Solved

create a vpn connections when both sides have same network addressing

Posted on 2010-11-08
18
476 Views
Last Modified: 2012-05-10
I have to create a VPN between 2 sites but they both have the same internal ip scheme of 192.169.0XX
I believe I have to do NAT but I need step by step instuructions on how to do this.
Thanks
0
Comment
Question by:kcassone
  • 5
  • 3
  • 3
  • +3
18 Comments
 
LVL 23

Expert Comment

by:jakethecatuk
Comment Utility
if they are on the same IP address range, then you will really struggle.

if you have a device at each location with an IP of 192.168.0.1 how will the VPN tunnel know which device you want?

don't think you're going to be able to solve this one without changing the range of one site.
0
 

Author Comment

by:kcassone
Comment Utility
There must be way to do this!
0
 
LVL 23

Expert Comment

by:jakethecatuk
Comment Utility
a lot will depend on what you are using to establish the VPN link.

what hardware do you have?
0
 
LVL 15

Expert Comment

by:JBond2010
Comment Utility
This is not the best to do it. Why not change the ip schema on either site? Technically this could prove very cumbersome. When PCs are sending and receiving packets your router performs what is known as bitwise, where is compare the ip host address and the subnet to decide if the packet is destined internally or an external network. I can't see how this can be achieved when both networks are using the same ip schema.
0
 
LVL 7

Expert Comment

by:compaqus
Comment Utility
Your host will not ask your default gw if the address you are looking for is on the same subnet as yourself.

http://www.experts-exchange.com/Software/System_Utilities/Remote_Access/VPN/Q_23024107.html
0
 
LVL 7

Expert Comment

by:compaqus
Comment Utility
Maybe a peer to peer route? And static IP-s on both networks...
0
 

Author Comment

by:kcassone
Comment Utility
We need to keep information separate.
0
 
LVL 23

Expert Comment

by:jakethecatuk
Comment Utility
if you have to keep the information seperate, why the need for the VPN?

again - what hardare are you using to establish the VPN?
0
Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

 
LVL 15

Expert Comment

by:JBond2010
Comment Utility
This is not going to work for you. I have explained to you in my previous comment why the network id's have to be different.
0
 

Author Comment

by:kcassone
Comment Utility
For backups

We are using netvanta 3200 and
Netgear fvs318
0
 
LVL 23

Accepted Solution

by:
jakethecatuk earned 250 total points
Comment Utility
[quote from my first post]don't think you're going to be able to solve this one without changing the range of one site.[end quote]

guess what - you can't do it with your current config.
0
 
LVL 33

Assisted Solution

by:digitap
digitap earned 250 total points
Comment Utility
jake's got it.  i've researched this before and the netgear fvs318 will not perform NAT over VPN.  also, with a cursory glance at the specs on the netvanta, it doesn't look like it will either.

NAT over VPN is possible as I've done it with Sonicwall hardware many times.  As indicated already, the best option is to change the IP network so the two sites don't have the same IP subnet.  However, this isn't always an option.
0
 
LVL 33

Expert Comment

by:digitap
Comment Utility
@kcassone :: i'm sorry you weren't able to find the answer you were seeking here.  unfortunately, the hardware you have is limiting your abilities to perform a VPN with identical subnets.  this was pointed out by myself (http:#a34088449) and jake (http:#a34088381).  although not a desireable solution, it is still a solution and points should be awared accrodingly.  two options exist:

all points going to jake for his solution here: http:#a34088381
split between myself (http:#a34088449) and jake (http:#a34088381)

i suppose there is a third option, which is to have the question deleted, but that would be up to a moderator.
0
 
LVL 33

Expert Comment

by:digitap
Comment Utility
the author's hardware doesn't support what they are requesting.  my solution and jake's solution point this out.  i'm proposing a point split:

Jake's as the solution: http:#a34088381
Mine as assisted solution: http:#a34088449
0
 
LVL 23

Expert Comment

by:jakethecatuk
Comment Utility
I agree with digitap
0
 

Expert Comment

by:thermoduric
Comment Utility
I am restarting the auto-close procedure on behalf of the question asker. After Moderator review, the new disposition seems to be more appropriate to the outcome of this question.

- thermoduric -
EE Community Support Moderator
http://www.experts-exchange.com/Q_26663260.html

0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now