FN,
Thanks for the ideas to consider. Here are my responses:
- I had wondered about the IP issue. The client is attempting to contact 12.133.x.x, but the DSR-250N has a WAN IP of 10.1.x.x because it is connected to another network switch. Does that mean it will never work?
- Yes, the server is behind NAT, with everything forwarded. That's what the NAT-T setting (on both server and client) is for, right? The client is not behind NAT.
- I verified the PSK. I don't have any certificates.
- I did set it to use ESP, not SA. I had tried SA in the past but some other settings were different. So this is something to try again.
- I did try without any firewalls, but that didn't change anything.
So I guess the concern is: can we ever have clients connecting over VPN if the WAN IP on the VPN server is not the same as the external (inbound) static IP (i.e. when we are using NAT)?
BUT, unfortunately this is all moot now, since the DSR-250N fried this afternoon. It's the second one in two weeks to do that, so it's going back to be replaced by something else. We'll still want to use VPN, so I have definitely learned a lot that I can try in the future. But it will be with different hardware.
Please do let me know if you think VPN won't be possible with our current setup (through another network). But for now I'll consider this case closed because I can't test anything else.
Thanks!
-M