DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

VPN Incoming Connections

  • allawishous
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
26 Apr 2017 12:28 #1 by allawishous
VPN Incoming Connections was created by allawishous
Hi All,


I just setup my Vigor 2860Ln with a VPN service (PureVPN) and I can not get incoming connections to work from the outside world.
To keep a long story short, the only way to get a Static IP on our 4G LTE connection is to use VPN with a static IP and open ports.
But for testing purposes I am just trying to get this going on our ADSL which already has a static IP.

I have no issue with connecting to the ports which forward to windows client machines from the outside world when the VPN is not connected, but when it is connected they wont go through.
The issue does not seem to be the actual VPN service. As this is setup with a static ip and all ports forwarded. I have checked this, when using the VPN just on a client machine rather than the Vigor Router, then you can connect from the outside world.

Screenshots are linked below of the settings, I am just routing all VPN traffic in and out from my client machine (192.168.1.2). I can ping, browse etc to the outside world, just I cant get incoming connections to pass to the client machine.

Please help, I have tried so many settings.












Thanks in advance!


Chris

Please Log in or Create an account to join the conversation.

  • allawishous
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
26 Apr 2017 12:58 #2 by allawishous
Replied by allawishous on topic Re: VPN Incoming Connections
**UPDATE**

I have managed to track down what seems to be the problem, but not sure how to solve. It doesnt seem to route the incoming connection properly over VPN. See the image below of the firewall syslog.

It routes to 192.168.1.2 when going to the ADSL ip, but not when to the VPN IP , from the outside world.

Any ideas?


Please Log in or Create an account to join the conversation.

  • allawishous
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
26 Apr 2017 13:15 #3 by allawishous
Replied by allawishous on topic Re: VPN Incoming Connections
**2nd UPDATE**


I think I have solved the issue. It seems that for WAN1 (ADSL) incoming connections are forwarded fine using "NAT>Open Ports", but for VPN incoming connections you have to setup "NAT>Port Redirection" also..
Is that correct?

Please Log in or Create an account to join the conversation.

More
27 Apr 2017 16:12 #4 by fryr
Replied by fryr on topic Re: VPN Incoming Connections
Can you not use a dynamic DNS service so that your external WAN IP Address, even though it changes, is accessible from a static DNS name that the router is updating automatically?

Please Log in or Create an account to join the conversation.

  • allawishous
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
03 May 2017 16:43 #5 by allawishous
Replied by allawishous on topic Re: VPN Incoming Connections

fryr wrote: Can you not use a dynamic DNS service so that your external WAN IP Address, even though it changes, is accessible from a static DNS name that the router is updating automatically?



Unfortunately not. On Vodafone UK you are behind CGNAT (http://www.donaldsimpson.co.uk/2016/10/24/tunneling-out-of-carrier-grade-nat-cgnat-with-ssh-and-aws/), so the only real way I found is using a VPN service.

As everything is working for me, the only question I still have outstanding was how I resolved the issue and was it the correct way....
"It seems that for WAN1 (ADSL) incoming connections are forwarded fine using "NAT>Open Ports", but for VPN incoming connections you have to setup "NAT>Port Redirection" also..
Is that correct?"

Please Log in or Create an account to join the conversation.