VPN - supporting multiple private NAT clients

From: Venger (venger_at_augustmail.com)
Date: 10/31/03


Date: Thu, 30 Oct 2003 22:49:25 -0600


Gentlemen -

Have a client with a pair of offices linked with Sonicwall VPN between
them - 192.168.1.X and 2.X. Works famously, better than I ever expected it
to.

We wish to connect a laptop to one of the office firewalls across the
internet via VPN. This brought about a conflagration of conflicting thoughts
about what can, and cannot, be done.

If said laptop is behind a NAT router with a 192.168.1.X address, it cannot
create a VPN to the first Sonicwall - the destination route and local route
are the same. If we were to connect to the second firewall, it would appear
that since that firewall is already attached via a site to site VPN, it
would have a conflict between two VPN connections, with overlapping address
space.

Which then begs the question... how can you support dozens of clients who
could quite possibly each have the same private NAT address, say
192.168.1.100, much less similar address space?

NAT Traversal?

Any information is definitely appreciated. Our Sonicwalls talk to each other
fine, but are barfing on connecting the laptop. I assume that NAT traversal
is an issue here, the firmware is 5.1.7.0 and they do not currently support
NAT traversal on that firmware release...

Thanks,

Venger



Relevant Pages

  • Re: SBS 2008 - Firewall Appliance?
    ... Cisco ASA 5510 Appliance Content Security Edition Bundle ... 250 IPsec VPN peers, ... But "firewall services" are simply listed as included. ... If you don't need AV or VPN then this is overkill....and I recommend running client AV on a server that can handle monitoring anyways....not using an edge device as the client AV manager...but that's another conversation. ...
    (microsoft.public.windows.server.sbs)
  • Re: remoting not working through vpn
    ... These can act differently depending on where the VPN terminates. ... I have ISA firewall and all my VPN connections terminate on the firewall system. ... The other case might be that you have tunneled the VPN completely through the firewall and let it terminate on the server itself. ... The problem may be in how the client system is presenting its ...
    (microsoft.public.dotnet.framework.remoting)
  • Re: Teleworking
    ... Cisco VPN Client running on local PC ... ADSL router runing VPN passthrough and full firewall ... > simplify the management and deployment of PGP and reduce overall PGP ...
    (Security-Basics)
  • Re: RE:Sizing a Firewall for a Client
    ... about the Sonic Wall Pro, when in turn will cost you at least 3 times as ... Sizing a Firewall for a Client ... We've tested the Sonicwall with up to 5 VPN clients at once ...
    (Security-Basics)
  • Re: WRT54GL with DD-WRT VPN firmware - wheres the beef?
    ... There is no "server" of any real ... Netgear Prosafe VPN client works well with Sonicwalls in a GroupVPN SA using ... even have access to another Sonicwall, ...
    (alt.internet.wireless)