[plug] vpn breaks home network

Rob Dunne rob.dunne at gmail.com
Sun Dec 9 11:51:34 WST 2007

Hi list,

I have a little home network with a ASDL2+ modem, a hub and
two computers with IP addresses (plastic)
and (lycra)

It all works well until I start up cisco vpn on plastic. The vpn
works but I can not see lycra any more.

I think what I need is a "VPN pass-through" on the modem. Does this
sound right?

The vpn gives the following information when it starts up.
Client address:
Server address:
Encryption: 256-bit AES
Authentication: HMAC-SHA
IP Compression: None
NAT passthrough is active on port UDP 10000
Local LAN Access is disabled

The modem (iconnectAccess621) has an IP Forwarding menu
that has VPN with IPSEC L2TP -- which (if I understand it)
sets up the following
Protocol PortStart PortEnd PortMap
UDP  500   500   500
ESP   *     *     *
UDP 4500   4500   4500

turning this on doesn't fix the problem. Perhaps because the
vpn is expecting "NAT passthrough" on "port UDP 10000"?

I have tried to set this up as a "Custom Port Forwarding" with
Source IP
Destination IP
Port Start 10000
Port End 10000
Port Map 10000
Protocol UDP

but I am really just guessing here. Is the "source" the server at work
or the modem or what?

any pointers received gratefully!


