Guides Unlimited Contacts Per Site/Sub Account Unlimited Pages Per Site/Sub Account Unlimited Blog Posts Per Site/Sub Account Unlimited Users Per Site/Sub Account Unlimited Products Per Site/Sub Account Unlimited Visitors Per Site/Sub Account 100 Gigs Of File Storage 50,000 Free Email Sends* Unlimited Domain Names Per Site/Sub Account *Email sending can be purchased in packs of 10,000 for $10/Month. You can also add your own external sending service to send without limits. Email sends are shared in a pool throughout all websites and email addresses on the account. System emails are always free. Good to know Length of access: lifetime Redemption deadline: redeem your code within 30 days of purchase Updates included Sellful: ERP Agency Plan (Lifetime) normally costs $1,497 but it can be yours for only $349.97, that's a saving of $1,147.03 (76%) off! For terms, and more details click the link below. Get a lifetime plan to Sellful at 76% off (was $1,497) Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • No its not, there are ton of Youtube videos to get you started, what do you think people did before AI existed?
    • Read this in Humor Simpson 's voice, "Out of my way Moe".
    • You still can, its just under the Transform flyout for WordArt now
  • Recent Achievements

    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
    • First Post
      DrWankel earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      506
    2. 2
      +Edouard
      181
    3. 3
      PsYcHoKiLLa
      86
    4. 4
      Michael Scrip
      78
    5. 5
      Steven P.
      76
  • Tell a friend

    Love Neowin? Tell a friend!