VPN - how to access internet and VPN resources at the same time?

May 08, 2006 3 Replies
VPN - how to access internet and VPN resources at the same time? open original image

Hi,



I've asked this here already, but I probably didn't phrase it very well.



I've got a Cisco 837, which I have configured as a VPN server (pptp). The router is 192.168.1.1/24.



My VPN address pool is 172.16.1.1 to 172.16.1.5.


When I establish a VPN connection to my server using a bog-standard Windows PPTP connection, I have two scenarios:


1) If I have the box "use default gateway on remote network" ticked then I can access my VPN resources (e.g. 192.168.1.150, 12.168.1.201), but I can't resolve any DNS.


2) If I have the box "use default gateway on remote network" unticked then I can resolve DNS, but I can't access my VPN resources (e.g.



192.168.1.150, 12.168.1.201) unless I do a "ROUTE ADD 192.168.1.1 MASK
255.255.255.0 172.16.1.1".

With my old DrayTek I used to be in scenario 2, e.g. have the box unticked, but I could quite happily surf the web AND access VPN resources, without requiring the ROUTE ADD command.



Can anyone suggest what I need to configure on my VPN? Having googled for three days, the concept of LOOPBACK keeps occurring, as does Split DNS, but I'm sure it must be something very simple that's required.



Or is there some way of adding some kind of alias on the router, such that instead of trying toa ccess my VPN resources via 192.168.1.x I access them via 172.16.x.x and the addresses get translated? I'm clutching at straws here in desperation!


Many thanks,


Jim



PS Happy to make a PayPal donation to anyone who can help me achieve the solution!!!


I forgot to say - it's the identical problem as described here:

formatting link
but surely there's a simple solution? I get varying addresses (dynamic) so ROUTE ADD is not really ideal.

Jim

Okay, I'm reposnding to my own question - but then again I talk to myself too !

I've just connected to a client's VPN on address x.x.x.240. I was assigned a local IP of x.x.x.160.If I look at my routing table (ROUTE PRINT) I see that the VPN Server has automatically added a static route for me:

x.x.x.0 mask 255.255.255.0 x.x.x.160

This is exactly what I want to achieve! So, can anyone help me add the appropriate lines to my config so that a static route of

192.168.1.0 mask 255.255.255.0

Thank you everyone,

Jim

Okay, nobody in this NG seemed able (or willing!) to help.

The solution is this: Make your VPN address ranges on the same subnet as the router.

My router is 192.168.1.1, and my subnet is 255.255.255.0. I have now set my VPN address pool to be 192.168.1.251 to 192.168.1.254. When I establish a VPN session now, I get the correct routing table (192.168.1.0/24).

For the benefit of anyone else trying to achieve the same.

Jim

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required