<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IPSEC VPN Problem?]]></title><description><![CDATA[<p dir="auto">I am not sure where to post this. I have setup a simple network with a IPSEC VPN. No VLANS; IPSEC assigns the client PC 192.168.30.xxx/24  It looks physically like this:</p>
<p dir="auto">Cable modem–&gt;pfsense--&gt;Switch--&gt;hosts &amp; and problem server</p>
<p dir="auto">Logically:</p>
<p dir="auto">WAN--&gt;Router(192.168.11.1)--&gt;Switch(192.168.11.28)--&gt; Problem Server (NVR) (192.168.11.29)</p>
<p dir="auto">When using the VPN</p>
<ul>
<li>
<p dir="auto">I can't access the switch config page over VPN</p>
</li>
<li>
<p dir="auto">I can't access the Network Video Recorder using the NVR client over VPN</p>
</li>
<li>
<p dir="auto">I can access the NVR client using tightVNC, but I receive a connection error</p>
</li>
<li>
<p dir="auto">I can access the webpage of all IP cameras</p>
</li>
</ul>
<p dir="auto">The NVR software &amp; switch seems to be suffering from a strange one way communication problem over the VPN but work fine on the LAN. When accessing the switch config page it seems to be trying to load but never does and eventually finishes loading after a few minutes but displays nothing (chrome); just a white screen, no error messages from chrome. When running ping on a IP camera over VPN:</p>
<p dir="auto">Pinging 192.168.11.77 with 32 bytes of data:<br />
Reply from 192.168.11.77: bytes=32 time=37ms TTL=63<br />
Reply from 192.168.11.77: bytes=32 time=23ms TTL=63<br />
Reply from 192.168.11.77: bytes=32 time=33ms TTL=63<br />
Reply from 192.168.11.77: bytes=32 time=27ms TTL=63</p>
<p dir="auto">NVR over VPN ping:</p>
<p dir="auto">Pinging 192.168.11.29 with 32 bytes of data:<br />
Reply from 192.168.11.29: bytes=32 time=37ms TTL=127<br />
Reply from 192.168.11.29: bytes=32 time=30ms TTL=127<br />
Reply from 192.168.11.29: bytes=32 time=43ms TTL=127<br />
Reply from 192.168.11.29: bytes=32 time=19ms TTL=127</p>
<p dir="auto">When using trace route to any <strong>accessible</strong> host over VPN I get this, dont know if this is normal:</p>
<p dir="auto">Tracing route to 192.168.11.77 over a maximum of 30 hops</p>
<p dir="auto">0  Bob-PC.localdomain [192.168.30.1]<br />
  1    *        *        *   <br />
Computing statistics for 0 seconds…<br />
            Source to Here  This Node/Link<br />
Hop  RTT    Lost/Sent = Pct  Lost/Sent = Pct  Address<br />
  0                                          Bob-PC.localdomain [192.168.30.1]</p>
<p dir="auto">Ping statistics for 192.168.11.77:<br />
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),<br />
Approximate round trip times in milli-seconds:<br />
    Minimum = 23ms, Maximum = 37ms, Average = 30ms</p>
<p dir="auto">The NVR network settings are as follows:</p>
<p dir="auto">IP: 192.168.11.29<br />
Subnet: 255.255.255.0<br />
Default Gateway: 192.168.11.1</p>
<p dir="auto">Here is a trace route to the <strong>non-accessible</strong> NVR, the same results for the switch:</p>
<p dir="auto">Tracing route to 192.168.11.29 over a maximum of 30 hops</p>
<p dir="auto">1    *        *        *    Request timed out.<br />
  2    29 ms    30 ms    27 ms  192.168.11.29</p>
<p dir="auto">Trace complete.</p>
<ul>
<li>
<p dir="auto">Why cant I access the switch setup page over vpn?</p>
</li>
<li>
<p dir="auto">Why cant I use the NVR client software over vpn?</p>
</li>
</ul>
<p dir="auto">Any help would be appreciated guys, thanks in advance.</p>
]]></description><link>https://forum.netgate.com/topic/86795/ipsec-vpn-problem</link><generator>RSS for Node</generator><lastBuildDate>Sat, 08 Aug 2026 18:49:59 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/86795.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 20 Jul 2015 03:48:41 GMT</pubDate><ttl>60</ttl></channel></rss>