How to send client traffic out local ISP with OpenVPN point-to-point VPN

Hi everyone,

I'm hoping this is a simple question as it's got me a little stumped.

I have two office each with separate internet accounts and Ubiquiti EdgeRouters installed at each (basically Vyatta routers) and a point-to-point VPN connecting the two so our IP phone system can talk.  The problem I'm having is that client traffic at Site B destined for the internet is being sent across the VPN and out Site A's ISP.  How can I only send traffic from 1 IP across the VPN and send everything else out the local ISP.

Here's the layout:

Site A
[Ubiquiti EdgeRouter]
- WAN: <Static Assigned Public Address>
- LAN: 172.16.0.1
- VTUN: 10.99.99.1
[Phone System]
- IP: 172.16.0.2
[DHCP Pool]
172.16.1.1-172.16.1.254

Site B
[Ubiquiti EdgeRouter]
- WAN: <Static Assigned Public Address>
- LAN: 172.16.100.1
- VTUN: 10.99.99.2
[Phone System]
- IP: 172.16.100.2
[DHCP Pool]
172.16.101.1-172.16.101.254

I only need traffic between device 172.16.0.2 and device 172.16.100.2 to go across the VPN.  Everything else can go out the local gateway at each site to the internet.  To clarify, my VPN is working correctly in that I have no problem talking to each side, but I want the VPN only to apply to the two devices needed.

Hope this makes sense.

Thanks,
Phil

The
pcasalegnoAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

tolinromeCommented:
You have a vpn that seems to be tunneling everything from remote site to corporate. You need to specify in your vpn config that the only traffic to tunnel is the voice traffic (if thats what you want) and you define that by subnets usually.

It seems that your LAN is on the same subnet as the Phone system thats why everything is going accross. Define in your VPN only the phone system.

I'm not familiar with that type of router but you may have to put your phone system on a different subnet than your data and only have the voice subnet tunnel the traffic over. Then your LAN data traffic would go straight out the internet.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
VPN

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.