DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

2830 VLAN cannot access VPN or Remote Management

  • gcunning
  • Topic Author
  • Offline
  • New Member
  • New Member
More
09 May 2013 00:12 #76118 by gcunning
Hi
I have set up a 2830 with 2 Lans,
192.168.8.0 (the corporate Lan) no DHCP - servers and PC's connected
192.168.2.0 (The Guest LAN) with DHCP - WIFI AP's connected

The object is to keep the guests away from the corporate lan.

I have set the VLAN's to go to physical ports, The corporate to port 1 and the guest to 2,3 and 4

It all works internally, the correct IP addresses are issued to the correct LAN and access is available to the internet.

When I try to remote manage the system or connect to a VPN which is set up to LAN1 I am just ignored, no errors, nothing.

I have been reading about this tonight. Is it because I only have 1 public IP address from my provider. I am only interested in connecting to the first VLAN.

Hopefully someone will be able to provide some hints, as I have run out of ideas.

Thank you

Please Log in or Create an account to join the conversation.

  • gcunning
  • Topic Author
  • Offline
  • New Member
  • New Member
More
09 May 2013 08:29 #76120 by gcunning
SOLVED: Although it was an idiot mistake working too late, I will explain it in case anyone else falls for it.

I was removing a BT Business Hub. If you read various forums on the internet you do not need to provide the hub with a username and password to connect to BT Business. This is partially correct, it will work without a username and password, but account features such as fixed IP are not applied consistently.

So I put my BT username and password in and all is good.

Please Log in or Create an account to join the conversation.

More
27 Jun 2013 08:54 #76809 by dushami
Glad you solved it, now perhaps you can help me with that exact config! My corporate LAN PCs will lose connectivity after a few hours. I can't work out exactly why & it's driving me nuts. My vlans are to physical ports - vlan0 to 1&2, vlan1 to 3&4. Wifi Access points are on vlan1. I suspect that this is a DNS issue. I have no firewall rules setup right now, just default. My LAN clients are fixed IP & I've tried using the router IP 192.168.2.1 as dns, BT's server & google (8.8.8.8). My "wifi" clients use the router IP 200.1 as dns & gateway. The wifi clients never lose connectivity & I can always VPN to he router & try to see what's going on. Can you share those simple parts of your config please? I feel I'm going round in circles with what should be a straightforward config.

Thanks
Scott

Please Log in or Create an account to join the conversation.

  • gcunning
  • Topic Author
  • Offline
  • New Member
  • New Member
More
27 Jun 2013 09:31 #76810 by gcunning
More than happy to share my configs, or we can share a remote session and you can have a look.

Are you loosing broadband connectivity or is it the network just resets itself? I have a problem that some VPN clients cause the rooter to reboot. I am available this afternoon if you want to copy my config. email is giles at crackingit.co.uk

Please Log in or Create an account to join the conversation.

  • gcunning
  • Topic Author
  • Offline
  • New Member
  • New Member
More
27 Jun 2013 09:38 #76811 by gcunning
If you suspect it is DNS then my setup is.

LAN0 Corporate LAN - Subnet 192.168.8.0 DNS 192.168.8.15 (A windows 2008 server) DHCP server 192.168.8.15
LAN1 Public LAN - Subnet 192.168.2.0 DNS BT Broadband DHCP server is the Draytek.

The wifi clients are on AP's my router is not an n. DHCP capability is disabled on the APs, with either the server or the router providing DHCP depending on the LAN connected to.

Please Log in or Create an account to join the conversation.

More
27 Jun 2013 09:56 #76812 by dushami
Thanks Giles, that's pretty much as I've configured it. Of course, all this surfaced on the very day that I'm going on holiday for two weeks! They kept it quiet for 3 weeks....
I've just VPN'd into the box & shutdown the Unifi Access points & removed the wifi vlan. I'm just going to have the corporate PCs using this box until they get their work done this morning (y'know, wages etc!). Thanks for the offer. I'll pick this up again when I get to my destination.

Please Log in or Create an account to join the conversation.

Moderators: ChrisSami