Recommended Posts

Hi,

 

even though we usually use Cisco VPN clients, I've recently had a weird issue with networking and here it is:

 

- pc (client) on location A needs to connect through VPN to location B. 

- client's local network subnet is 192.168.1.0/24.

- client's external IP is A.B.C.D.

- server local network subnet is same as clients, 192.168.1.0/24.

- server runs VPN server on Microsoft Small Business Server.

- servers external IP is W.X.Y.Z.

 

Connection is successful. However, when trying to access other computers on local network on location B, we found out, because of same subnets, we're still accessing clients networking. 

 

Example (problem):

 

Client > VPN > Server. Success. Client access 192.168.1.10 on server part (should lead to Exchange server). Error. It leads to NAS device (which is on client intranet.

 

Is there any easy workaround for this or is it better to reconfig Work intranet IP's and switch them to 192.168.X.Y?

 

 

Thank you for your help!

Don't have much experience with VPN configuration, but I guess it is probably cleaner over the long-term to reconfigure the IPs?

 

However, I've seen an option before in a VPN software (in my limited VPN experience) that allow you to do a "one-to-one NAT", meaning like you can map all the 192.168.1.X on the server side to 192.168.2.X or something (so to access the server via the VPN, the client would use 192.168.2.0 instead). No idea if that works with the Microsoft Small Business Server VPN though.

Don't have much experience with VPN configuration, but I guess it is probably cleaner over the long-term to reconfigure the IPs?

 

However, I've seen an option before in a VPN software (in my limited VPN experience) that allow you to do a "one-to-one NAT", meaning like you can map all the 192.168.1.X on the server side to 192.168.2.X or something (so to access the server via the VPN, the client would use 192.168.2.0 instead). No idea if that works with the Microsoft Small Business Server VPN though.

 

Are we talking about VPN client or VPN server configuration here? It is more logical that VPN client has this option, not server, so Microsoft Small Business Server hasn't got much to do here.

 

But, if we're talking about VPN client, the classic built-in Microsoft client has an option "Use default gateway on remote network option" which is great, except.. it works only for outbound traffic, local network doesn't :|

Its a common problem with remote vpn connections or site to site vpn setups.. If for example the remote client is 192.168.1.0/24 and the site is he is vpn too is 192.168.1.0/24 your going to have some problems.

or if you have site A 192.168.1.0/24 --- site to site vpn --- Site B 192.168.1.0/24

The best solution is to change one of the locations ip scheme as suggested by sc302. Home users normally have much easier to change their side to say 192.168.27.0/24 so it doesn't fall into the commonly used 192.168.1,2,3.0/24 etc..

If your setting up a business sort of location and will having remote home users, etc. Its good practice to use a bit of oddball local network, say 10.0.82.0/24 or 172.31.0/24,etc..

Worse case depending on the equipment being used, NATs can be put in place - but its more complex and would only suggest you do that if just really not possible to change a locations IP scheme at the current time. But the long term solution would be to make sure all sites in your network use their own unique ip address space that falls in line with your company overall policies.

Other solution that can be done for the remote users that need access to a few machines and the IPs overlap is to create host routes to those specific IPs that push it down the tunnel vs computer just thinking hey 192.168.1.62 is local to my 192.168.1.0/24 network no reason to send that traffic down the tunnel.

But you still can run into issue where the server your talking to says hey 192.168.1.100, depending on the vpn solution used - say if use tap vs tun is trying to talk to me - that is local, no reason to send it back to the gateway to go out the vpn. If remote client gets a vpn IP that is different than every network in use you should be ok with host routes on the remote clients to get to a handful of machines, etc..

In the long run, best solution is to make sure either remote users or remote sites do not have overlapping ip schemes.

This topic is now closed to further replies.
  • Posts

    • I agree with what I think you are saying, just not in the way you are saying it. Like any tool, the amount it represents your work is perorational to the effort you put into it. It is similar to why 2nd grade math students learning to add and subtract are not allowed to use calculators, but a high-school calculous student is. For the 2nd grader, that tool would completely replace the work they are doing, for the calculous student the same tool allows them to work far more effectively while in no way replacing their effort or knowable. If you spend 30 seconds writing a prompt, then the image that comes out is no more "yours" than if you found the same image with a Google Image search. However, many of these generative tools also support highly iterative processes that allow back and forth, and merging generated images with photos or human created images. I am sure you would agree that a human spending hours of time working on a project, even if AI was involved in the process, still reflects that human's work.
    • Windows 11 version 26H2 is now available for testing in the latest preview build by Taras Buria Friday Windows 11 preview builds are here. Insiders in the Experimental (formerly Dev) and Beta Channel can download builds 26300.8697 and 26220.8690. There are no new features, but Microsoft is officially moving the Experimental Channel to version 26H2. In addition, Microsoft is improving the copy dialog in File Explorer, the Start menu reliability, and fixing virtualization issues. Here is the changelog: [General] With today’s build, Windows Insiders in the Experimental channel will see the versioning updated under Settings > System > About (and winver) to version 26H2. For more information, see the Windows Insiders blog. [File Explorer] We’ve improved the visual consistency and reliability of the Copy dialog in Dark mode, including its launch experience and the expanded progress view. [Start menu] - Also available in Beta Improved reliability of Start menu reflecting newly installed or removed apps without requiring sign-out or restart. [Taskbar] Fixed an issue for Insiders using the new smaller taskbar option, where the system tray might get cut off or pushed off screen. [Settings] - Also available in Beta Improved reliability of Settings > Apps > Startup. [Virtualization] - Also available in Beta This update addresses an issue that could result in bugchecks citing HYPERVISOR_ERROR (0x20001) and KMODE_EXCEPTION_NOT_HANDLED (0x1E) errors after installing the latest flights on some devices during system restarts, virtual machine operations, or while running some gaming applications. You can find the official changelog for the Experimental build here and for the Beta build here.
    • I've always preferred this possibility. There is something that feels good about the idea that all matter in the universe will eventually come back together and maybe even result in another big bang. The idea that the universe would fizzle out over the eons and forever drift apart is a little depressing. I realize it is not logical to let a basic human desire for life to have a grand everlasting meaning change the way I feel about a scientific theory, but I am human, so that is how I feel :-).
    • Windoze 11 could finally go to hell, instead of making me savor yet another error I've never had. "Bad Pool Caller" or whatever TF cryptic crap0la message it is. Adding salt to injury, it says something along these lines (on the blank black screen after it hard stops): "Your windoze needs to restart. You can restart." NO WAY SHERLOCK. The PEECEE, look, it's *blocked*, I can do jack sh1t with it as it is and you say that it needs to restart? Further, that I can restart? What am I supposed to do, take a herbal bath? Sudo a sandwich? Timewaster pile of useless slop and errors, coded by monkeys and force-fed on us by a pedo-founded corporation, that's all there is to it. Now, let's have a fun weekend trying to handle the error, which after a quick internet check can basically be due to EVERYTHING, from memory faults to drivers to motherboard issues. Thanks M$.
    • Zen Browser 1.21.3b by Razvan Serea Zen Browser is a privacy-focused, open-source web browser built on Mozilla Firefox, offering users a secure and customizable browsing experience. It emphasizes privacy by blocking trackers, ads, and ensuring your data isn't collected. With Zen Mods, users can enhance their browser experience with various customization options, including features like split views and vertical tabs. The browser is designed for efficiency, providing fast browsing speeds and a lightweight interface. Zen Browser prioritizes user control over the browsing experience, offering a minimal yet powerful alternative to traditional web browsers while keeping your online activity private. Zen Browser’s DRM limitation Zen Browser currently lacks support for DRM-protected content, meaning streaming services like Netflix and HBO Max are inaccessible. This is due to the absence of a Widevine license, which requires significant costs and is financially unfeasible for the developer. Additionally, applying for this license would require Zen to be part of a larger company, similar to Mozilla or Brave. Therefore, DRM-protected media won't be supported in Zen Browser for the foreseeable future. Zen Browser offers features that improve user experience, privacy, and customization: Privacy-Focused: Blocks trackers and minimizes data collection. Automatic Updates: Keeps the browser updated with security patches. Zen Mods: Customizable themes and layouts. Workspaces: Organize tabs into different workspaces. Compact Mode: Maximizes screen space by minimizing UI elements. Zen Glance: Quick website previews. Split Views: View multiple tabs in the same window. Sidebar: Access bookmarks and tools quickly. Vertical Tabs: Manage tabs vertically. Container Tabs: Separate browsing sessions. Fast Profile Switcher: Switch between profiles easily. Tab Folders: Organize tabs into folders. Customizable UI: Personalize browser interface. Security Features: Inherits Firefox’s robust security. Fast Performance: Lightweight and optimized for speed. Zen Mods Customization: Deep customization with mods. Quick Access: Easy access to favorite websites. Open Source: Built on Mozilla Firefox with community collaboration. Community-Driven: Active development and feedback from users. GitHub Repository: Contribute and review the source code. Zen Browser 1.21.3b changelog: New Features Updated to Firefox 152.0.1 Fixes Fixed transparency not working after updating to 1.21.2b (#14259) Fixed frequent crashes affecting users with Intel Raptor Lake processors Fixed an issue on macOS where choosing a PDF option, such as "Save as PDF", from the system print dialog would send the job to your printer instead of saving a file. Other minor bug fixes and improvements. Download: Zen Browser | 90.2 MB (Open Source) Download: Zen Browser ARM64 | Other Operating Systems View: Zen Browser Home Page | Screenshots 1 | 2 | Reddit Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Collaborator
      ryansurfer98 went up a rank
      Collaborator
    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      577
    2. 2
      +Edouard
      190
    3. 3
      Michael Scrip
      77
    4. 4
      PsYcHoKiLLa
      76
    5. 5
      Steven P.
      73
  • Tell a friend

    Love Neowin? Tell a friend!