VPN with 2 network cards - vpn clients cannot see LAN.

Problem: When a VPN client connects they can only access the server and not any LAN computers. Unable to even ping the LAN computers. The VPN client machine connects via PPTP and receives the appropriate IP address but the subnet mask field is blank. The router is being set to 192.168.1.2
Here's my network setup:
en0: (external) IP: 192.168.1.2 and is connected to aDSL modem (192.168.1.1)
en1: (internal net) IP: 192.168.2.1
The internal en1 network range is: 192.168.2.2 - 192.168.2.25
The VPN range being handed out is: 192.168.2.26 - 192.168.2.30
VPN client machines are able to fully interact with the server, just cannot reach any LAN computers.
Any ideas??
XServe Mac OS X (10.4.9) Various Intel laptops and G5/G4 Lan machines
XServe   Mac OS X (10.4.9)   Various Intel laptops and G5/G4 Lan machines

>The network address at the vpn client location is not 192.168.2.0/24. The vpn client has a public IP.
So you're saying that your client system has a 192.168.2.x address, and that's also the address range you're using behind the VPN?
That won't work.
You now have two 192.168.2.x networks - one local to the client and one over the VPN.
Normal routing rules dictate that the local connection wil always take priority over the remote connection, so the client will look on the local LAN for anything in the 192.168.2.x range, completely ignoring the VPN.
If you think about it, your machine is told that it has two paths to get to anything in the 192.168.2.x network, either directly connected, or across the VPN connection. Given teh choice, which one do you think you'd take?
The only real solution here is to use a different subnet at each end of the link - either change the client network to something else, or change the internal corp network. If you don't do that you'll have to set up host-based routes (one per system over the VPN) that overrides the local routing table (assuming that's even possible... I'd have to think about it).

Similar Messages

  • Hello! I have configured my Wireless network to support bonjour protocol. When I support mDNS in the same Vlan I can see the Apple TV with my iPhone, but I cannot see it with my iPad.

    Hello! I have configured my Wireless network to support bonjour protocol. When I support mDNS in the same Vlan I can see the Apple TV with my iPhone, but I cannot see it with my iPad. Someone know if there is any different in the Bonjour protocol between the iPhone and the iPad???
    It is like if the iPad changes the process at some point...
    Thank you!

    You don't need to configure anything specific for it to work unless you had some special filtering in place already.
    What do you mean specificly by can not "see" it with your iPad?

  • I bought a iPad2 with ios5 on it, I bought imovie in App Store, I edited a short video 1m 30sec, I transfered it on iTune newly upgrated, I see my vid  in iTune , I put it on my imac os x 10.6.8 with imovie 11. I cannot see this vid! Have I mistaken somwh

    I bought a iPad2 with ios5 on it, I bought imovie in App Store, I edited a short video 1m 30sec, I transfered it on iTune newly upgrated, I see my vid  in iTune , I put it on my imac os x 10.6.8 with imovie 11. I cannot see this vid! Have I mistaken somewhere?
    I feel quite upset to not use this function, because it is one of the reasons Ibought this device. To be almost free, anywhere I want,  I take my Ipad , whrite, shoot, edit, and post to report the experience I live.

    I bought a iPad2 with ios5 on it, I bought imovie in App Store, I edited a short video 1m 30sec, I transfered it on iTune newly upgrated, I see my vid  in iTune , I put it on my imac os x 10.6.8 with imovie 11. I cannot see this vid! Have I mistaken somewhere?
    I feel quite upset to not use this function, because it is one of the reasons Ibought this device. To be almost free, anywhere I want,  I take my Ipad , whrite, shoot, edit, and post to report the experience I live.

  • Hello. I recently updated numbers on my macbook pro. I like the auto completion feature (proposing te word as I type). With this new update, I cannot see this feature and it doesn't work automatically. Can I have any help on this issue ?

    Hello. I recently updated numbers on my macbook pro. I like the auto completion feature (proposing te word as I type). With this new update, I cannot see this feature and it doesn't work automatically. Can I have any help on this issue ?

    This is really unfortunate. I'm sorry that nothing works. I was going to mention holding down the power button and doing a force shutdown but you already did that. You might need to take it into the Apple store. I don't know if booting into safe mode would help. You would have to turn off the machine again, hit the start button and hold down the shift key after you hear the tone, but normally you would let go of the shift key when you see the apple logo and spining wheel. Maybe by holding down the shift key after you here the tone will cause the screen to come back on? The other option is to start up from the 'install disk' if your machine came with one. You would insert the disk, then shut down the computer, and hold down the C key right after hitting the start button.
    Here's the link for the safeboot
    http://support.apple.com/kb/HT1564?viewlocale=nl_nl

  • Solaris9 x86 problem with network cards, ACPI, IRQs

    Hello!
    For the last two days I've been trying to solve the problem of Solaris9 x86 not being able to use my network card. I have tried with 3c905CX-TX-M, RealTek 8139 and Realtek 8029 and none of them works. The problem is the following:
    Everything is properly configured, networking etc., but the cards can only send and cannot receive packets. When trying to ping, the packets leave the NIC but none of the reponses are detected by NIC. When I check with 'kstat elxl' I can see that 'intr' is zero, and out_packets is increasing as it's sending packets.
    From the discussion forum I can see that this same problem has been known for several years. One of the conclusions is that Solaris x86 sucks at dealing with IRQ setup and that the best thing is to disable ACPI and 'PnP OS' option in BIOS. However, I've tried all releases of AMI bios and none them has neither of those options. I have played with various priority levels in BIOS but all that has accomplished is that the card, when first started, captures a few interrupts/packets but then stops again. This is usually just enough to finish the ARP exchange (arp -a shows the remote host).
    And of course, all the cards work just fine in WindowsXP and Linux. And all the cards work nice in another PC which runs the same Solaris 9 x86.
    My motherboard is Gigabyte 7VTXE. (The other one in which it works is ASUS P2B-DS).
    I would really appreciate help!
    Josip

    I had almost identical problem today on an HP Kayak - which happened to be dual CPU one. The fix
    set pcplusmp:apic_forceload = -1
    in /etc/system worked for me. The only drawback is that it also leaves the machine single CPU. AFAIK this (downloadable) S9x86 kit is licensed only for one CPU anyway, so I wonder if something has been fixed in the code to make sure it is not run on multi-CPU systems. Before the fix, mpstat showed thousands of interrupts on CPU0, both CPUs were constantly busy at about 70% and there was no network connection on a number of cards I tried (3Com 90x - elxl, Intel iprb, another one with Realtek 8139 was never recognized, so I did not bother too much to find if there is a fix for this); pinging out resulted in the hub port light blinking, nothing comes back.
    Anyway, the fix is good enough to test s9 for now; everything else seemed to be OK. If it may be of some use for somebody, don't go into the disk option of the Solaris Management Console; the machine in question had Windows 2003 server (RC2) installed before Solaris9, the disk tool decided that there was no label on the disk and asked to write it on; I clicked the 'cancel' button, but the partition table was irreversibly damaged, so I had to start from installing W2k3. My guess is that tool has been tested only with Sparc, so there is no issue with BIOS level partitioning there. BTW, system info of the SMC insists that the CPUs are Sparcs...

  • Want to check local wifi hotspots with network card

    I've been told that my new MacBook Pro comes with a wireless network card and that I can use it to check whether there are wifi networks around.  Is there a way find out info on local networks with my Mac?

    Well, it's not technically a card, it's built in, but it's easy.  First go to System Preferences (it's under your Apple Menu, top right corner), then click on Network.  Along the right side is an icon that says "Airport".  Click on that.  Then check off "Show AirPort status in menu bar".  On your menu bar, then you should see something that looks like a signal (which shows strength).  If you click on that, you will see all the hotspots near you.

  • PCI USB2 Controller card conflicts with network card

    I've installed a PCI USB2 controller card since my motherboard (IWill K266-R) only has support for USB1. However, the card seems to conflict with one of my network cards, because traffic on the internet-connected NIC is very slow, and often drops completely. Traffic to and from the other (local) NIC seems to work fine, though.
    I have tried moving around all three cards in different PCI slots, I think I've tested almost every possible combination by now. I've also tried disabling as much as possible in BIOS, such as onboard sound, serial and parallel ports etc. I've tried lowering the FSB.
    For now, I've removed the controller card, and is using the USB1 ports on the motherboard instead. This is very frustrating, though.
    Does anyone have any suggestion on what I can try next? I've browsed forums, both this and others, but I haven't found any more hints on what to try. Could there be some setting in Arch that could affect these sorts of things?

    "I guess the ATA100 card will work fine correct?"
    If you mean large drive support, it may provide that or may require a firmware update to do so. You should check the manufacturer's web site for specifics. All ATA-133 cards do provide 48-bit LBA for large drive support. I'd return the Ultra ATA-66 card to the eBay seller, although many refuse to pay for return shipping, even when the mistake is their own, either through ignorance or deliberate misrepresentation. In cases such as this, it's sometimes more cost-effective to swallow the loss and keep the incorrect part.
    "Will adding a jumper apply for a ATA100 card as well? I'll need a blue and gray ribbon correct?"
    If you use an 80-conductor ribbon cable with color-keyed connectors, set the drive configuration jumper to CS and connect the drives to the cable as you wish (in terms of physical placement in the computer). If the ribbon cable doesn't have color-keyed connectors, set the jumper for the device connected to the end connector as Master and the drive (if any) connected to the middle connector as Slave.

  • I have a MacBook air. I'm having problems with my cursor either I cannot see it or disappears is there anything I can do to fix it

    I'm having a problem with my cursor. It either disappears or I cannot see it immediately. Is there a way to make an adjustment on the display of the curse

    reset SMC , also uncheck and check each setting on the cursor
    SMC reset
    Shut down the computer.
    Plug in the MagSafe power adapter to a power source, connecting it to the Mac if its not already connected.
    On the built-in keyboard, press the (left side) Shift-Control-Option keys and the power button at the same time.
    Release all the keys and the power button at the same time.
    Press the power button to turn on the computer. 
    Note: The LED on the MagSafe power adapter may change states or temporarily turn off when you reset the SMC.

  • Why users with rights defined as View cannots see the data of the form ?

    Hi,
    I have a nice form page. My application has an authorization scheme with an authentification function : return acl_custom_auth. It is working well. I have defined users with Edit, View and Admin rights. Unfortunately on a form, if the user is defined as "View" he cannot see the data, he only sees the item but their content is not diplayed. I don't understand why. I would like him to see the data.
    The authorization scheme of the page is "Access control -view" as well as the items of the page.
    Do you have any idea of what is going wrong here ?
    Thank you for your kind help !
    Regards,
    Christian

    Another thing that can be done though mon tech-savy people may not know about it.
    Locate a group of PDF's and select at least 5-6 of them as a Group.
    hold down Option key while click on file menu
    Click on Get info.
    One window will open for the group.  in Mountain Lion (OSX.8.2) the term will change to Show Inspector.
    click on the  button next to Open With.
    choose either Reader or Acrobat.
    just bellow is a question Use Acrobat (or Reader) to open all files of this type, Click on it and choose yes.
    Make sure you have a mix of Adobe PDF's and Preview PDF/s for  this to work. If it wasn't good for opening other Type Files I'd compress Preview and throw the original away. It’s a nusiance.

  • Why can't I use Snapfish anymore with iPhoto 08? I cannot see the library.

    I recently upgraded to iPhoto (iLife 08) now when I try to upload pics to snapfish it cannot see the folder. I know it is there cause I see it in Finder. It shows all other folders but the iPhoto folder is invisible. Does anyone know a setting or a way that I can utilize photo developing other than the proprietary ones for Apple?
    Please help. I feel like I've been swindled. (Seems Like something Microsoft would do)
    Jeff

    Jeff
    You haven't been swindled, no one is forcing you to do anything.
    With iPhoto 7 (iLife 08) the old iPhoto Library Folder is now a Unix Style Package File. The change was made to the format of the iPhoto library because many users were inadvertently corrupting their library by browsing through it with other software or making changes in it themselves.
    It has never been the correct procedure to root through the iPhoto Library Folder - in fact on every version the documentation has expressly stated that you should never do so.
    There are many, many ways to access your files in iPhoto:
    For 10.5 users: You can use any Open / Attach / Browse dialogue. On the left there's a Media heading, your pics can be accessed there. Apple-Click for selecting multiple pics.
    Uploaded with plasq's Skitch!
    To upload to a site that does not have an iPhoto Export Plug-in the recommended way is to Select the Pic in the iPhoto Window and go File -> Export and export the pic to the desktop, then upload from there. After the upload you can trash the pic on the desktop. It's only a copy and your original is safe in iPhoto.
    This is also true for emailing with Web-based services. If you're using Gmail you can use THIS
    If you use Apple's Mail, Entourage, AOL or Eudora you can email from within iPhoto.
    If you use a Cocoa-based Browser such as Safari, you can drag the pics from the iPhoto Window to the Attach window in the browser.
    Or, if you want to access the files with iPhoto not running, then create a Media Browser using Automator (takes about 10 seconds) or use THIS
    Other options include:
    1. *Drag and Drop*: Drag a photo from the iPhoto Window to the desktop, there iPhoto will make a full-sized copy of the pic.
    2. *File -> Export*: Select the files in the iPhoto Window and go File -> Export. The dialogue will give you various options, including altering the format, naming the files and changing the size. Again, producing a copy.
    3. *Show File*: Right- (or Control-) Click on a pic and in the resulting dialogue choose 'Show File'. A Finder window will pop open with the file already selected.
    All of these are faster and safer than rooting around in the iPhoto Library Folder
    You might also check if Snapfish have updated their plug-in for iPhoto yet? If Snapfish haven't bothered to update their plug-in, you might want to check out many of the other services that have. Or are supported by an app like PictureSync. So, nothing proprietary there.
    Regards
    TD

  • Lion VPN with a Windows 7 client; can't browse network

    So, here's my setup..
    I have a Lion Server running VPN (192.168.1.11 /24), a windows box behind the VPN (192.168.1.15) and a Windows 7 client connecting.
    I've been able to get the Windows 7 client to actually connect to the VPN. I can also manually go to the client machine (i.e. \\192.168.1.15 ), and I've even thought of creating a static hosts entry for the netbios name -> IP, but, while all that works, the simple fact is that I can NOT browse the network using either a mac client OR a windows client.
    DHCP/DNS is being done by the router (A Verizon Actiontec router with a MoCA connection.)
    I COULD get the lion server to serve dns/dhcp for the whole network, but, haven't yet. Lion server uses the router IP as it's DNS (and does not use the local DNS at all). I've tried to both ways though; didn't solve the issue.
    So, is there any way to fix the ability to browse beyond the VPN? Lion does not include (that I can find) a WINS server....
    Lion server is DMZ'd from the router. So, all ports are open.
    Help!

    No one has any ideas on how to fix this?

  • Lion Server VPN dual network cards

    I have a XServe running Lion 10.7.3.  When I connect to the vpn I can only connect to the server and nothing else on the network. How can I set it up to see the whole network?

    Simple. Configure your VPN correctly.
    Of course, you might have done that, but since you're so light on details there's no way for us to know.
    From your description, though, it sounds like you haven't configured the server to hand out the right range of VPN networks. When a client connects, the VPN server sends it a list of networks/subnets to send over the VPN tunnel - e.g. "hi, client, send me all traffic for 10.1.2.0/24".
    If you haven't set this then the the client doesn't know what traffic to send over the VPN vs. sending to the public internet. That's what I assume is going on here, but I could be wrong.
    If you have got the routing correct the next issue would be DNS - have you set the right (internal) DNS server in the VPN server settings, so that the server knows to tell the clients what DNS server to use? If you haven't then the client will continue to use its normal DNS server which likely doesn't know anything about your internal network hostnames. Pinging a resource by IP address rather than hostname would be a simple check for this.
    So check your VPN configuration and report back if that's not a solution. Either way it likely comes down to a configuration error on the server.

  • My power mac g4 with wireless card 801.11b cannot log into new AirPort Extreme 801.11ac network

    everything worked until I upgraded to airport extreme. I used all same settings as with previous extreme al other items logged in to new network, but would not accept power mac. Apple wireless card 801.11b may not be able to communicate with AC standard. Can anyone suggest an upgrade card or means of getting the power mac on the wireless network to communicate with various wireless printers

    Hello!
    I have noticed that some manufacturers (Linksys and possibly D-LINK) only accept upper-case WEP keys only.
    This drove me nuts when trying to integrate a Linksys PC PCMCIA card into my old "g" network.
    As far as using WEP, it's bad and broken; but I understand that your choice of security is limited to the devices that you are trying to network.
    For what it's worth, I have my network set up with the AEBS 'n' connected to my Cable Modem, with one of the ports going to a gigabit switch for my wired network. I then have two AirTunes set up as WDS extensions for music & Internet delivery to two separate areas. The AEBS 'n" serves up DHCP and routing for the entire network.
    It works quite well; I get 54 mbits/sec for the two WDS AirTunes, and 145 mbits/sec to one of my ATV's. My gigabit wired machines see data rates of 15-27 MBytes/sec (depending on the type of transfer).
    Good luck!

  • VPN client cannot access Lan

    Hi,
    I can connect via VPN to my ASA 5505 but I cannot access my asa. I do not quite understand the routing,acl and nat configs I would need.
    attached is my config

    Here is the my config

  • PC based client cannot see keyword tags on my exported JPEGs, PC based client cannot see keyword tags on my exported JPEGs

    Hey,
    Im having a very wierd problem that I can't quite get my head around and would appreciate some help!
    I am delivering exported JPEGs from Aperture to a client workning in a PC environment. These photos are all Keyworded, and these keywords show up when i click the "get info" button on the exported files. Also, I was asked to double check using Adobe bridge, and low and behold, all tags are there, I can see them, and so can anyone else with a mac. (and yes I did select the embed metadata in exported files button on export!)
    The problem is that when they move to the PC environment, noone can see these tags. This is a huge problem, as I am delivering around 1,000 photos to be archived in a smart database that uses the tags to sort the photos.
    HELP!

    The Keyword, as with Captions (Description in Photoshop) is not found in file properties, but must be seen with  true photo app.  OSX does provide that in a Get Info window, but that will not necessarily be true in other operating systems.  Knowing the apps they have used to search for the Keyword is important.
    Ernie

Maybe you are looking for