• May 08, 2025, 04:02:02 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: VPN - DMZ - how to make it all work?  (Read 6131 times)

chrysalid

  • Level 1 Member
  • *
  • Posts: 12
VPN - DMZ - how to make it all work?
« on: October 14, 2011, 10:20:41 AM »

Hello,
I have a client that is using a DIR-655 router.
He uses Cisco VPN to access his work PC.
At first, the only way we could get this to work was by skipping the router and plugging directly in to the modem.
This is not ideal - so after receiving no response here to this question - I did the following - I put his PC (by IP) in a DMZ.
This has done the trick - but will only work until the next time his IP address changes.
Is there another (more permanent) fix?
Thanks,
Amber
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: VPN - DMZ - how to make it all work?
« Reply #1 on: October 14, 2011, 10:35:07 AM »

Can you set his PC up for a reserved IP address so it doesn't change? I recommend doing this for all devices regardless. Helps maintain a constant IP address and helps some in troubleshooting and wont break options and rules on the router should they change while using DHCP.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

chrysalid

  • Level 1 Member
  • *
  • Posts: 12
Re: VPN - DMZ - how to make it all work?
« Reply #2 on: October 14, 2011, 11:43:35 AM »

Is that different from a static IP?
If so - I'm not sure how to do that...
This is a work laptop - so when he takes it to his office, his IP addy changes - when he gets back home, there are others on his network - so he doesn't always get his same IP.

Thanks!
Amber
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: VPN - DMZ - how to make it all work?
« Reply #3 on: October 14, 2011, 12:04:32 PM »

Well you can reserve or make a Static IP address on the 655 router for when the LT is at home. Can his IT department do the same thing when he's at work?
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

Hard Harry

  • Guest
Re: VPN - DMZ - how to make it all work?
« Reply #4 on: October 14, 2011, 05:28:16 PM »

Well you can reserve or make a Static IP address on the 655 router for when the LT is at home. Can his IT department do the same thing when he's at work?

Why do so many people have such horrible IT's? It amazes me. Not your fault, just saying the horror stories I could tell.

Need alot more info:
Is it a Cisco VPN unit? Like something you plug in? Or a client(software)? What does it use? PPPTP? IPSec? Does he require a static IP? What ports does it use? Does he require a code from a little key chain like thing?
Logged

chrysalid

  • Level 1 Member
  • *
  • Posts: 12
Re: VPN - DMZ - how to make it all work?
« Reply #5 on: October 14, 2011, 06:46:49 PM »

The VPN access is done with Cisco's software client.
IPSec.
He doesn't require a static IP.
I'm not sure about the port - where would I find that out?
He doesn't use a little key chain like thing :)
Logged

Hard Harry

  • Guest
Re: VPN - DMZ - how to make it all work?
« Reply #6 on: October 14, 2011, 07:21:29 PM »

Well the same people who gave your the VPN software should have provided you with some settings and requirements.  But anyway..

1. Make sure you set a DHCP reservation.
  • [Setup > Network Settings]
  • Look under "Number of Dynamic DHCP Cliens" and choose his. You can usually tell by host name. If not, turn every other device off except his.
  • Click Reserve and his info should come up under "Add DHCP Reservation" and click Save
  • Click on save settings up top.


2. Turn down Firewall.
  • [Advanced > Firewall Setting] Make sure UDP and TCP Endpoint Filtering is set to Endpoint Independent.
  • Make sure IPSec is checked under ALG configuration.


3. Make sure his laptop is connecting wired. Sometimes the client software only installs on the local area connection IPStack.

4. Turn off securespot. [Advanced > Securespot]

Try it that way, with the computer out of the DMZ. If it doesn't work, there are specific ports you need to open, and must contact your work's IT[/list]
Logged

chrysalid

  • Level 1 Member
  • *
  • Posts: 12
Re: VPN - DMZ - how to make it all work?
« Reply #7 on: October 18, 2011, 04:01:10 PM »

Ok - thanks for all your help!

I set up this laptop with a DHCP reservation (I assume it will always have the current IP address of 192.168.0.100)?
I made the first suggested change to the firewall. The 2nd item (IPSec) was already checked.
I couldn't find the Securespot to turn off...
But after doing all this - VPN wouldn't work.
Once I put the laptop back into the DMZ it worked...

What do I try next?

Thanks :)
Amber
Logged

Hard Harry

  • Guest
Re: VPN - DMZ - how to make it all work?
« Reply #8 on: October 19, 2011, 12:03:21 PM »

You need to contact your IT. We need more info about your network and VPN configuration to help. Even if you have to contact a supervisor or something, they should be helping you more.
Logged