DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

VPN Routing with multiple remote networks

  • andylamb
  • Topic Author
  • Offline
  • New Member
  • New Member
More
27 Feb 2013 10:38 #1 by andylamb
Hi,
I've setup a vpn using a 2710 to an ASA. My config within the vpn part has a new of remote networks, my local network is 192.168.27/24 and I have a remote networks of 192.168.xx/24 and 10.100 xx/24. The tunnel comes up ok phase 1 and 2 are fine but I have a major routing issue, any networks that exist in the 'more' option I'm unable to route to.

On the main screen where you have tcp/ip network settings, you have my wan ip, their gateway etc The configured remote network IP within that screen I can route to. ie if I confiure it with 192.168.128/24 i'm able to get to devices on that network. But I've added 10.100.51/24 to the more network and I can't route to this. If I swap these around and place the 10.100.51/24 on the main screen and 192.168.xx.xx in the more option. The 10 works and the 192 stops. The routing table shows those subnets to go down the tunnel and all look fine...
Can anyone help?
Thanks
Andy

Please Log in or Create an account to join the conversation.

More
27 Feb 2013 11:00 #2 by voodle
It's complicated unfortunately - the drayteks pass multiple subnets in a different way from cisco routers, the draytek routers pass multiple subnets through a single subnet SA (configured from the main VPN profile), it's not possible to add subnets to the SA. They're effectively applying a static route to the VPN tunnel.
The cisco routers are different in that they can have multiple subnets in a single security association and pass them through that way.
The way around it is to make multiple security associations (aka vpn tunnels) from the draytek to the cisco to get those other subnets or set up the cisco so that it will allow the multiple subnets to pass through a single subnet's security association.

Hopefully I'm right on this, but that's how it's worked when I've come across it previously.

Please Log in or Create an account to join the conversation.