Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Problems accessing BCM50 through VPN

Status
Not open for further replies.

3Series

Technical User
Apr 8, 2009
6
CA
I've noticed a couple other posts on this issue, but with slightly different configurations or equipment.

We have a number of IP Softphones (2050) set up on staff laptops to connect to our BCM50. When the computers are in the office & connected to our LAN everything works as expected, but when any of us is offsite and connected through VPN, we can't seem to connect to the BCM. We can access (and ping the IP addresses of) all the other resources on the network as normal, except the BCM.

Some additional info:

Our BCM and VPN Router (Cisco 851W) are on same subnet 192.168.16.x and both have static IPs

BCM: 192.168.16.251
VPN Router: 192.168.16.253

Based on some of the responses in the other posts, I've attempted some suggested tests:

using Element Manager, I can successfully Traceroute to the DNS Server (192.168.16.3) and one static IP phone on our network (192.168.16.201), but not the VPN router or any other active IP within our LAN.

I am also able to ping the DNS Server, VPN Router and the IP Phone from within EM, but when I try to ping any other IP address in our LAN, I get the following Error message:

"Error happened. Error Detail: extrinsic method could not be executed (Failed to execute the /bin/ping - c3 192.168.16.x command)"

I've checked the firewall settings and VPN connection settings, but I can't find anything obvious that would block access to the BCM and there doesn't seem to be anything untoward in the BCM configuration that would cause this issue either. Any advice/help to narrow down possible causes would be greatly appreciated!!

Thanks in advance.
 
could be a port blocking, disable the router and the laptop firewall and try again
 
3SERIES ....
The error you receive, "Error happened. Error Detail: extrinsic method could not be executed (Failed to execute the /bin/ping - c3 192.168.16.x command)" is the equivalent of "Request Timed Out". The ping failed to complete.
What else is in the network between the VPN Router and the BCM?
What is between the BCM and other network devices?
Is there a data switch?
Are you using VLAN's?


-SD-
 
Thanks SD.

Yes, there is a data switch. We're using an HP ProCurve 2524 switch between the VPN Router and the other devices on out network, including the BCM.

Here's a simple diagram to illustrate how we're currently set up:

WAN
|
Cable Modem
|
VPN Router (also Wireless Access Point)
|
HP Switch (24 port)
| | |||+
Server BCM50 Other PCs & Devices

As far a using VLANs, I'm not sure if we're actively using any. I do see one listed in the Interface/Connection list when I'm looking at the router config using Cisco SDM, but it doesn't appear to have any associations/rules or NAT set for it. It's set up as VLAN for IRB and is joined to an existing bridge group (pointing to the router IP Address).

Unfortunately, the BCM and Router/Network were installed and configured by different parties, both before my arrival, and neither of whom have been much help in resolving this issue so far. Each keeps pushing the issue back to the other, so I'm now delving into this problem out of sheer frustration!

 
What is the default gateway and subnet on the BCM? You need the GW to be 192.168.16.253 or blank or make sure whatever the current GW is knows how to route BCM traffic back to VPN router. Be careful of creating a triangle route though..

 
Looking at IP Subsystem>General Settings in Element Manager, I see the following under IP Settings:

Obtain IP Address Dynamically (Unchecked)
IP Address - 192.168.16.251
IP Subnet Mask - 255.255.255.0
Default Gateway - 192.168.16.253

I also notice that the DNS settings are populated with the correct Domain and DNS Server Address settings. Would this infomation confict in any way with the above settings, seeing as it's set for a static IP?
 
That looks like a working config.. I would start to rule out the switch programming. If you don't how to program or look at the switch programming you might be able to rule it out by physically bypassing the switch. Maybe plug the BCM directly into the VPN router or put an unmanaged switch in between them as a test.. If that still doesn't work then I would suspect something in the VPN configuration.

 
Thanks for the info bjsvec. I think I'll give bypassing the switch and connecting the BCM directly to the Router a try and see if anything changes.

Hopefully, it does make a difference as I'm a bit leary of getting into the VPN config.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top