Members Login
Username 
 
Password 
    Remember Me  
Post Info TOPIC: SecureClient FP3 and broadband


Status: Offline
Posts: 7
Date:
SecureClient FP3 and broadband


Hi Gurus


I have got Secureclient working with broadband, where the ADSL router is assigns 192.168.1.x to my client, i'd like it to work using a 10.0.0.0/24 address as this is a default for this device, does this conflict the RFC 1918??, when ever i try to connect to the policy server, i get the error message communication with gateway failed. But i have no problems connecting when i make the assigned address 192.168.1.x, on each occassion these address ranges are NAT to a routable address, i have also tried enabling office mode but this doesn't make a difference


any suggestions pls



__________________


Status: Offline
Posts: 4
Date:

Seeing as how rfc 1918 describes the networks 10.0.0.0/8 as well as 192.168.0.0/16, using it certainly shouldn't go against the rfc. Could you be hitting a conflict with your internal network? If you are trying to use 10.1.1.0/24 on your home connection, and your protected network is trying to protect 10.1.0.0/16, I think your firewall will have problems routing packets back to you.

We got around that problem by creating an ip pool for vpn clients, and assigning internal addresses from that pool. (look on the NAT tab for your firewall configuration.)

__________________


Status: Offline
Posts: 7
Date:

Hi thanks for your posting, we already have a an IP pool configured for office mode users on the 172.16.x.x, have you got ideas as to how i could sorting out the routing problems with the addresses 10.0.0.0/8 and 10.0.0.0/24


thanks


A



__________________


Status: Offline
Posts: 4
Date:

If your firewall is assigning your vpn client from the 172.16 network range, I wouldn't think it is a routing problem any more. The only residual problem we have had with ip addresses as assigned by remote devices is that _even_though_ the firewall is properly natting the incoming vpn connections, if it sees a second vpn connection with the same rfc 1918 address in use (on the far end), it dumps the first user (and logs it).

We're not using office mode, so I can't speak to what might account for the different behavior between your setup and mine.

__________________
Page 1 of 1  sorted by
 
Quick Reply

Please log in to post quick replies.

Tweet this page Post to Digg Post to Del.icio.us


Create your own FREE Forum
Report Abuse
Powered by ActiveBoard