Jump to content

Recommended Posts

Posted

Morning all,

 

Has anyone successfully managed to get VPN working over a Virgin Media Voom connection with static IP's? It uses GRE tunneling which I think is what prevents it working, it also doesn't support modem mode although I believe this can be enabled with a firmware update only if I went to Dynamic IP's, would a dynamic DNS service then be the only option?

 

Thanks,

 

Simon

Posted

Are you trying to setup IPsec behind a Hitron router?

 

Or are you trying a IPSec site to site VPN?

 

Modem mode should have no impact on Dynamic or Static IP. You are literally handing off the routing and firewall to another device behind the Hitron. The Vroom service is a VM business connection I'd be surprised if it had that limitation to be honest.

Posted
It's IPSec site to site, we have it running over our backup connection currently but obviously would prefer it running over the VM connection. Virgin disable modem mode on the Hitron's when using static IP's , I'm afraid it's not much more than a residential connection with go faster stripes!
  • Thanks 1
Posted (edited)
It's IPSec site to site, we have it running over our backup connection currently but obviously would prefer it running over the VM connection. Virgin disable modem mode on the Hitron's when using static IP's , I'm afraid it's not much more than a residential connection with go faster stripes!

 

Thanks for that, I guess I won't be going Vroom anytime soon if that is the case. I'd double check with VM and complain about this limitation personally, businesses will want to use their own firewall, maybe the conspiracy thought is that they would want people to go with their more expensive service without the Hitron.

Edited by Davit2005
Posted
It's IPSec site to site, we have it running over our backup connection currently but obviously would prefer it running over the VM connection. Virgin disable modem mode on the Hitron's when using static IP's , I'm afraid it's not much more than a residential connection with go faster stripes!

 

I am still struggling to believe that this is the case. I suggest to give them another call and ask for this to be raised at a higher level.

 

Reading the link below, specifically the quote.

 

Background

In its out-of-the-box setup, the Hitron can also be referred to as being in Gateway mode (or ‘Residential’ Gateway mode). For former SuperHub users, this was known as ‘Router mode’.

 

This means that the box is working as an integrated router and modem i.e. you can access the Internet and maintain a network which supports multiple devices using just one piece of hardware.

 

However, in some situations this may not be suitable for your needs. A common scenario is where you have your own router and wish to use the Hitron only to access the Internet. This is where we would disable the ‘Gateway function’ and allow the box to operate in ‘Modem only Mode’.

 

By disabling the NAT and DHCP features on the Hitron CGNv4, the public IP is passed directly to the second device (in this case, your second router). This device then manages the NAT connection to the rest of your network.

 

If you’d like to use this function, you need to have either a PC directly connected to your modem, or to your router.

 

You may then host any service you’d like as it’s not processed by the modem and is only subject to upload/download speed restrictions.

 

 

 

https://www.virginmediabusiness.co.uk/help-and-advice/products-and-services/hitron-router-guide/dynamic-modem-only-mode-user-guide/

Posted
I am still struggling to believe that this is the case. I suggest to give them another call and ask for this to be raised at a higher level.

 

Reading the link below, specifically the quote.

 

 

 

 

 

https://www.virginmediabusiness.co.uk/help-and-advice/products-and-services/hitron-router-guide/dynamic-modem-only-mode-user-guide/

 

I wish that was the case, sadly they fail to mention that only applies if you have a dynamic IP , the firmware they use for the statics on the Hitron via the GRE Tunnel has the RG function removed - I'm waiting on a call back from someone higher up the tree but that's what the first line support have confirmed.

  • Thanks 1
Posted
I wish that was the case, sadly they fail to mention that only applies if you have a dynamic IP , the firmware they use for the statics on the Hitron via the GRE Tunnel has the RG function removed - I'm waiting on a call back from someone higher up the tree but that's what the first line support have confirmed.

 

Thanks

 

I'd be interested to know the outcome. I currently have a BT connection at home but was considering Vroom as an additional or replacement but I'd only consider that if I can use my own firewall with the static public IP.

 

Given my own personal experience with VM it is unlikely to ever happen though.

Posted
I wish that was the case, sadly they fail to mention that only applies if you have a dynamic IP , the firmware they use for the statics on the Hitron via the GRE Tunnel has the RG function removed - I'm waiting on a call back from someone higher up the tree but that's what the first line support have confirmed.

 

Ever intrigued about this I done some looking around on the internet and found this post.

 

https://community.virginmedia.com/t5/Networking-and-WiFi/LAN-to-LAN-VPN-via-VMB-Hitron-CGNV4-Router/td-p/4092175

 

 

Re: LAN to LAN VPN via VMB Hitron CGNV4 Router

on ‎30-10-2019 08:08

 

Strictly speaking the Hitron router doesn't have a modem mode in the same sense as the residential Hub does - instead if you have static addresses, the Hitron can 'pass through' these addresses to your own equipment (the Draytek in your case). The way the static addresses are done is by the Hitron establishing a GRE tunnel back to VM Andy routing all the traffic through it. In this mode, the Hitron's firewall is still,active even though iti is no longer performing any NAT function and although you 'should' be able to establish your own VPN tunnel through this GRE tunnel, I'm not too surprised that you have issues.

 

With the Hitron reset back to dynamic IP mode, you now have a double-NAT issue and I would imagine that the Hitron is again getting in the way of your IPSEC tunnel. Even if the tunnel comes up, I am wondering if it might not renegotiate properly when the SA lifetime expires.

 

In essence here is no real difference between the VM business and residential connection, you will be connected to the same cabinet and the same infrastructure, the difference isn't with the SLA and supposedly quicker support in the vent of an outage.

 

So it might sound a bit controversial but I would be tempted to think about abandoning the business connection (if possible) and just get a standard residential connection (again if VM will allow it), put the Hub in proper modem mode and run the Draytek behind that. Of course if you are worried about downtime effecting the business, then you can always see about a second cheap DSL line as a backup. Yes, you will have to reconfigure the tunnel settings at both ends as the VPN can't auto failover but that might be few and far between. Does your current Drsytek support multi-wan connections?

 

John

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...