What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

No NAT Loopback via OpenVPN Server

azdeltawye

Occasional Visitor
Hello,

I recently bought an RT-AC86U and flashed it with Merlin 382.1_2 firmware. Everything is checking out great except I can't access my security cam NVR via WAN IP through OpenVPN from mobile device. I can access the NVR via LAN IP when tunneling through VPN but I would prefer to use WAN IP so I don't need multiple logins; the WAN NVR login allows back door access through port-forwarding from qualified IP white list...

When I start the OpenVPN session the status page shows virtual IP of 10.8.0.2. My NVR is at 192.168.0.50. Could I add something to the routing table to allow access to NVR via WAN IP from 10.8.0.2?

As a side note; my old TRENDnet TEW-827 router did not support NAT Loopback but when accessing NVR /LAN IP via OpenVPN it would list my login IP as the gateway (192.168.0.1) and not the 10.8.0.X IP like the RT-AC86U does. That is puzzling to me...

Any help would be appreciated.
Thanks,
Darren
 
Still can't figure this out...
Here are some steps I took to troubleshoot:
  • Trace route from computer on my LAN (192.168.x.x) to my public WAN IP (209.234.x.x) and it took one hop. This would be expected due to successful NAT loopback.
  • Trace route from my mobile device VPN client (10.8.x.x) to a server on my local LAN and it took one hop - as expected.
  • Trace route from mobile device VPN client (10.8.x.x) to WAN IP (209.234.x.x) and it took over 24 hops.
  • Added WAN IP to the 'custom configuration' text box in the advanced settings of the VPN server setup: route 209.234.x.x 255.255.255.255
  • Verified WAN IP was in routing table
  • Trace route from mobile device VPN client (10.8.x.x) to WAN IP (209.234.x.x) and it took over 24 hops...
VPN server setup is mostly default except for TCP port and the addition above to the routing table. Considering trying TAP instead of TUN...

Rapidly running out of ideas. Looking for some help...

THanks,
Darren
 
Update:
I setup a second OpenVPN server on my RT-AC86U using a layer 2 bridge (TAP) connection in the advanced settings. This seemed like the easiest way to allow remote clients to connect to local servers using WAN IP via VPN. Unfortunately I quickly found out that OpenVPN does not support TAP connections on iOS devices:(.

So back to square one.

Any ideas would be greatly appreciated..

Thanks,
Darren
 

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top