Need access to subnet via safenet vpn client

Posted on 2006-05-13
Last Modified: 2010-04-08
Okay...frustrated again. Here´s the deal.
I need access to subnet (only) via dynamic vpn connection. Might be routing/gateway problem.!

Main-office has one Zywall-router with 1 WAN and inside addr. /24.
The subnet is located on a layer 3 switch/router /24    Subnet= /24
PC´s on net, gateway to and can internet that way.

I need VNC acces to IP, through VPN-client - but can only connect to PC´s

When I connect my laptop inside the LAN, with ip, I succesfully ping 192.168.1.xx and 192.168.41.xx devices.
and VNC ok.

But when I VPN-in via SafenetClient, I can ping all on the net - no answer from   ????
Question by:HHLiisborg
    LVL 1

    Accepted Solution

    I am not an expert in Zywall devices but as you says it sounds more to me like a routing problem
    Q1) when you connect from your local lan, who is your default gateway (DG)? you can check it with ipcofig in win xP

    if your DG is not the internal ip address of your zywall router then someone else is doing the routing job for it, this explains why when you connect from your vpn client the zywall does not knows how to reach the required network. then you will have to add this route on it
    must be something like this
    in order to reach network /24 you have to ask ip address x.y.z.w

    when x.y.z.w is your internal DG.

    Q2) when you connect from vpn, what is your ip and your DG?

    if your firewall is giving you ip address from a network different from the inside your L3/ switch router will do not know how to reach it  so you will have to add a route on it pointing to this network

    in order to reach network a.b.c.d ask  internal zywall ip address

    Author Comment

    Hi red... first of all, the Layer 3 switch was defect :-( Couldn´t add route.
    Second, if you want access to subnets through vpn, you have to specify the hole IP-Range, and not just the local net.

    The VPNnet-policy must be - ....of cause, otherwise there´s no way the vpn can get answer from 41.0 net.

    Anyway..your reply, made me certain of routing-probs. Just needed to confirme. Thanx

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Highfive Gives IT Their Time Back

    Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

    If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
    The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
    Need more eyes on your posted question? Go ahead and follow the quick steps in this video to learn how to Request Attention to your question. *Log into your Experts Exchange account *Find the question you want to Request Attention for *Go to the e…
    Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…

    760 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    12 Experts available now in Live!

    Get 1:1 Help Now