VPN: 2 network with same IP scheme problem

Posted on 2011-03-09
Last Modified: 2012-08-13
We have a windows 2008 server, running as DC/DNS/DHCP,etc. I setup the VPN on it, i don't have problem establish the connection on the client workstation. But the problem is sometimes I cannot use the \\servername, even I try the \\server_IP. When I ping it replies though.
i noticed that the 2 network use same IP scheme as 192.168.1.x, is this causing the problem? why? if that's the case, then I think it's not practical, as how can we expect the network that client at all use different IP scheme, like in hotel, airport, cafe, etc
Question by:okamon
LVL 33

Expert Comment

ID: 35091124
you've encountered a common problem. is a VERY common subnet. you could pick something in the area, like this isn't used often.

how some company's get around that is to do what's called tunnel all rather than split tunneling. split tunneling says that your remote users has access to resources on the local network AND the remote network. what this usually amounts to is they access the vpn to access intra-network resources and use the local network to get to the internet. if you "tunnel all" then they only have access to resources on the intra-network and that's it. they'd have to disconnect from the vpn to access the internet. there is a way that you can get internet access over the vpn as well, but i'm not familiar with how to do that on a 2008 vpn server...only a sonicwall appliance.

tunnel all would force all the traffic to go over the VPN regardless of the local subnet. this would almost certainly resolve the issue you are seeing, unless it's a DNS issue. do you see the same issue when the subnet is different?

in your case of resolving the server name, it may be more of an issue with DNS. are you passing an internal DNS server to the IP settings of the vpn client? if not, then it's probably not going to resolve the server name. of course, it could be that the subnet is the same and is trying to resolve the name on a local DNS server which wouldn't know anything about your server.

Author Comment

ID: 35104969
I don't have any issue if I am on different subnet. So do you know how can I setup tunnel all in windows 2008? When I first setup vpn client, in tcp/ip setting, by default it is "Use default gateway on remote network"..... this is not tunnel all? as they will pass through the remote network to go to internet though....
LVL 33

Expert Comment

ID: 35105819
Yes, checking that box does mean tunnel all. it means all the resources on the local network are not accessible and traffic is sent through the vpn connection.

my expectation is that if you are on an identical network, then tunnel all should work. if it's not, then changing the IP subnet for your remote clients get is the next option and, quite possibly, your only option.

Author Comment

ID: 35118221
it seems the tunnel all working for me, if i am on different subnet, there is no issue.... there is no other solution?
Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

LVL 33

Expert Comment

ID: 35118274
if tunnel all doesn't work with duplicate subnets, then you need to change the subnet for you remote users. sorry.

if you believe another answer exists, then try clicking the request attention link in your question. request a mod to adjust your zones and send a request for other experts to review your question. either you'll get an answer that you like or one that supports mine. i know i'd want a second opinion.
LVL 10

Expert Comment

ID: 35120860
You have to change remote site IP range....

Otherwise, you can route specific ip (or small ip ranges) to remote sites (to access specific servers for example) but after a few sites, it will be unmanageable!

Author Comment

ID: 35122467
Thank you. as digitap mentioned some vpn server can do tunnel all. windows 2008 vpn server cannot handle that? It seems on the vpn client, by default it direct all traffic, but it doesn't help.  
LVL 68

Accepted Solution

Qlemo earned 400 total points
ID: 35328805
As has been said already - VPNs (of all kind) work only reliable if the subnets are different. Anything else depends on how the VPN client manages traffic. "Tunnel All" can be used only with a few VPN Clients, like Checkpoint, Nortel or Cisco. MS VPN (PPTP) is not able to do that.

With MS VPN and conflicting subnets  - and NOT having set "Use default gateway on remote network" -   whether you have access to the remote network or the local network is not predictable.
With "Use default gateway" many entries have precedence over the local ones, including DNS and routes. It is not "Tunnel all", which forces all traffic to go thru VPN without exception, though.

The way ampranti described (using more specific routes for the remote network) is working best. E.g. if you need access to only three specific machines, say, .5, .7, you can create routes to those. However, it is not easy to do that, and you need to apply the routes on each connect - with a probably changing interface or gateway address, which makes things even more complicated. If you are interested, we can work on that.

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

26 Experts available now in Live!

Get 1:1 Help Now