Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

IPO gateway addresses for LAN1 & LAN2 (WAN) 3

Status
Not open for further replies.

testman1

Vendor
Oct 7, 2007
135
US
I have an IPO R8.1.
In the IPO can anyone tell me where to put the gateway addresses for both LAN1 & LAN2 (WAN)

My LAN1 network is 192.168.10.0 with a gateway of 192.168.10.1
My LAN2 (WAN) is 192.168.20.0 with a gateway of 192.168.20.1

Thanks.
 
Does anyone have an example of what the IPO IP Routes would look like if I were using both LAN1 & LAN2?

Thanks
 
Yes, the "Help" file in that window will tell you all you need to know, it's very easy :)

 
ip adress 0.0.0.0
mask 0.0.0.0
gateway 192.168.10.1
LAN 1

all ip destination will be routed via LAN 1 gateway..

 
The system like any device can't have 2 default gateways, it can route all or certain ranges out one interface or the other, but only one can be the default for all unknown traffic :)

 
This is my existing configuration:
I would like all unknown traffic to go out on LAN2. LAN2 has a static ip address connected directly to the Internet. (I am only using the 192.168.20.0 network as a stand-in for my question).

The IPO static ip address for LAN1 is 192.168.10.2
The IPO static ip address for LAN1 is 192.168.20.2

ip route:
ip address: 0.0.0.0
subnet: 0.0.0.0
Gateway ip address: 192.168.20.1
Destination: LAN2
Metric: 0

Under this setup everything works fine except when I use a VPN connection from a remote laptop to connect to the 192.168.10.0 network, I can't ping from the VPN connected laptop to the IPO LAN1 ip address (192.168.10.2). I get no reply.
The whole reason for this is I would like to use a IPO SIP Softphone on the remote laptop, but since I can't ping the IPO LAN1 ip address (192.168.10.2) I can't get it to work.

The only reason I have the LAN2 connected to the Internet is so that I can have a 9608 H.323 telephone connect to the IPO without going through a router; this works great.

Any help would be greatly appreciated...
 
The gateway address should be the next hop out from the system, not the systems own address (it already knows this), so it's usually the ISP's router address :)

 
Ps don't leave it on the internet directly, it may seem like a good idea or the only way round an issue, but it WILL be port scanned and then subsequently hacked....seriously, it will :)

 
I was hacked with SIP so I shutdown SIP on the LAN2(WAN). It was just a stupid password mistake on my part.

All that being said, non of this is a good idea, but I just can't get SIP to work through a VPN.
When I shutdown the LAN2(WAN) and just use the internal LAN1 I can then get the SIP softphone to work through the VPN, except the audio doesn't work.

This is tough stuff...
 
No audio is the routers blocking/changing the SIP ports, don't let it open yourself up to hacking again, for example all they need to do is connect phone manager, then they have the user list. Then they just need to guess user passwords (if you even have any set) and then they can call anyone and transfer anywhere or forward the user wherever they like, it's not worth it. It will cost you less to buy decent routers than pay for the bill they will rack up :)

 
your VPN might have a different IP range then 192.168.10.x
so make sure that you point the VPN range to the proper LAN1 gateway. Assuming 192.168.30.x is your VPN range that gets assigned then the IP route would be

192.168.30.0
mask 255.255.255.0
192.168.10.1
LAN1

this way all traffic for the VPN range will get sent out over the LAN1 gateway and not the LAN2 gateway

if this doesn't work right away reboot the system as I have noticed that sometimes the IP routes do not work properly until rebooted (sucks and is not in the manual that I can tell but true)

But if that is not working then your router is probably no good like amriddle01 mentioned

Joe W.

TeleTechs.ca
FHandw, ACSS (SME), ACIS (SME)


“This is the end of the world, make sure to buy your T-shirt before it is too late"
Original expression of my daughter
 
Westi (Joe W.)
Thanks. That was it! I had to do one other thing in the Netgear VPN client, but you sent me in the right direction.

It is very much appreciated...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top