VPN client and IP address conflicts (2024)

roadkill401

macrumors 6502a

Original poster

Jan 11, 2015
509
186
  • Aug 9, 2024
  • #1

I know that Apple provides no support for VPN, so I am stuck on how to get around this.

Like most everyone here, I get my internet from a service provider not by buying a T1 or some network connection from the telecom giants. So I am stuck using their broadband modem/router to connect. This dictates some things like sadly for me the IP address scope that I can use. They are a!h here and force me to use a 192.168.2.x ip address space. Not that it really makes my life horrible.

But my kid is going to university and their house has internet too and also use the 192.168.2.x ip address range. This then causes the issue that they cannot VPN back to home.

I have the VPN server setup fine inside my home and it works just great for them to connect from any other location it seems other than their house as the VPN client on the macOS doesn't work like you'd expect it should or could. I have the IPSec setup fine and even have the checkbox to 'route all traffic through the VPN' but for whatever reason, because the IP address at their house is the same as mine here, the Mac cannot see my network when connected. so if they try and connect to any of the machines inside my 192.168.2.x network, the traffic doesn't get sent over the VPN at all, and just stays local to their house. If they go to a friends house and not change a single configuration or setting, it works fine as the friends have a different ip address set like 10.0.1.x. or perhaps 192.168.1.x. it is just if the two IP address ranges are the exact same that it doesn't work.

I can't change mine, and they don't have the power to force the house to change theirs.

Does anyone know of any work around that might work?

DeltaMac

macrumors G5
Jul 30, 2003
13,656
4,517
Delaware
  • Aug 9, 2024
  • #2

Does your VPN support have any suggestions?

  • Aug 9, 2024
  • #3

I'm no network expert but some thoughts as I went through something similar. There may be other (software) solutions though.
It comes down to the complexity of your home network and if you could afford a second router/access point:
I have the main router provided by my ISP in the 192.168.2.x ip address space.
I bought a second router/access point without any expensive modem functionality but a simple WAN port. That WAN port is connected to the main router to get internet access.
Said second router/access point is configured to the 192.168.4.x ip address space and all PCs are physically connected to it and WiFi as well as VPN are set up on it.

(I'm not from the US but for what it's worth, I use a 70€ FritzBox 4040 for that. https://en.avm.de/products/fritzbox/fritzbox-4040/)

Edit: For VPN to work on the second router, I had to forward the ports: 500, 4500 and 1701.

Last edited:

roadkill401

macrumors 6502a

Original poster

Jan 11, 2015
509
186
  • Aug 9, 2024
  • #4

DeltaMac said:

Does your VPN support have any suggestions?

what VPN support? I installed a VPN server at my house, and configured the vpn client on my kids Mac. The VPN server software say that nothing is wrong on their end. If the client doesn't direct the network packets to the server then what can they do about it? The problem is on the client end and as I sad Apple refuses to take any support for network issues seriously. they suggest that you post to the apple suggestion site and they will consider it. like as if that will ever happen

roadkill401

macrumors 6502a

Original poster

Jan 11, 2015
509
186
  • Aug 9, 2024
  • #5

arw said:

I'm no network expert but some thoughts as I went through something similar. There may be other (software) solutions though.
It comes down to the complexity of your home network and if you could afford a second router/access point:
I have the main router provided by my ISP in the 192.168.2.x ip address space.
I bought a second router/access point without any expensive modem functionality but a simple WAN port. That WAN port is connected to the main router to get internet access.
Said second router/access point is configured to the 192.168.4.x ip address space and all PCs are physically connected to it and WiFi as well as VPN are set up on it.

(I'm not from the US but for what it's worth, I use a 70€ FritzBox 4040 for that. https://en.avm.de/products/fritzbox/fritzbox-4040/)

Edit: For VPN to work on the second router, I had to forward the ports: 500, 4500 and 1701.

that is then doing double NAT that in network terms is considered a rather bad thing to do. what I am stuck is either on how to get the Apple built in client to function correctly. Or more likely how to force MacOS to properly handle the network correctly. if the issue is that the MacOS can't insert the VPN to act as the primary network interface and still allow it to then repackage all network requests into encrypted bundles and forward them off to the physical network interface that is connected to the wifi/ethernet then there isn't much that can be done. if its a MacOS limitation then even a third party vpn client won't do much.

Bigwaff

Contributor
Sep 20, 2013
2,351
1,642
  • Aug 9, 2024
  • #6

roadkill401 said:

I can't change mine, and they don't have the power to force the house to change theirs.

Does anyone know of any work around that might work?

You need 1:1 NAT enabled on the VPN tunnel... if your VPN implementation supports it.

Marco Klobas

macrumors 6502
Jul 14, 2017
458
915
Italy
  • Aug 9, 2024
  • #7

No network expert here too. AFAIK double NAT isn't bad per se: you just have to know what are you doing – taking into account that usually every setup is done twice (say, a port forwarding).

Back to your issue: maybe a tool like Tailscale could help.

  • VPN client and IP address conflicts (8)

Reactions:

gilby101

G

gilby101

macrumors 68030
Mar 17, 2010
2,761
1,532
Tasmania
  • Aug 11, 2024
  • #8

Marco Klobas said:

Back to your issue: maybe a tool like Tailscale could help.

Tailscale is so much easier than VPN for remote access for a group of people.

You must log in or register to reply here.

VPN client and IP address conflicts (2024)
Top Articles
BFH, Urteil v. 23.05.2006 - VI R 21/03
Metv Plus Schedule Today Near Texas
Metra Union Pacific West Schedule
News - Rachel Stevens at RachelStevens.com
Wellcare Dual Align 129 (HMO D-SNP) - Hearing Aid Benefits | FreeHearingTest.org
Did 9Anime Rebrand
Pbr Wisconsin Baseball
Canelo Vs Ryder Directv
Visustella Battle Core
Corporate Homepage | Publix Super Markets
Myunlb
What Does Dwb Mean In Instagram
Mawal Gameroom Download
FAQ: Pressure-Treated Wood
A rough Sunday for some of the NFL's best teams in 2023 led to the three biggest upsets: Analysis - NFL
Alejos Hut Henderson Tx
Saberhealth Time Track
ᐅ Bosch Aero Twin A 863 S Scheibenwischer
Mani Pedi Walk Ins Near Me
Dirt Removal in Burnet, TX ~ Instant Upfront Pricing
Florida History: Jacksonville's role in the silent film industry
Www.publicsurplus.com Motor Pool
Tyler Sis University City
Boston Dynamics’ new humanoid moves like no robot you’ve ever seen
Naya Padkar Gujarati News Paper
SOGo Groupware - Rechenzentrum Universität Osnabrück
Maine Racer Swap And Sell
Www.1Tamilmv.con
Airg Com Chat
Craigslist/Phx
Publix Coral Way And 147
Soiza Grass
Nsu Occupational Therapy Prerequisites
Spinning Gold Showtimes Near Emagine Birch Run
Craigslist Greencastle
Best Weapons For Psyker Darktide
Td Ameritrade Learning Center
Oriellys Tooele
What Is Kik and Why Do Teenagers Love It?
Ladyva Is She Married
Foxxequeen
Kushfly Promo Code
Plasma Donation Greensburg Pa
60 Second Burger Run Unblocked
Fallout 76 Fox Locations
Coleman Funeral Home Olive Branch Ms Obituaries
Besoldungstabellen | Niedersächsisches Landesamt für Bezüge und Versorgung (NLBV)
Best brow shaping and sculpting specialists near me in Toronto | Fresha
The Missile Is Eepy Origin
Secondary Math 2 Module 3 Answers
Sdn Dds
Palmyra Authentic Mediterranean Cuisine مطعم أبو سمرة
Latest Posts
Article information

Author: Mrs. Angelic Larkin

Last Updated:

Views: 6036

Rating: 4.7 / 5 (67 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Mrs. Angelic Larkin

Birthday: 1992-06-28

Address: Apt. 413 8275 Mueller Overpass, South Magnolia, IA 99527-6023

Phone: +6824704719725

Job: District Real-Estate Facilitator

Hobby: Letterboxing, Vacation, Poi, Homebrewing, Mountain biking, Slacklining, Cabaret

Introduction: My name is Mrs. Angelic Larkin, I am a cute, charming, funny, determined, inexpensive, joyous, cheerful person who loves writing and wants to share my knowledge and understanding with you.