Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


VPN: 2 network with same IP scheme problem

Posted on 2011-03-09
Medium Priority
Last Modified: 2012-08-13
We have a windows 2008 server, running as DC/DNS/DHCP,etc. I setup the VPN on it, i don't have problem establish the connection on the client workstation. But the problem is sometimes I cannot use the \\servername, even I try the \\server_IP. When I ping it replies though.
i noticed that the 2 network use same IP scheme as 192.168.1.x, is this causing the problem? why? if that's the case, then I think it's not practical, as how can we expect the network that client at all use different IP scheme, like in hotel, airport, cafe, etc
Question by:okamon
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 33

Expert Comment

ID: 35091124
you've encountered a common problem. is a VERY common subnet. you could pick something in the area, like this isn't used often.

how some company's get around that is to do what's called tunnel all rather than split tunneling. split tunneling says that your remote users has access to resources on the local network AND the remote network. what this usually amounts to is they access the vpn to access intra-network resources and use the local network to get to the internet. if you "tunnel all" then they only have access to resources on the intra-network and that's it. they'd have to disconnect from the vpn to access the internet. there is a way that you can get internet access over the vpn as well, but i'm not familiar with how to do that on a 2008 vpn server...only a sonicwall appliance.

tunnel all would force all the traffic to go over the VPN regardless of the local subnet. this would almost certainly resolve the issue you are seeing, unless it's a DNS issue. do you see the same issue when the subnet is different?

in your case of resolving the server name, it may be more of an issue with DNS. are you passing an internal DNS server to the IP settings of the vpn client? if not, then it's probably not going to resolve the server name. of course, it could be that the subnet is the same and is trying to resolve the name on a local DNS server which wouldn't know anything about your server.

Author Comment

ID: 35104969
I don't have any issue if I am on different subnet. So do you know how can I setup tunnel all in windows 2008? When I first setup vpn client, in tcp/ip setting, by default it is "Use default gateway on remote network"..... this is not tunnel all? as they will pass through the remote network to go to internet though....
LVL 33

Expert Comment

ID: 35105819
Yes, checking that box does mean tunnel all. it means all the resources on the local network are not accessible and traffic is sent through the vpn connection.

my expectation is that if you are on an identical network, then tunnel all should work. if it's not, then changing the IP subnet for your remote clients get is the next option and, quite possibly, your only option.
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.


Author Comment

ID: 35118221
it seems the tunnel all working for me, if i am on different subnet, there is no issue.... there is no other solution?
LVL 33

Expert Comment

ID: 35118274
if tunnel all doesn't work with duplicate subnets, then you need to change the subnet for you remote users. sorry.

if you believe another answer exists, then try clicking the request attention link in your question. request a mod to adjust your zones and send a request for other experts to review your question. either you'll get an answer that you like or one that supports mine. i know i'd want a second opinion.
LVL 10

Expert Comment

ID: 35120860
You have to change remote site IP range....

Otherwise, you can route specific ip (or small ip ranges) to remote sites (to access specific servers for example) but after a few sites, it will be unmanageable!

Author Comment

ID: 35122467
Thank you. as digitap mentioned some vpn server can do tunnel all. windows 2008 vpn server cannot handle that? It seems on the vpn client, by default it direct all traffic, but it doesn't help.  
LVL 71

Accepted Solution

Qlemo earned 1600 total points
ID: 35328805
As has been said already - VPNs (of all kind) work only reliable if the subnets are different. Anything else depends on how the VPN client manages traffic. "Tunnel All" can be used only with a few VPN Clients, like Checkpoint, Nortel or Cisco. MS VPN (PPTP) is not able to do that.

With MS VPN and conflicting subnets  - and NOT having set "Use default gateway on remote network" -   whether you have access to the remote network or the local network is not predictable.
With "Use default gateway" many entries have precedence over the local ones, including DNS and routes. It is not "Tunnel all", which forces all traffic to go thru VPN without exception, though.

The way ampranti described (using more specific routes for the remote network) is working best. E.g. if you need access to only three specific machines, say, .5, .7, you can create routes to those. However, it is not easy to do that, and you need to apply the routes on each connect - with a probably changing interface or gateway address, which makes things even more complicated. If you are interested, we can work on that.

Featured Post

New feature and membership benefit!

New feature! Upgrade and increase expert visibility of your issues with Priority Questions.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
Make the most of your online learning experience.
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor ( Top Charts is a view in which you can set seve…

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question