Recommended Posts

Hi,

 

even though we usually use Cisco VPN clients, I've recently had a weird issue with networking and here it is:

 

- pc (client) on location A needs to connect through VPN to location B. 

- client's local network subnet is 192.168.1.0/24.

- client's external IP is A.B.C.D.

- server local network subnet is same as clients, 192.168.1.0/24.

- server runs VPN server on Microsoft Small Business Server.

- servers external IP is W.X.Y.Z.

 

Connection is successful. However, when trying to access other computers on local network on location B, we found out, because of same subnets, we're still accessing clients networking. 

 

Example (problem):

 

Client > VPN > Server. Success. Client access 192.168.1.10 on server part (should lead to Exchange server). Error. It leads to NAS device (which is on client intranet.

 

Is there any easy workaround for this or is it better to reconfig Work intranet IP's and switch them to 192.168.X.Y?

 

 

Thank you for your help!

Don't have much experience with VPN configuration, but I guess it is probably cleaner over the long-term to reconfigure the IPs?

 

However, I've seen an option before in a VPN software (in my limited VPN experience) that allow you to do a "one-to-one NAT", meaning like you can map all the 192.168.1.X on the server side to 192.168.2.X or something (so to access the server via the VPN, the client would use 192.168.2.0 instead). No idea if that works with the Microsoft Small Business Server VPN though.

Don't have much experience with VPN configuration, but I guess it is probably cleaner over the long-term to reconfigure the IPs?

 

However, I've seen an option before in a VPN software (in my limited VPN experience) that allow you to do a "one-to-one NAT", meaning like you can map all the 192.168.1.X on the server side to 192.168.2.X or something (so to access the server via the VPN, the client would use 192.168.2.0 instead). No idea if that works with the Microsoft Small Business Server VPN though.

 

Are we talking about VPN client or VPN server configuration here? It is more logical that VPN client has this option, not server, so Microsoft Small Business Server hasn't got much to do here.

 

But, if we're talking about VPN client, the classic built-in Microsoft client has an option "Use default gateway on remote network option" which is great, except.. it works only for outbound traffic, local network doesn't :|

Its a common problem with remote vpn connections or site to site vpn setups.. If for example the remote client is 192.168.1.0/24 and the site is he is vpn too is 192.168.1.0/24 your going to have some problems.

or if you have site A 192.168.1.0/24 --- site to site vpn --- Site B 192.168.1.0/24

The best solution is to change one of the locations ip scheme as suggested by sc302. Home users normally have much easier to change their side to say 192.168.27.0/24 so it doesn't fall into the commonly used 192.168.1,2,3.0/24 etc..

If your setting up a business sort of location and will having remote home users, etc. Its good practice to use a bit of oddball local network, say 10.0.82.0/24 or 172.31.0/24,etc..

Worse case depending on the equipment being used, NATs can be put in place - but its more complex and would only suggest you do that if just really not possible to change a locations IP scheme at the current time. But the long term solution would be to make sure all sites in your network use their own unique ip address space that falls in line with your company overall policies.

Other solution that can be done for the remote users that need access to a few machines and the IPs overlap is to create host routes to those specific IPs that push it down the tunnel vs computer just thinking hey 192.168.1.62 is local to my 192.168.1.0/24 network no reason to send that traffic down the tunnel.

But you still can run into issue where the server your talking to says hey 192.168.1.100, depending on the vpn solution used - say if use tap vs tun is trying to talk to me - that is local, no reason to send it back to the gateway to go out the vpn. If remote client gets a vpn IP that is different than every network in use you should be ok with host routes on the remote clients to get to a handful of machines, etc..

In the long run, best solution is to make sure either remote users or remote sites do not have overlapping ip schemes.

This topic is now closed to further replies.
  • Posts

    • Nothing Ear buds with active noise cancellation are at their lowest price ever with 51% off by Fiza Ali Amazon is currently offering the Nothing Ear wireless earbuds at their lowest price ever with 51% off limited prime deal. The earbuds feature an 11mm dynamic drivers with a ceramic diaphragm, and support high-resolution audio codecs including AAC, SBC, LDAC, and LHDC 5.0. They support active noise cancellation of up to 45dB across a frequency range of up to 5000Hz, and include a smart ANC algorithm, adaptive noise cancellation, and a transparency mode that allows surrounding sounds to be heard when needed. Connectivity is provided via Bluetooth 5.3, with support for multiple profiles including HFP, A2DP, AVRCP, and others. The earbuds also support dual connection, allowing them to be paired with two devices at the same time. Additional features include IP54 water and dust resistance for the earbuds and IP55 for the charging case, in-ear detection, pinch controls, low-latency mode, Google Fast Pair, Microsoft Swift Pair, and a three-microphone system per earbud for clearer voice calls. The Nothing X app, available on Android and iOS, provides access to custom EQ settings, bass enhancement, personal sound profiles, ear tip fit testing, firmware updates, customisable controls, dual-device management, and a find-my-earbuds feature. In terms of battery performance, each earbud has a 46mAh battery and the charging case has a 500mAh capacity. With active noise cancellation (ANC) turned off, the earbuds should offer up to 8.5 hours of playback on a single charge and up to 40.5 hours in total with the charging case. With ANC enabled, playback should last up to 5.2 hours on the earbuds and up to 24 hours with the case. For calls, talk time should reach up to 5 hours on the earbuds and 23 hours with the case when ANC is off, while ANC on should provide up to 4 hours on the earbuds and 18 hours with the case. Finally, fast charging should deliver up to 10 hours of playback from 10 minutes of charging when ANC is disabled. Nothing Ear Wireless Earbuds Bluetooth: $73.15 (Amazon US) - 51% off Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Microsoft officially launched its Copilot Cowork enterprise AI agent on June 16, 2026, switching to usage-based pricing on the same day it disclosed it is considering a Microsoft-hosted version of China's DeepSeek V4 as a lower-cost engine for the platform — a pairing that puts the company on a collision course with both its enterprise customers' security teams and a White House that has spent months trying to wall off Chinese AI from American infrastructure.................... https://www.techtimes.com/articles/318647/20260618/microsoft-eyes-deepseek-v4-copilot-cowork-what-azure-hosting-cannot-fix.htm  
    • Forza Horizon 6 gets another hotfix for one of the game's online modes by Taras Buria Recently, Forza Horizon 6 players discovered an interesting glitch that allowed farming a crazy amount of in-game credits in a few minutes. Playground Games quickly pulled the plug on the exploit by disabling one of the game's online modes, and today, the studio is rolling out another hotfix. In my review, I complained about the game still showering gamers with cars, credits, and wheelspins. As such, earning money in Forza Horizon 6 is not a particularly difficult task. You simply have to play the game, crazy, I know. However, people still found an easier path to becoming a billionaire in Forza Horizon 6. All you had to do was purchase the Hummer EV, install a specific tune, shift in reverse while going at about 15 MPH, hit a wall, and get launched into the stratosphere at the speed of light. While mid-air, launch Eliminator and quickly get eliminated. Boom, the game just awarded you with a few million in-game credits. Initially, Playground Games disabled Eliminator to prevent people from farming credits. Now, following the release of the first balancing update, developers are rolling out a new update that re-enables Eliminator and gives users a free McLaren Sabre as a gesture of goodwill. Here is the changelog: One critical issue remains unpatched, though. There are quite a few reports of the game wiping gamers' saves, and developers are still looking into that. To avoid potential data loss, Playground Games recommends taking one of the steps outlined in a previously published support article.
  • Recent Achievements

    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      591
    2. 2
      +Edouard
      171
    3. 3
      PsYcHoKiLLa
      76
    4. 4
      Michael Scrip
      67
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!