Contivity VPN Problems

Hi there -

I have a very strange problem that I hope someone can explain to me. I have two Contivity 221's that are setup as a main office and remote office to create a VPN. The VPN is used to allow remote users to use IP2004 telephones with the main office Succession at home.

The Contivity's set up the VPN tunnel with no problem. I can ping computers on both sides of the VPN - I can remotely configure the Contivity's from both sides with the local addresses. What I simply cannot understand is why the only thing (AND THE MOST IMPORTANT THING) I cannot ping is the Signaling Server! I can see everything else but the Signaling Server.

This has me completely baffled. Anyone have any ideas???

Thank you in advance.

Reply to
compufxr
Loading thread data ...

First a silly question

1- Can you ping your Signaling Server on your local network.

2- Have you made your VPN box on your local network the default gateway for your Signaling Server ?

Hope this helps

JP

a écrit dans le message de news: snipped-for-privacy@g14g2000cwa.googlegroups.com...

Reply to
JP

gateway for

Yes, of course I can ping the Signaling Server on the local network. I can connect an IP phone to it as well. Everything works except when it comes through the contivity. I tried making the contivity the gateway but then I was completely unable to telnet into and use the web interface to make any changes or check the logs. I had to use the console cable on my laptop to be able see anything that was going on with the contivity. It was probably due to the fact that the gateway address was also the address I used for laptop's gatway and therefore it was trying to find the gateway through the gateway. In any case it still did not work for me. Any other ideas?

Thank you in advance for your help!

simply

Reply to
compufxr

Can you ping something else (not your Signalling server) on your local network from your distant network ?

Do you have some very restrictive mask (kind of 255.255.255.240) that would exclude your signalling server ?

Do you have permit all set on your tunnel & interface filters. Could there be some ICMP restrictions on your tunnel set by your contivity ?

JP

JP (*) wrote:

gateway for

Yes, of course I can ping the Signaling Server on the local network. I can connect an IP phone to it as well. Everything works except when it comes through the contivity. I tried making the contivity the gateway but then I was completely unable to telnet into and use the web interface to make any changes or check the logs. I had to use the console cable on my laptop to be able see anything that was going on with the contivity. It was probably due to the fact that the gateway address was also the address I used for laptop's gatway and therefore it was trying to find the gateway through the gateway. In any case it still did not work for me. Any other ideas?

Thank you in advance for your help!

simply

Reply to
Kashmir

I can ping a laptop ont he same network. I am using a standard /24 subnet (255.255.255.0) so I should have more than enough addresses. I will have to check the last one, but I doubt that is the problem. Thank you for your input though!

Reply to
compufxr

Are there any important ports being blocked by the signaling server? Or do you have a managed switch at the remote end behind the Contivity box that is blocking ports?

Reply to
J. McGoggin

"compufxr" said to all and sundry:

Are you using client tunnels or branch office tunnels? If client, it shouldn't matter since everything is on the same network and at that point I'd start looking at filters on the Contivity. If branch office, which generally entails VPN's coming in from different subnets, it sounds like a one-way route such that the Contivity knows to pass traffic to the Signaling Server, but the Signaling Server has no route back to the branch office. If that is the case, try enabling something like Rip2 on both the Contivity and your core router, or add a static route on your core router for the purpose of testing this.

Just a thought. Not knowing your network, if you've removed all filters and such from the core, then by process of elimination you're left with routing and the Contivity.

-- Dan

  • Dan Sorenson DoD #1066 ASSHOLE #35 BOTY 1997 snipped-for-privacy@svtv.com *
  • Vikings? There ain't no vikings here. Just us honest farmers. *
  • The town was burning, the villagers were dead. They didn't need *
  • those sheep anyway. That's our story and we're sticking to it. *
Reply to
Natural Born Cereal Killer

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.