Conflicting VPN setting [Win10] [R7000]

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
martixy
DD-WRT Novice


Joined: 29 Oct 2012
Posts: 16

PostPosted: Mon Nov 29, 2021 16:54    Post subject: Conflicting VPN setting [Win10] [R7000] Reply with quote
I am trying to merge 2 networks, so we get access to each other's files.

To that end I went with the simplest and most direct route - I enabled the PPTP VPN server on my R7000. All computers running windows 10.

The VPN clients have no trouble accessing my computer on the host network.

However there is a network setting on the clients that seems to lead to a functional conflict.

In the VPN connection properties -> Networking -> IPv4 properties -> Advanced there is a setting called Use default gateway on remote network

OFF = Prevents guest internet traffic from tunneling through the VPN (VPN performance is fairly low). Prevents host network from accessing guest machine over the network (cannot map drives).
ON = Tunnels guest internet traffic through VPN. Allows host network to access guest machine.

The problem is, I want both for guest internet traffic to not tunnel through the VPN (due to the low performance) and for the host network to be able to access the guest machine (the reason for doing this in the first place).

Is this possible?

(Some theory as to what's going on, so I learn some networking magic also appreciated.)
Sponsor
eibgrad
DD-WRT Guru


Joined: 18 Sep 2010
Posts: 9157

PostPosted: Tue Nov 30, 2021 3:56    Post subject: Reply with quote
I assume your PPTP clients are running on Windows. IOW, this is NOT a case of a PPTP client on some remote dd-wrt router connected to your locally hosted PPTP server on dd-wrt.

If you examine the PPTP client on dd-wrt, you'll notice there are two fields to identify the Remote Subnet and Remote Subnet Mask (i.e., the IP network on which the PPTP server is running). Your PPTP clients need to have the same ability to identify the remote network if you choose NOT to use the PPTP server as a default gateway. I haven't used PPTP in years, even on dd-wrt, let alone Windows. So I don't recall if and where you can establish that information on the PPTP client config. But in the worst case, you could add the routing information directly from a command prompt once the PPTP client was established.

Code:
route -p add 192.168.2.0 mask 255.255.255.0 <pptp-gateway>

_________________
ddwrt-ovpn-split-basic.sh (UPDATED!) * ddwrt-ovpn-split-advanced.sh (UPDATED!) * ddwrt-ovpn-client-killswitch.sh * ddwrt-ovpn-client-watchdog.sh * ddwrt-ovpn-remote-access.sh * ddwrt-ovpn-client-backup.sh * ddwrt-mount-usb-drives.sh * ddwrt-blacklist-domains.sh * ddwrt-wol-port-forward.sh * ddwrt-dns-monitor.sh (NEW!)
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 10389
Location: Netherlands

PostPosted: Tue Nov 30, 2021 13:00    Post subject: Reply with quote
For me it is also a very long time ago I used PPTP, it is outdated and insecure.

You might consider using OpenVPN or WireGuard
the guides and documentation are stickies in this forum
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=327398
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=327397

_________________
Routers:Netgear R7800, R7000, R6400v1, R6400v2, Linksys EA8500, EA6900 (XvortexCFE), E2000 (converted WRT320N), WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
martixy
DD-WRT Novice


Joined: 29 Oct 2012
Posts: 16

PostPosted: Thu Dec 02, 2021 7:19    Post subject: Reply with quote
Here are the client routing tables with or without the default gateway being remote:
(I removed a bunch of 224.0.0.0 and above routes to make it smaller. And the 255.255.255.255 route with my public IP.)
Code:

===========================================================================
Interface List
 18...d8 cb 8a 12 f5 46 ......Intel(R) Ethernet Connection I217-V
 37...........................martixy-net-gate
 15...28 c2 dd 1a 58 17 ......Realtek 8821AE Wireless LAN 802.11ac PCI-E NIC
 14...2a c2 dd 1a 58 17 ......Microsoft Wi-Fi Direct Virtual Adapter
  5...28 c2 dd 1a 58 16 ......Bluetooth Device (Personal Area Network)
  1...........................Software Loopback Interface 1
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1      192.168.1.3   4245
          0.0.0.0          0.0.0.0         On-link     192.168.0.152     26
        127.0.0.0        255.0.0.0         On-link         127.0.0.1   4556
        127.0.0.1  255.255.255.255         On-link         127.0.0.1   4556
  127.255.255.255  255.255.255.255         On-link         127.0.0.1   4556
    192.168.0.152  255.255.255.255         On-link     192.168.0.152    281
      192.168.1.0    255.255.255.0         On-link       192.168.1.3   4491
      192.168.1.3  255.255.255.255         On-link       192.168.1.3   4491
    192.168.1.255  255.255.255.255         On-link       192.168.1.3   4491
===========================================================================

===========================================================================
Interface List
 18...d8 cb 8a 12 f5 46 ......Intel(R) Ethernet Connection I217-V
 37...........................martixy-net-no-gate
 15...28 c2 dd 1a 58 17 ......Realtek 8821AE Wireless LAN 802.11ac PCI-E NIC
 14...2a c2 dd 1a 58 17 ......Microsoft Wi-Fi Direct Virtual Adapter
 17...28 c2 dd 1a 58 17 ......Microsoft Wi-Fi Direct Virtual Adapter #2
  5...28 c2 dd 1a 58 16 ......Bluetooth Device (Personal Area Network)
  1...........................Software Loopback Interface 1
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1      192.168.1.3     20
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    331
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    331
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    331
      192.168.0.0    255.255.255.0    192.168.0.151    192.168.0.152     26
    192.168.0.152  255.255.255.255         On-link     192.168.0.152    281
      192.168.1.0    255.255.255.0         On-link       192.168.1.3    266
      192.168.1.3  255.255.255.255         On-link       192.168.1.3    266
    192.168.1.255  255.255.255.255         On-link       192.168.1.3    266
===========================================================================

(code blocks on this forum are not monospace font so I guess it's misaligned)

It makes no difference for the client machine routing, however a machine on the host network cannot access the client in the second instance (when the default gateway is not set to remote).

I suppose I will start looking into openVPN as well.
the-joker
DD-WRT Developer/Maintainer


Joined: 31 Jul 2021
Posts: 1898
Location: All over YOUR webs

PostPosted: Thu Dec 02, 2021 8:36    Post subject: Reply with quote
@martixy

First I must apologize for this offtopic intrusion.

re >(code blocks on this forum are not monospace font so I guess it's misaligned)

Easy fix, first I have this working on my forums theme (on my signature) version 1.1.9
However I can also submit a patch for the forums that does this by default easy fix really.

Attaching shameless screenshot of theme for your snippet =)

Take care.

_________________
Saving your retinas from the burn!🔥
DD-WRT Inspired themes for routers
DD-WRT Inspired themes for the phpBB Forum
DD-WRT Inspired themes for the SVN Trac & FTP site
Join in for a chat @ #style_it_themes_public:matrix.org or #style_it_themes:discord

DD-WRT UI Themes Bug Reporting and Discussion thread

Router: ANus RT-AC68U E1 (recognized as C1)
martixy
DD-WRT Novice


Joined: 29 Oct 2012
Posts: 16

PostPosted: Thu Dec 02, 2021 13:48    Post subject: Reply with quote
Cool. This looks much more readable.

As a networking noob I've had to learn as I go. I've gotten familiar the routing table and how to read netmasks. But it's not like I'm following a structured networking course, so I still don't know:
1. How metric is calculated. I know it's the "distance" - a lower metric means this route is preferred. And I also know its a combination of ...something - interface metric and ???
2. How routing actually works hop by hop.
3. What happens with the VPN - like do packets hop from the physical interface to the virtual?

But I am learning.

Even if I'm not a network engineer, I am a programmer, and I had one good and one bad system config, so you diff, and start figuring out which part of the diff makes or breaks your system.

Today I stared at the routing tables for a long, long time. After some experiments, and some failures, I finally figured out a solution.

I don't know why it's a solution, but it is:
Code:
route add 0.0.0.0 mask 0.0.0.0 0.0.0.0 if 44

(as in client->host(client PC to PC on host network) works without it, but host->client does not - it seems to catch some packets that arrive at the client but are dropped without it - I don't know which packets tho - packet-capturing a working host->client connection did not reveal any src/dst address apart from the two machines. if 44 is the VPN interface btw.)

I did come up with a funny way of working remotely without losing access if I mess up - a deadman switch.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum