Problem with proposed subnet configuration?

Problem with proposed subnet configuration?

NewsGroups | Search | Tools
 comp.dcom.vpn  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Problem with proposed subnet configuration? Ray Bellis 03-07-2005
Posted by Ray Bellis on March 7, 2005, 12:47 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


We have a customer who is part of a (large) internal network using
10.0.0.0/8

Each department within the network is assigned a /16, and each site
within that department is assigned a /24 from that /16.

The routing within this network is handled by a managed VPN provider,
and each site has its own connection to the network - traffic from a
particular office does *not* route via the relevant department HQ back
to the core network.

Our customer is the HQ of the department using 10.225.1/24, and they
want to connect some new sites without using the managed VPN provider.

We had hoped to split out each of the /24s from 10.225.128.0 upwards,
and then use an IPSEC VPN between there and the main network, i.e.

+-----------------+ +-----------------+
| | | |
| 10.225.128.0/24 +---- VPN ----+ 10.225.1.0/24 |
| + | |
+-----------------+ +-----------------+

This works fine so long as we only want to talk to department HQ.

However they also need to be able to talk to other parts of the internal
network which are in other parts of the 10/8 network.

We therefore attempted to configure the VPN router at the
10.225.128.0/24 site with a remote IPSEC subnet of 10/8.

At this point that router stops responding to its configuration
interface! :(

We can only surmise that this is because the router sees incoming
packets on its LAN interface, and decides solely on the basis of the
tunnel's remote subnet that these packets must be tunneled, even though
they're addressed to the router's own LAN interface.

I'm lead to believe that this should be a perfectly normal
configuration, and yet it doesn't work properly on these Zyxel 662 DSL
routers.

Can anyone point me at some documentation that proves (or otherwise)
that the Zyxel behaviour is incorrect?

kind regards,

Ray




Similar ThreadsPosted
IPSec as solution to subnet problem May 21, 2008, 9:07 am
Comtrend CT-535 - Configuration for VPN March 23, 2005, 4:44 am
configuration pour VPN client February 24, 2008, 7:00 am
Contivity configuration backup and restore. June 21, 2005, 6:07 pm
Xincom TwinWan Router VPN configuration September 29, 2005, 6:44 am
IPSec Fallback mechanism subnet/supernet January 8, 2008, 11:17 pm
SSH through VPN problem February 19, 2006, 3:45 am
VPN-NAT problem March 15, 2006, 7:21 am
problem June 16, 2006, 5:29 pm
VPN Problem October 15, 2006, 1:25 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map