Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


nicmair

244 posts

Master Geek


#319733 27-May-2025 09:09
Send private message quote this post

Hi, I have an issue I'm hoping to get some clarification on and hope the community can help me understand what's going on. I'm not expecting a solution, just some insights to help me process this.

 

We will have 14 2degrees business connections (all fibre) and are deploying IPSec VPN tunnels across them. The first 4 sites were successfully set up, but we were unable to establish the IPSec VPN for the next 4 sites, (only 8 have been setup yet so far). We are using Grandstream devices as the hardware, and each site is allocated a static IP address by 2Degrees. Our main site, 10.10.1.1, is the destination address that sites need to reach to establish an IPSec VPN (not the real IP address of course).

 

After a lot of digging we have found, (not the real IP addresses/ranges)

 

  • The first 4 sites were allocated an IP address in the 10.10.1 range
  • The second 4 sites, were allocated an IP in the range 11.11.2 range
  • Any device on the 10.10.1 range can establish an IPSec VPN connection to any other device on the 10.10.1 range, Any device on the 11.11.2. range can establish an IPSec VPN connection to any other device on the 11.11.2 range, BUT NO IPSec VPN can be established between devices on the 10.10.1 and the 11.11.2 ranges
  • A device on 10.10.1 can ping a device on 11.11.2, but 11.11.2 cannot ping a device on 10.10.1
  • If we do a whatsmyip from any device, we get a different IP address from the static IP that 2Degress has assigned.
  • If we do whatsmyip from our 10.10.1.1 site and then use that IP Address as the destination IP Address on a 11.11.2 assigned device, the IPSec VPN works.

We logged a ticket with 2D business support saying we think there is routing issues between the 2 IP ranges, and the first solution was to reassign static IP's in the same range, (i.e. replace the 11.11.2 addresses with 10.10.1 addresses, but they quickly advised that their system doesn't allow selecting a static IP address).  They then said the solution was to "move" all our connections to a different platform so that all the IP Address would be in the same range, (and this will take some weeks to complete).  I've requested they continue to look at the original issue further, e.g. why 10.10.1 and 11.11.2 can't talk to each other.

 

This is all well above my head, so hoping that someone can help explain what's going on, and especially why when we do the whatsmyip, we get a different IP to the static IP that 2D have assigned the site, (clearly the easiest fix for us is to the just use the IP address we get when we do the whatsmyip on our main site, but we have no idea if this itself is static, or could change).   To be clear, the 2D support desk has been very supportive and helpful, and I've no issues there.

 

Cheers Nic.


Create new topic
lxsw20
3552 posts

Uber Geek

Subscriber

  #3377154 27-May-2025 09:52
Send private message quote this post

By 10.10.x you are talking about an private address space I think, which isn't really anything to do with 2D.

 

11.11 is not private address space, so yes the routing may well be borked. This isn't a 2D issue, its an internal network addressing issue.

 

 

 

https://www.okta.com/identity-101/understanding-private-ip-ranges/

 

 




michaelmurfy
meow
13240 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #3377156 27-May-2025 10:01
Send private message quote this post

lxsw20:By 10.10.x you are talking about an private address space I think, which isn't really anything to do with 2D.

 

and each site is allocated a static IP address by 2Degrees.

 

I think the OP is more using those IP addresses as an example. They're not real addresses.





Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.