Link to home
Start Free TrialLog in
Avatar of jcl64213
jcl64213

asked on

VPN Site-Site with external IP on same subnet.

Hello,

SonicWALL NSA routers

I have a network with 10 site to site vpn's. We switched providers on two of our sites. The buildings are on the same street and I got these IP's

Site A -   X.X.49.53
Site B -  X.X.49.52

I was able to recreate all of the tunnels with the exception of Site A to Site B. I'm wondering if it has to do with the fact that they are on the same .49 network. Any idea if this is the case?

Thanks in advanced
Avatar of John
John
Flag of Canada image

Normal VPN must be on different subnets internally or it will not work.

But here you have 2 external IP addresses on the same subnet. I have not run across that. Make sure the Internal Subnets are completely different.
Avatar of jcl64213
jcl64213

ASKER

Yes, the internal subnets are different, it was a functioning vpn until the new external IP's. I contacted the ISP to see if I can change one of the static IP's to a different subnet but they told me that my area was assigned that subnet and until those numbers where exhausted I would keep getting the same and they would be wasting good IP's.
Avatar of Qlemo
"on the same network" depends on the network mask and hence routing info. But it is very unlikely the netmask is a host IP only (/32), and so those are seen as on the same subnet, not needing any routing - which is certainly not correct.
ASKER CERTIFIED SOLUTION
Avatar of John
John
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
However, thinking more about it, you should be able to create a host route using the assigned remote gateway - that should work.

E.g.:
Site A, x.x.49.53/24, ISP gateway x.x.49.1
Site B, x.x.49.52/24, ISP gateway x.x.49.1
=> on Site A, create route x.x.49.52/32 gateway x.x.49.1
      on site B, create route x.x.49.53/32 gateway x.x.49.1
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
A different external subnet makes a lot of sense and that has solved your issue.
It's very abnormal that you were assigned multiple IPs in the exact same subnet for two different locations. But that would've been the root of your issue.
I said here https:#42223791 that you needed a different external IP and that is what you did.