Hi, trying to get an L2TP/IPsec VPN working so it can be used to go out on the net and to devices behind the CCR1009 as one of the IP's in the 104.19x.x.x subnet.
When remotely connected to the VPN and search 'my ip' with a search engine, it does report the IP as 104.19x.x.x. The problem is trying to connect to hosts/devices on the 104.19x.x.x behind Eth2.
Our CCR 1009 is setup with the following:
Eth1: 192.154.x.x (WAN)
Eth2: 104.19x.x.x (LAN)
198.168.1.1 (Private LAN)
The 104.19x.x.x/24 is routed to the 192.154.x.x/28 subnet. The WAN external gateway is 192.154.x.6x
The hosts/devices behind the CCR1009 all have 104.19x.x.x IP addresses. Some hosts have NIC2 using the 192.168.1.0/24 but there is no src natting wanted. I only put it in the question for completeness.
We cannot have masquerading on Eth2 because external devices require data coming from the 104.19x.x.x subnet.
The issue is when connecting to the L2TP VPN remotely, and the client wants to get email, the connection to the mail server (which is on the 104.19x.x.x subnet) times out. This is intermittent but a problem nonetheless.
On the remote windows clients, have the L2TP connection to 192.158.x.x. The PPP Profile in the CCR 1009 for L2TP server has local and remote address set to use a pool which contains IP's in 104.19x.x.x/28 subnet. The IP's in the pool are not used by any other devices obviously.
Any idea on either what might be wrong with the configuration??
Thanks!