Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


nicmair

250 posts

Master Geek
+1 received by user: 40


#319733 27-May-2025 09:09
Send private message

Hi, I have an issue I'm hoping to get some clarification on and hope the community can help me understand what's going on. I'm not expecting a solution, just some insights to help me process this.

 

We will have 14 2degrees business connections (all fibre) and are deploying IPSec VPN tunnels across them. The first 4 sites were successfully set up, but we were unable to establish the IPSec VPN for the next 4 sites, (only 8 have been setup yet so far). We are using Grandstream devices as the hardware, and each site is allocated a static IP address by 2Degrees. Our main site, 10.10.1.1, is the destination address that sites need to reach to establish an IPSec VPN (not the real IP address of course).

 

After a lot of digging we have found, (not the real IP addresses/ranges)

 

  • The first 4 sites were allocated an IP address in the 10.10.1 range
  • The second 4 sites, were allocated an IP in the range 11.11.2 range
  • Any device on the 10.10.1 range can establish an IPSec VPN connection to any other device on the 10.10.1 range, Any device on the 11.11.2. range can establish an IPSec VPN connection to any other device on the 11.11.2 range, BUT NO IPSec VPN can be established between devices on the 10.10.1 and the 11.11.2 ranges
  • A device on 10.10.1 can ping a device on 11.11.2, but 11.11.2 cannot ping a device on 10.10.1
  • If we do a whatsmyip from any device, we get a different IP address from the static IP that 2Degress has assigned.
  • If we do whatsmyip from our 10.10.1.1 site and then use that IP Address as the destination IP Address on a 11.11.2 assigned device, the IPSec VPN works.

We logged a ticket with 2D business support saying we think there is routing issues between the 2 IP ranges, and the first solution was to reassign static IP's in the same range, (i.e. replace the 11.11.2 addresses with 10.10.1 addresses, but they quickly advised that their system doesn't allow selecting a static IP address).  They then said the solution was to "move" all our connections to a different platform so that all the IP Address would be in the same range, (and this will take some weeks to complete).  I've requested they continue to look at the original issue further, e.g. why 10.10.1 and 11.11.2 can't talk to each other.

 

This is all well above my head, so hoping that someone can help explain what's going on, and especially why when we do the whatsmyip, we get a different IP to the static IP that 2D have assigned the site, (clearly the easiest fix for us is to the just use the IP address we get when we do the whatsmyip on our main site, but we have no idea if this itself is static, or could change).   To be clear, the 2D support desk has been very supportive and helpful, and I've no issues there.

 

Cheers Nic.


Create new topic
lxsw20
3689 posts

Uber Geek
+1 received by user: 2174

Subscriber

  #3377154 27-May-2025 09:52
Send private message

By 10.10.x you are talking about an private address space I think, which isn't really anything to do with 2D.

 

11.11 is not private address space, so yes the routing may well be borked. This isn't a 2D issue, its an internal network addressing issue.

 

 

 

https://www.okta.com/identity-101/understanding-private-ip-ranges/

 

 




michaelmurfy
meow
13579 posts

Uber Geek
+1 received by user: 10910

Moderator
ID Verified
Trusted
Lifetime subscriber

  #3377156 27-May-2025 10:01
Send private message

lxsw20:By 10.10.x you are talking about an private address space I think, which isn't really anything to do with 2D.

 

and each site is allocated a static IP address by 2Degrees.

 

I think the OP is more using those IP addresses as an example. They're not real addresses.





Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.