setting up VPN through 2 routers

mibo01

Honorable
Apr 26, 2015
6
0
10,510
I used to be on Comcast and that worked fine until a couple of months ago the latencies started to climb, and my VoIP was barely usable. One party would often drop out for 10-20sec, and the communication sounded like the Verizon guy: "Can you hear me now?"
So I am trying Centurylink right now (the only 2 choices here). The came and installed line and modem ("bonded pair"), and when they left, I had Internet, VoIP, etc. Not sure yet how well that all works. I do have a problem with VPN, though. It is not working. I need it for work and also if I need to access my network from the outside.
The system now consists of the cable modem, connected to a NetGear SafePro firewall and router, and from there into my network. The first thing I noticed was that the cable modem and the Netgear router had the same IP address (192.168.0.1), and both were set up as DHCP server. I tried to disable the cable modem as DHCP router, which killed my internet connection. At the moment, the cable router is set up as 192.168.1.1 and as a DHCP router. The Netgear router has an IP address of 192.168.1.200 on the WAN side, and acts as a DHCP router on the 192.168.0. segment on the LAN side. This seems to work, as I am writing this from within my network :)
But how do I get the VPN established to my Win2011 SBS Server? I can ping it from the outside (IP address through no-ip.org), but I can't establish a VPN tunnel. The cable has a "VPN" option where I can define a target for the VPN traffic, but if I user the internal IP for the server, it tells me that is is an invalid address (it's on the 192.168.0 segment while the modem is on 192.168.1). Specifying the second routers IP address (192.168.0.200) is accepted, but doesn't work.

Sorry for the long post, but where can I find clear information how to set this up?

Thanks for your help.
 

mibo01

Honorable
Apr 26, 2015
6
0
10,510
Thanks, John, but that doesn't seem to work. I forwarded 1723 (both TCP and UDP) to the netgear router, and from there (TCP only) to the server. No luck. I know that the netgear router works, because I have no problems if I connect it to my Comcast modem. Although Comcast had to do something to enable it also. Do I need to open other ports as well? The cable modem has some settings to forward protools (VPN PPTP, for example), which I am also all forwarding to the netgear box. Still nothing.

Yes, I am doing double NAT at the moment for convenience. The Netgear box does the DHCP and everything is set up that way, and since I am trying a few things, I didn't want to change too many parameters at the same time ...

There is a way to set the modem to "transparent" mode, and I might try that, but I will need Centurylink on the line for that as I will have to set up the netgear box to connect to Centurylink directly.
 

mibo01

Honorable
Apr 26, 2015
6
0
10,510
Hi John, appreciate your feedback. I just set the modem to pass-through (they call it a "transparent bridge"), used my netgear router to log in, and presto - VPN.
The static IP address is not a problem as I have the server registered with no-ip.org, and they keep it registered with the dynamic IP from Centurylink. So far, no issues with that.