DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

VPN Account to use a specific IP address

  • coderus
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
28 May 2009 16:08 #1 by coderus
Hi,
Is there was to setup a VPN account so that when it appears on the local network you can specify the IP address which a particular account has. The reason why is that I would like to control which each VPN account can get access to, or put them on a separate VLAN or subset (or both).

As the minute I see different IP addresses being given to the same account (on the same machine). I was initially hoping that DHCP and MAC address sticky feature would work but VPN devices don't seem to appear in the list. Or if the device is on LAN it's IP address isn't mirrored when its VPN's in.

Thanks

Please Log in or Create an account to join the conversation.

More
28 May 2009 17:37 #2 by louis-m
Replied by louis-m on topic VPN Account to use a specific IP address
i was after this on a 2950 but it simply doesn't support it. you need a /24 network for the router to work for vpn's. i could however, restrict what entered the tunnel from the other end (linksys) although its not ideal.
i can port base vlan my lan but i can't restrict incoming hosts to a certain part of it. the ssl side of it is good for this though!
to restrict via ipsec vpn and vlans, you may have to invest in a 3300.

2820 = 3.3.2_RC5
2950 = 3.2.4

Please Log in or Create an account to join the conversation.

  • macavity
  • User
  • User
More
29 May 2009 16:16 #3 by macavity
Replied by macavity on topic Assigning IP to Dial In User
Do you mean for a dial in PPTP user?

If so, yes it can be done but not with the Remote Dial-in User menu.

The LAN-to-LAN Profile menu can be adapted to be used for a single use dialing in.

Set:

Common Settings
===========
- Call Direction - IN

Dial IN Settings
==========

- PPTP checked
- Set Username
- Set Password
- (If required) tick "Specify Remote VPN Gateway" and put in the IP that the dial-in user is originating from

TCP Network Settings
==============
My WAN IP = 0.0.0.0
Remote Gateway IP = 192.168.1.XXX ( xxx is what ever IP you want to assign to user)
Remote Network IP = 0.0.0.0
Remote Network Mask = 255.255.255.255

Please Log in or Create an account to join the conversation.