DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Routing Port Over IPSec

  • thekingster
  • Topic Author
  • Offline
  • New Member
  • New Member
More
03 Nov 2012 14:26 #74015 by thekingster
Routing Port Over IPSec was created by thekingster
Hi

I have an IPSec setup between 2 offices and all of our clients servers are restricted to our main office IP address for RDP. I want my workers in the sub office to connect down the IPSec tunnel when using port 3389 RDP rather than out the office default gateway. I have tried a few things but to no avail.

Can anyone provide any pointers?

Thanks
Dave

Please Log in or Create an account to join the conversation.

  • thekingster
  • Topic Author
  • Offline
  • New Member
  • New Member
More
17 Nov 2012 00:31 #74233 by thekingster
Replied by thekingster on topic Re: Routing Port Over IPSec
Nobody??? Surely an easy one?

Please Log in or Create an account to join the conversation.

More
19 Nov 2012 15:33 #74267 by jedi98
Replied by jedi98 on topic Re: Routing Port Over IPSec
Not as easy as you might think.

From what you say I guess that you are doing: -
Code:
/- -\ Sub-office / \ RDP User (public ip:3389) --(lan)--> Router --< >--> Router --(lan)--> RDP Service \ / \-(internet)-/

And what you are trying to do is:-
Code:
/----IPSEC---\ Sub-office / \ RDP User (public ip:3389) --(lan)--> Router --< >--> Router --(lan)--> RDP Service \ / \- -/

Trouble is I don't think that you can because you cannot redirect addresses in>>out and you cannot redirect across vpn (AFAIK).

Can you not get the client users at the sub office to use private ip:3389 (eg. 192.168.1.13:3389) instead of public ip:3389? Or internal DNS name if you have internal DNS?

Please Log in or Create an account to join the conversation.

More
20 Nov 2012 19:01 #74286 by asimm.it
Replied by asimm.it on topic Re: Routing Port Over IPSec
only way it can work is as jedi has outlined.

any traffic for the remote lan will route down the vpn tunnel if you use the private lan ip addresses from remote desktop.

I would assume that this is what is happening anyway if you are connecting to more than one pc on the remote network, that is unless you have multiple public ip addresses and port forwarding mapping to individual pc's on port 3389.

Please Log in or Create an account to join the conversation.

Moderators: Sami