Solved

How to send client traffic out local ISP with OpenVPN point-to-point VPN

Posted on 2014-10-15
1
269 Views
Last Modified: 2014-10-16
Hi everyone,

I'm hoping this is a simple question as it's got me a little stumped.

I have two office each with separate internet accounts and Ubiquiti EdgeRouters installed at each (basically Vyatta routers) and a point-to-point VPN connecting the two so our IP phone system can talk.  The problem I'm having is that client traffic at Site B destined for the internet is being sent across the VPN and out Site A's ISP.  How can I only send traffic from 1 IP across the VPN and send everything else out the local ISP.

Here's the layout:

Site A
[Ubiquiti EdgeRouter]
- WAN: <Static Assigned Public Address>
- LAN: 172.16.0.1
- VTUN: 10.99.99.1
[Phone System]
- IP: 172.16.0.2
[DHCP Pool]
172.16.1.1-172.16.1.254

Site B
[Ubiquiti EdgeRouter]
- WAN: <Static Assigned Public Address>
- LAN: 172.16.100.1
- VTUN: 10.99.99.2
[Phone System]
- IP: 172.16.100.2
[DHCP Pool]
172.16.101.1-172.16.101.254

I only need traffic between device 172.16.0.2 and device 172.16.100.2 to go across the VPN.  Everything else can go out the local gateway at each site to the internet.  To clarify, my VPN is working correctly in that I have no problem talking to each side, but I want the VPN only to apply to the two devices needed.

Hope this makes sense.

Thanks,
Phil

The
0
Comment
Question by:pcasalegno
1 Comment
 
LVL 7

Accepted Solution

by:
tolinrome earned 500 total points
ID: 40384365
You have a vpn that seems to be tunneling everything from remote site to corporate. You need to specify in your vpn config that the only traffic to tunnel is the voice traffic (if thats what you want) and you define that by subnets usually.

It seems that your LAN is on the same subnet as the Phone system thats why everything is going accross. Define in your VPN only the phone system.

I'm not familiar with that type of router but you may have to put your phone system on a different subnet than your data and only have the voice subnet tunnel the traffic over. Then your LAN data traffic would go straight out the internet.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now