Koozali.org: home of the SME Server

VPN configuration with SME

Offline mophilly

  • *
  • 384
  • +0/-0
    • Mophilly
VPN configuration with SME
« on: May 21, 2009, 05:26:36 PM »
This question may be off topic. If you know of a better forum, please let me know. Also, this is more or less a continuation of http://forums.contribs.org/index.php/topic,43793.0.html, as the solution I mention there helped but not entirely resolve the problem.

I have a simple configuration where a Netopia DSL modem connects to the internet and the SME Server Gateway stands behind it. The DSL modem offers wireless internet access via DHCP to visitors in the office. SME allows VPN access to selected clients and to remote workers. There is a "pinhole" in the DSL modem config that maps the SME server to the internet so it can play it role a gateway server. You can see a diagram at this link: http://www.mophilly.com/images/LaMesaTopology.png

The problem we are having is the wireless clients cannot connect to, say, yahoo mail, when connected to SME via VPN. The workstations behind SME connect fine, and if the VPN connection is closed then the wireless clients can also connect. This affects only secure sites.

I have been studying VPN configuration articles on the web. There is an enormous amount of information to digest. I am posting here in hopes that someone has a link or two to share, or can draw on experience with this topology.

Thanks, in advance.
- Mark

Offline JoshuaR

  • ****
  • 125
  • +0/-0
    • Tech-Eze
Re: VPN configuration with SME
« Reply #1 on: May 22, 2009, 03:44:29 AM »
Simple thing first, do you have any kind of filtering software internally that would stop them access that kind of site, and if so have you tried un-checking the vpn connection from using the remote default gateway? See the below image...
Life's tragedy is that we get old too soon, and wise too late...

Offline mophilly

  • *
  • 384
  • +0/-0
    • Mophilly
Re: VPN configuration with SME
« Reply #2 on: May 22, 2009, 06:35:53 PM »
Thanks for the reply, Joshua.

I don't believe there is any software on the client machines that would block the sites in question. One of the sites is yahoo mail.

I have asked the user to check the vpn connection settings per your note, and I am waiting for a reply.

Thanks, again.
- Mark

Offline mophilly

  • *
  • 384
  • +0/-0
    • Mophilly
Re: VPN configuration with SME
« Reply #3 on: May 22, 2009, 08:47:39 PM »
Well, unfortunately the client in question does not have the option on the advanced panel of the vpn connection.

My suspicion is that the Netopia modem is not configured correctly for both the wireless access and the gateway though which the outbound traffic from the vpn tunnel must travel. But then, I don't know, which is why I posted here.

All ideas are most welcome.
- Mark