Routing over Draytek LAN-LAN VPN to third party router at one end

We have a LAN-LAN VPN working fine between two sites (A and B), both with a Draytek 2850n.  At site A there is a static route in the 2850n which routes two subnets (10.3.0.0/24 and 172.16.0.0/24) to a third party Cisco 877 (and works properly).  At site B we want to be able to route across the VPN and to the Cisco for the relevant subnets.  I have set up the subnets in the "More" section of the VPN profile at site B, and a TRACERT confirms the traffic is reaching the 2850n at site A, but goes no further.

There are no load balance / route policies in place on either 2850n.

How can we configure the 2850n routers so that the traffic will pass from site B to site A's Cisco?

Here are the relevant parts of the routing tables (WAN routes removed and WAN IPs redacted) from site A:

Key: C - connected, S - static, R - RIP, * - default, ~ - private
*            0.0.0.0/ 0.0.0.0          via [Site A WAN IP]   WAN1
S~          10.3.0.0/ 255.255.255.0    via 10.152.112.2      LAN1
C~      10.152.112.0/ 255.255.255.0    directly connected    LAN1
S~      10.152.115.0/ 255.255.255.0    via [Site B WAN IP]   VPN-3
S~        172.16.0.0/ 255.255.255.0    via 10.152.112.2      LAN1

Open in new window

Here's site B:
*            0.0.0.0/ 0.0.0.0          via [Site B WAN IP]   WAN2
S~          10.3.0.0/ 255.255.255.0    via [Site A WAN IP]   VPN-1
S~      10.152.112.0/ 255.255.255.0    via [Site A WAN IP]   VPN-1
C~      10.152.115.0/ 255.255.255.0    directly connected    LAN1
S~        172.16.0.0/ 255.255.255.0    via [Site A WAN IP]   VPN-1

Open in new window

Thanks in advance for any advice.
LVL 2
David HaycoxConsultant EngineerAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

NetExpert Network Solutions Pte LtdTechnical SpecialistCommented:
Based on the info provided by you, u understood the traffic from site B to the new subnet looks like below

LAN -- site B --- vpn -- site A --- cisco device

In that case, Have you added the route on the cisco router for the  new subnet towards site A.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
David HaycoxConsultant EngineerAuthor Commented:
I don't have control of that router, it's supplied by a third party.  Would the traffic from site B not appear to come from the site A Draytek's IP?

I've set up something similar in the past which just worked when I added the extra subnets to the Draytek VPN, so I wasn't expecting to have to reconfigure the Cisco.

Here are the IP details, if this helps:

Site A Cisco      10.152.112.2/24
Site A Draytek 10.152.112.90/24
Site B Draytek  10.152.115.1/24
NetExpert Network Solutions Pte LtdTechnical SpecialistCommented:
//Would the traffic from site B not appear to come from the site A Draytek's IP?//  - Nope; as you are not modifying the Site B Lan network over VPN tunnel,

Since the traffic from Site B to cisco device dropped after Site A, I am very sure that the Cisco device doesn;t have back routing to site B networks.

Need to check the routing table on the cisco device
Determine the Perfect Price for Your IT Services

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden with our free interactive tool and use it to determine the right price for your IT services. Download your free eBook now!

David HaycoxConsultant EngineerAuthor Commented:
Thanks, I will contact the third party in question and post back the results.
Kash2nd Line EngineerCommented:
drayteks' are not brilliant in handling those.
If you have the actual network which you want site A to see then a route needs adding to site A router.

However, if the subnet doesn't exist on site B (draytek) then merely putting it in won't help.

I were in similar position with cisco and draytek and cisco tech wanted me to appear from the networks they allocated for me.
I had to get another router, configure it with the network they wanted and plug it into draytek which could then see it (on configured ports) and then cisco would connect without issue.
David HaycoxConsultant EngineerAuthor Commented:
Kash: I've had something very similar working before with the Draytek-Draytek VPN and a third party Cisco.  Only difference from the Draytek config was that there was a second IP set up for routing as the subnet of the Cisco was different.  In the current situation the Cisco and Draytek at Site A are in the same subnet already.

I have a route set up on the site A Draytek and it works for local clients.

In any case I have put in a change request with the company that manages the Cisco; they asked for the remote subnet and local gateway to add their config, so that looks promising.  Will post back when completed.
NetExpert Network Solutions Pte LtdTechnical SpecialistCommented:
David, As I said in my last update that , the Cisco router has to have back routes to your site B new subnets and the gateway to reach site B network is site A draytek router.
David HaycoxConsultant EngineerAuthor Commented:
Yes, understood.  Have asked for that route to be added, was just responding to Kash's post.  Will update as soon as have news.  Thanks!
David HaycoxConsultant EngineerAuthor Commented:
Spot on!
Kash2nd Line EngineerCommented:
glad it got sorted. apologies I could't feedback in, been sorting those mikrotek's out :)
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Routers

From novice to tech pro — start learning today.