ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite

    IT Discussion
    edgerouter lite ubiquiti vpn remote access site-to-site
    5
    29
    3.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • EddieJenningsE
      EddieJennings @wirestyle22
      last edited by

      @wirestyle22 said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

      @eddiejennings Control Panel > Sync Center > Manage Offline Files > Disable Offline Files

      Test that just to see. You will need to reboot.

      That seemed to work. Enabling it again prevented me from accessing DFS shares.

      1 Reply Last reply Reply Quote 0
      • EddieJenningsE
        EddieJennings @Dashrender
        last edited by

        @dashrender said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

        So what happens when you ping domain.com?

        Couldn't find a host.

        1 Reply Last reply Reply Quote 0
        • JaredBuschJ
          JaredBusch @EddieJennings
          last edited by JaredBusch

          @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

          The next challenge was being able to access the colo's ERL from the office. To do this, I had to add a rule to the WAN_LOCAL ruleset on the Colo's ERL, to allow traffic tp TCP 22 and 443 from 192.168.2.0/24. I had to do the same for 192.168.1.0/24.

          Or you could just allow new from IPSEC packets.

          0_1514322954976_03d90969-cace-4b2d-9cff-42f39d2b4b09-image.png
          0_1514322980770_bafb915f-975c-4fd1-8255-2556f2e33032-image.png

          0_1514323099109_beea765b-5545-4b9d-91cc-c414ca735729-image.png

          jbusch@jared:~$ show configuration commands firewall | grep "rule 40"
          set firewall name WAN_LOCAL rule 40 action accept
          set firewall name WAN_LOCAL rule 40 description 'Allow IPSEC'
          set firewall name WAN_LOCAL rule 40 ipsec match-ipsec
          set firewall name WAN_LOCAL rule 40 log disable
          set firewall name WAN_LOCAL rule 40 protocol all
          set firewall name WAN_LOCAL rule 40 state established disable
          set firewall name WAN_LOCAL rule 40 state invalid disable
          set firewall name WAN_LOCAL rule 40 state new enable
          set firewall name WAN_LOCAL rule 40 state related disable
          
          1 Reply Last reply Reply Quote 3
          • wirestyle22W
            wirestyle22
            last edited by

            @EddieJennings did you resolve your issue?

            EddieJenningsE 1 Reply Last reply Reply Quote 0
            • EddieJenningsE
              EddieJennings @wirestyle22
              last edited by

              @wirestyle22 said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

              @EddieJennings did you resolve your issue?

              Most likely so. It appears that offline files is the clue I needed. I can do some more testing tomorrow.

              wirestyle22W dbeatoD 2 Replies Last reply Reply Quote 1
              • wirestyle22W
                wirestyle22 @EddieJennings
                last edited by

                @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                @wirestyle22 said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                @EddieJennings did you resolve your issue?

                Most likely so. It appears that offline files is the clue I needed. I can do some more testing tomorrow.

                Awesome

                1 Reply Last reply Reply Quote 0
                • dbeatoD
                  dbeato @EddieJennings
                  last edited by

                  @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                  @wirestyle22 said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                  @EddieJennings did you resolve your issue?

                  Most likely so. It appears that offline files is the clue I needed. I can do some more testing tomorrow.

                  YOu don't use Offline files though right?

                  EddieJenningsE 1 Reply Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender
                    last edited by

                    It seems odd that performance would be an issue here. When accessing files you want the most live, up to date files, so as long as you have access, you should be getting them from the server.

                    What am I missing here.

                    1 Reply Last reply Reply Quote 0
                    • EddieJenningsE
                      EddieJennings @dbeato
                      last edited by

                      @dbeato said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                      @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                      @wirestyle22 said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                      @EddieJennings did you resolve your issue?

                      Most likely so. It appears that offline files is the clue I needed. I can do some more testing tomorrow.

                      YOu don't use Offline files though right?

                      I do. For the internal office people, the main profile folders (Desktop, Documents, etc.) are redirected to network storage. When you have folder redirection, I believe Offline files are enabled by default.

                      DashrenderD dbeatoD 2 Replies Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender @EddieJennings
                        last edited by

                        @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                        @dbeato said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                        @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                        @wirestyle22 said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                        @EddieJennings did you resolve your issue?

                        Most likely so. It appears that offline files is the clue I needed. I can do some more testing tomorrow.

                        YOu don't use Offline files though right?

                        I do. For the internal office people, the main profile folders (Desktop, Documents, etc.) are redirected to network storage. When you have folder redirection, I believe Offline files are enabled by default.

                        They are, but they don't have to be.

                        1 Reply Last reply Reply Quote 0
                        • dbeatoD
                          dbeato @EddieJennings
                          last edited by

                          @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                          @dbeato said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                          @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                          @wirestyle22 said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                          @EddieJennings did you resolve your issue?

                          Most likely so. It appears that offline files is the clue I needed. I can do some more testing tomorrow.

                          YOu don't use Offline files though right?

                          I do. For the internal office people, the main profile folders (Desktop, Documents, etc.) are redirected to network storage. When you have folder redirection, I believe Offline files are enabled by default.

                          Okay, but you don't have to have Offline files enabled, do you have users coming in and out with laptops from officess?

                          EddieJenningsE 1 Reply Last reply Reply Quote 0
                          • EddieJenningsE
                            EddieJennings @dbeato
                            last edited by

                            @dbeato said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                            @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                            @dbeato said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                            @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                            @wirestyle22 said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                            @EddieJennings did you resolve your issue?

                            Most likely so. It appears that offline files is the clue I needed. I can do some more testing tomorrow.

                            YOu don't use Offline files though right?

                            I do. For the internal office people, the main profile folders (Desktop, Documents, etc.) are redirected to network storage. When you have folder redirection, I believe Offline files are enabled by default.

                            Okay, but you don't have to have Offline files enabled, do you have users coming in and out with laptops from officess?

                            Yes, me. 😉
                            The folks who have laptops and occasionally come into the office, don't have folder redirection enabled. I'm the only person who would be affected by this; thus, I think my work around will just be using UNC paths if I need to get to file shares when I'm at home and connected to the VPN.

                            DashrenderD 1 Reply Last reply Reply Quote 0
                            • DashrenderD
                              Dashrender @EddieJennings
                              last edited by

                              @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                              @dbeato said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                              @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                              @dbeato said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                              @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                              @wirestyle22 said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                              @EddieJennings did you resolve your issue?

                              Most likely so. It appears that offline files is the clue I needed. I can do some more testing tomorrow.

                              YOu don't use Offline files though right?

                              I do. For the internal office people, the main profile folders (Desktop, Documents, etc.) are redirected to network storage. When you have folder redirection, I believe Offline files are enabled by default.

                              Okay, but you don't have to have Offline files enabled, do you have users coming in and out with laptops from officess?

                              Yes, me. 😉
                              The folks who have laptops and occasionally come into the office, don't have folder redirection enabled. I'm the only person who would be affected by this; thus, I think my work around will just be using UNC paths if I need to get to file shares when I'm at home and connected to the VPN.

                              Now you've lost me. I didn't really understand your earlier thing either between the two different UNCs you posted - can you expand up on that?

                              EddieJenningsE 1 Reply Last reply Reply Quote 0
                              • EddieJenningsE
                                EddieJennings @Dashrender
                                last edited by

                                @dashrender Yes. When I'm connected to the remote access VPN and Offline files are enabled, this condition occurs.

                                \\mydomain.com\shares\theITDeptShare fails.
                                \\serverName\theITDeptShare works.

                                DashrenderD 1 Reply Last reply Reply Quote 0
                                • DashrenderD
                                  Dashrender @EddieJennings
                                  last edited by

                                  @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                                  @dashrender Yes. When I'm connected to the remote access VPN and Offline files are enabled, this condition occurs.

                                  \\mydomain.com\shares\theITDeptShare fails.
                                  \\serverName\theITDeptShare works.

                                  Right, so the question is - why is your machine not resolving mydomain.com?

                                  You could likely easily solve this with a host file entry for mydomain.com (though perhaps not if the IP stack doesn't see mydomain.com as a valid host name, not sure).

                                  1 Reply Last reply Reply Quote 2
                                  • DashrenderD
                                    Dashrender
                                    last edited by

                                    I guess it does work

                                    https://i.imgur.com/NJ310OC.png

                                    1 Reply Last reply Reply Quote 0
                                    • DashrenderD
                                      Dashrender
                                      last edited by

                                      Lot of good things to try in this thread.

                                      https://social.technet.microsoft.com/Forums/windows/en-US/5f81b8a8-beff-49a7-a755-bc38c92b0658/cannot-access-dfs-share-over-vpn?forum=w7itpronetworking

                                      1 Reply Last reply Reply Quote 1
                                      • EddieJenningsE
                                        EddieJennings
                                        last edited by

                                        Thanks to @Dashrender for the assist. It looks like the problem was authentication. I authenticated to the VPN using domain\username rather than using the User Principal Name. Doing the latter allowed me to reach DFS shares.

                                        dbeatoD 1 Reply Last reply Reply Quote 0
                                        • dbeatoD
                                          dbeato @EddieJennings
                                          last edited by

                                          @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                                          Thanks to @Dashrender for the assist. It looks like the problem was authentication. I authenticated to the VPN using domain\username rather than using the User Principal Name. Doing the latter allowed me to reach DFS shares.

                                          Woops, that's crazy but definitely there is an issue with DNS.

                                          DashrenderD 1 Reply Last reply Reply Quote 0
                                          • DashrenderD
                                            Dashrender @dbeato
                                            last edited by

                                            @dbeato said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                                            @eddiejennings said in Passing traffic between a remote access VPN and Site-to-site VPN on an Edge Router Lite:

                                            Thanks to @Dashrender for the assist.  It looks like the problem was authentication.  I authenticated to the VPN using domain\username rather than using the User Principal Name.  Doing the latter allowed me to reach DFS shares.
                                            

                                            Woops, that's crazy but definitely there is an issue with DNS.

                                            huh?

                                            dbeatoD 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post