DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Routing Port Over IPSec
- thekingster
- Topic Author
- Offline
- New Member
Less
More
- Posts: 8
- Thank yous received: 0
03 Nov 2012 14:26 #74015
by thekingster
Routing Port Over IPSec was created by thekingster
Hi
I have an IPSec setup between 2 offices and all of our clients servers are restricted to our main office IP address for RDP. I want my workers in the sub office to connect down the IPSec tunnel when using port 3389 RDP rather than out the office default gateway. I have tried a few things but to no avail.
Can anyone provide any pointers?
Thanks
Dave
I have an IPSec setup between 2 offices and all of our clients servers are restricted to our main office IP address for RDP. I want my workers in the sub office to connect down the IPSec tunnel when using port 3389 RDP rather than out the office default gateway. I have tried a few things but to no avail.
Can anyone provide any pointers?
Thanks
Dave
Please Log in or Create an account to join the conversation.
- thekingster
- Topic Author
- Offline
- New Member
Less
More
- Posts: 8
- Thank yous received: 0
17 Nov 2012 00:31 #74233
by thekingster
Please Log in or Create an account to join the conversation.
- jedi98
- Offline
- Member
Less
More
- Posts: 186
- Thank yous received: 0
19 Nov 2012 15:33 #74267
by jedi98
Replied by jedi98 on topic Re: Routing Port Over IPSec
Not as easy as you might think.
From what you say I guess that you are doing: -
And what you are trying to do is:-
Trouble is I don't think that you can because you cannot redirect addresses in>>out and you cannot redirect across vpn (AFAIK).
Can you not get the client users at the sub office to use private ip:3389 (eg. 192.168.1.13:3389) instead of public ip:3389? Or internal DNS name if you have internal DNS?
From what you say I guess that you are doing: -
Code:
/- -\
Sub-office / \
RDP User (public ip:3389) --(lan)--> Router --< >--> Router --(lan)--> RDP Service
\ /
\-(internet)-/
And what you are trying to do is:-
Code:
/----IPSEC---\
Sub-office / \
RDP User (public ip:3389) --(lan)--> Router --< >--> Router --(lan)--> RDP Service
\ /
\- -/
Trouble is I don't think that you can because you cannot redirect addresses in>>out and you cannot redirect across vpn (AFAIK).
Can you not get the client users at the sub office to use private ip:3389 (eg. 192.168.1.13:3389) instead of public ip:3389? Or internal DNS name if you have internal DNS?
Please Log in or Create an account to join the conversation.
- asimm.it
- Offline
- Member
Less
More
- Posts: 156
- Thank yous received: 0
20 Nov 2012 19:01 #74286
by asimm.it
Replied by asimm.it on topic Re: Routing Port Over IPSec
only way it can work is as jedi has outlined.
any traffic for the remote lan will route down the vpn tunnel if you use the private lan ip addresses from remote desktop.
I would assume that this is what is happening anyway if you are connecting to more than one pc on the remote network, that is unless you have multiple public ip addresses and port forwarding mapping to individual pc's on port 3389.
any traffic for the remote lan will route down the vpn tunnel if you use the private lan ip addresses from remote desktop.
I would assume that this is what is happening anyway if you are connecting to more than one pc on the remote network, that is unless you have multiple public ip addresses and port forwarding mapping to individual pc's on port 3389.
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek