Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Site to Site VPN using RV082

Posted on 2010-09-05
4
Medium Priority
?
1,009 Views
Last Modified: 2012-05-10
Hello Experts Exchange Community

I submitted this question to the Cisco small business forum with no response at all.  I should have started here in the first place

I currently have an Linksys RV082 and RV042 setup for site to site VPN.  Everything seems to be working perfectly...except for one thing.  I cant communicate with anything that isnt using the RV082 as a gateway.  At the remote site that is using the RV042 I can ping and access files at the site hosting the RV082.  But only if those PC's or servers are using the RV082 as a gateway.  I have an exchange server, terminal server, and a web server that all go through a Adtran T1 router.  They use the Adtran as their default gateway.  I can not ping these servers from the RV042 side.  What do I need to do to be able to communicate with these servers from the RV042.  Any help would be greatly appreciated.  Please let me know if anyone needs more information on the network setup.

Attached is an image of an example of what the network looks like.  
CFT-VPN.jpg
0
Comment
Question by:CFT-TN
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 24

Accepted Solution

by:
rfc1180 earned 2000 total points
ID: 33607543
> have an exchange server, terminal server, and a web server that all go through a Adtran T1 router.  They use the Adtran as their default gateway.

You will need to add static routes on those servers

route -p add 172.16.10.0 mask 255.255.255.0 10.0.0.18 metric 1

Or preferably, you will need to move the adtran to a difference subnet and move layer 3 to the RV082 (if it has support for additional layer 3 interfaces

Billy
0
 
LVL 63

Expert Comment

by:SysExpert
ID: 33613103
Or alternatively add a route on the RV082 for traffic to those machines should go through the Adtran as a gateway.

0
 
LVL 24

Assisted Solution

by:rfc1180
rfc1180 earned 2000 total points
ID: 33613197
>Or alternatively add a route on the RV082 for traffic to those machines should go through the Adtran as a gateway.

You mean the other way around correct? The issue the author is having is the servers that are using the adtran as a gateway; add a route for 172.16.10.0 via 10.0.0.18 on the adtran. The only problem is that there is a potential issue of TCP half open sessions, so if there are any stateful inspections (SYN check, etc) then the packets could ultimately be dropped (Also, this is a sub-optimal configuration (As with static routes on the hosts; ideally you want the adtran directly connected to the RV082 as an additional subnet); this is more for traffic that was originated from 172.16.10.0 destined to any of the servers that are using the adtran is the gateway 10.0.0.18. A SYN packet that was sourced from 172.16.10.18 destined to 10.0.0.15 would reach 10.0.015 last hop being 10.0.0.18 and never traversing the adran; the problem would be the SYN-ACK traffic would traverse the adtran and if there is any stateful inspections of traffic, the SYN-ACK could potentially be dropped as it own no session recorded for an initial SYN.

Billy
0
 

Author Comment

by:CFT-TN
ID: 33649254
hey everyone.  I just got back from vacation and will try out everyones suggestions.  I will keep you posted.  Thanks for the comments.  This should get me in the right direction
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question