I have a dsl modem connected to a wan interface of a wifi router
/acces point ....the public ip 80.x.x.x is assigneed to the wifi AP
wan interface - dsl modem is transparent no firewall rules on it -
in the lan interface is connected a vigor2200plus vpn router so we
have this situation
80.x.x.x-->wifi wan-->192.168.10.2 wifi lan--->192.168.10.1
draytek2200 wan-->192.168.0.1 draytek lan
using the wireless interface i have made a vpn tunnel between two
branches using various access points and in the end there is another
draytek with wan 192.168.10.20 and lan 192.168.40.1
so we have the head subnet 192.168.0.0 and branch 192.168.40.0
configured the vigor in brach to accept - dial in - conecction from
branch draytek (lan to lan)
connection betwenn branches is ok
i can ping internal servers from host 192.168.40.5 to 192.168.0.100
even i have made the default route that of the tunnel so i can route
the internet traffic that is in the first ap that has the conection to
internet through the vpn tunnel !
so in the branch i can connect internet as well using the vpn tunnel.
i want to remotely control using pcanywhere (tcp & udp ports) so i
redirected in the first AP to point the head draytek for example
public : 5631 to 192.168.10.1 5631 tcp
public5632 to 192.168.10.1 5632 udp
then in the draytek
5631 to 192.168.0.33 5631 tcp --> host to be controlled
5632 to 192.168.0.33 5632 udp--> the same
and then this works ok i can enter that pc ok
NOW, i want to have access to the pcs in the 192.168.40.0
subnet........problem
i have no option in the redirection because the pcs are in other
subnet.....
in the branch the draytek has no default gateway configured in the wan
interface and i did that because in that way i could have cheked the
default gateway in the vpn tunnel configuration
so i have this situation
from head i can ping host 192.168.40.5
but i cannot redirect a packet coming from outside to it but packets
going from branch to internet - passing through head draytek -come
back without problem
You are about to answer a thread that has been inactive for more than 6 months. If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.