DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Allowing Incoming Traffic on VPN Client IP (Public IP)

  • ahem
  • Topic Author
  • User
  • User
More
13 Jul 2016 16:46 #1 by ahem
Hi All,
I am stuck in a problem and need some help.
I am using Draytek 2925ac and have a VPN Subscription with dedicated IP from PureVPN.
Router is configured with LAN to LAN Dial out VPN which is always on. PureVPN allocates public and dedicated IP.
There are services in LAN like my NAS, WebServer which I want to access from Internet using public IP (from PureVPN)

So my router gets 1 WAN IP from Virgin, 1 public IP from PureVPN.
NAT > Port Redirection is set from Any Source to LAN Client 1 for port number N
NAT> Port Open Setup for LAN Client 1 for port number N
Firewall> Default rule "Pass" (Firewall is factory default not disabled/enabled anything)

With all above in place and VPN Connected. Using website "ping.eu/port-chk" I am testing whether port N is open
> for WAN IP by Virgin : Result is "port is open"
> for Public IP by PureVPN : Result is "port is closed"

It seems incoming traffic with destination as public IP is getting blocked. Not sure if it is being sent to gateway on PUREVPN
I was expecting that since public IP is on router, all traffic should be forwarded to LAN Client 1
For that matter even router admin port 80 is showing closed on VPN Client IP where open on WAN IP.

Can some one help how to get this resolved.
For PPTP configuration I have just used following config:
Username, password and host address of Pure VPN
Dial Out + Always On
RIP Redirection Disabled
From first subnet to remote network, you have to do: NAT (It is not Route)
Rest is all default
My WAN IP 0.0.0.0
Remote Gateway IP 0.0.0.0
Remote Network IP 0.0.0.0
Remote Network Mask 255.255.255.0
Local Network IP 192.168.1.1
Local Network Mask 255.255.255.0

Please Log in or Create an account to join the conversation.

More
14 Jul 2016 13:46 #2 by admin3
Try IPsec instead and update the firmware. As far as I'm aware, passing port forwarded traffic across a VPN is possible but it requires the current firmware (check the release notes) and may be DrayTek specific potentially.



Forum Administrator

Please Log in or Create an account to join the conversation.