Solved

How to send client traffic out local ISP with OpenVPN point-to-point VPN

Posted on 2014-10-15
1
273 Views
Last Modified: 2014-10-16
Hi everyone,

I'm hoping this is a simple question as it's got me a little stumped.

I have two office each with separate internet accounts and Ubiquiti EdgeRouters installed at each (basically Vyatta routers) and a point-to-point VPN connecting the two so our IP phone system can talk.  The problem I'm having is that client traffic at Site B destined for the internet is being sent across the VPN and out Site A's ISP.  How can I only send traffic from 1 IP across the VPN and send everything else out the local ISP.

Here's the layout:

Site A
[Ubiquiti EdgeRouter]
- WAN: <Static Assigned Public Address>
- LAN: 172.16.0.1
- VTUN: 10.99.99.1
[Phone System]
- IP: 172.16.0.2
[DHCP Pool]
172.16.1.1-172.16.1.254

Site B
[Ubiquiti EdgeRouter]
- WAN: <Static Assigned Public Address>
- LAN: 172.16.100.1
- VTUN: 10.99.99.2
[Phone System]
- IP: 172.16.100.2
[DHCP Pool]
172.16.101.1-172.16.101.254

I only need traffic between device 172.16.0.2 and device 172.16.100.2 to go across the VPN.  Everything else can go out the local gateway at each site to the internet.  To clarify, my VPN is working correctly in that I have no problem talking to each side, but I want the VPN only to apply to the two devices needed.

Hope this makes sense.

Thanks,
Phil

The
0
Comment
Question by:pcasalegno
1 Comment
 
LVL 7

Accepted Solution

by:
tolinrome earned 500 total points
ID: 40384365
You have a vpn that seems to be tunneling everything from remote site to corporate. You need to specify in your vpn config that the only traffic to tunnel is the voice traffic (if thats what you want) and you define that by subnets usually.

It seems that your LAN is on the same subnet as the Phone system thats why everything is going accross. Define in your VPN only the phone system.

I'm not familiar with that type of router but you may have to put your phone system on a different subnet than your data and only have the voice subnet tunnel the traffic over. Then your LAN data traffic would go straight out the internet.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question