Re: Connecting to VPN Router That's Behind Another Router



Jeff wrote:

- An Actiontec (from Verizon FiOS) broadband wireless router, dynamic
WAN IP, LAN IP 192.168.0.1. DHCP and wireless is enabled with minimal
security. This is so guests can connect to the internet but not to
the main LAN (see below); they're outsde the firewall.

- A Netgear fvs114 is connected via ethernet to the Actiontec, it has
a WAN address of 192.168.0.2 and a LAN address of 192.168.1.1, so
it's "WAN" is just the Actiontec router's LAN, firewall enabled. [...]

Read my lips: You do *NOT* want to terminate an IPSec VPN on a private IP behind a NAT device. You *want* to terminate it on a public, routable IP.

Dump the 2 devices, get a serious firewalling/VPN device with at least *three* physical interfaces (WAN, LAN1 (untrusted), LAN2 (trusted), deny all traffic from LAN1 to LAN2, build the VPN between the roaming clients and LAN2 and terminate it on the WAN interface (public IP).

The device with the three interfaces might be an old PC running Linux with 3 or more NICs if you want to use cheap hardware. OpenSWAN and iptables will do all what you want but you need some skills to get everything running.

OR: if you want to keep 2 routers: use a public routable network between the 2 routers, don't use NAT on the extermal router and terminate the VPN on the public IP of internal router.

I'm trying to get VPN working on the netgear.

For a serious thing get a serious device, netgear is mostly cheap crap.

Wolfgang
.



Relevant Pages

  • Re: Public IP Address for Remote Access
    ... for wan access to your home pc you are better off using ... with vnc there are lots of things to do if you want a secure connection. ... home a internet provider that has dynamic ip addressing. ... router to the particular pc on you lan (note that all of the pcs on your lan ...
    (alt.sys.pc-clone.dell)
  • Re: AccessPoints
    ... Should I flash DD-WRT onto WRT54Gv6 ... The WAN (internet) connection or the ... If the WAN, then it doesn't matter because the WAN port is ... If it's the LAN side, ...
    (alt.internet.wireless)
  • Re: 2 isps Terminal Services access
    ... Access to Internet is through two routers, one (Lan IP 192.168.50.100) ... Both routers have NAT and forward port 3389 to the Win Terminal Server ... to do with a default gateway set on the server itself. ...
    (microsoft.public.windowsxp.network_web)
  • Re: One or two questions.
    ... The only piece of kit that gets the WAN address is my modem/router, everything else communicates using LAN addresses. ... One is the WAN (Wide Area Network - usually the Internet) IP Address ... IP Addresses to the things that Connect to it using its DHCP Server ...
    (uk.people.silversurfers)
  • Re: uucp via tcp through firewall fails
    ... > internal LAN IP of 12.100.108.66. ... > only the UNIX box and it setting naked on the Internet. ... > LAN and NAT'ed to a public WAN IP and what problems this will cause ... not within any of the specified private ranges, ...
    (comp.unix.sco.misc)