Page 1 of 1

Connectivity Between Host OS & Guest OS gets lost on VPN

Posted: 17. Feb 2015, 16:43
by khajan
Hi All,
I am facing a weird situation, where the connectivity between HOST OS(windows 7) and guest OS(windows 2008 enterprise server) gets lost whenever i open a VPN connectivity to connect to my Integration/Test environments. VPN client is (Juniper Networks\Network Connect 7.1.12) and DragNet. I have configured a host only network and the attached file shows the IP configs. Before VPN the ping works but as soon as it gets connected the PING between HOST & GUEST stops.
Is there someway that with VPN the PING works, (Route add ) or something static which can be configured to make this work.(I am not experienced in networking) so if somebody have a solution or faced this kind of issue and resolved it kindly let me know the details. If there are more details required let me know.

Host OS - IP Config All

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . : ******
Description . . . . . . . . . . . : Intel(R) Ethernet Connection I218-LM
Physical Address. . . . . . . . . : EC-F4-BB-1B-A1-E2
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 160.110.194.34(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Monday, February 16, 2015 9:32:01 AM
Lease Expires . . . . . . . . . . : Tuesday, February 17, 2015 11:46:04 AM
Default Gateway . . . . . . . . . : 160.110.194.1
DHCP Server . . . . . . . . . . . : 160.110.193.11
DNS Servers . . . . . . . . . . . : 160.110.138.24
160.110.138.26
NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter VirtualBox Host-Only Network:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : VirtualBox Host-Only Ethernet Adapter
Physical Address. . . . . . . . . : 08-00-27-00-F4-31
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 192.168.119.1(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
NetBIOS over Tcpip. . . . . . . . : Enabled


ping to 192.168.119.103(Guest) works

Guest OS- IP Config All

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Desktop Adapter
Physical Address. . . . . . . . . : 08-00-27-B4-24-13
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 192.168.119.103(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.119.1
NetBIOS over Tcpip. . . . . . . . : Enabled


ping to 192.168.119.1(Host) works


===================================================== After VPN ==========================
Host OS - IP Config All

This entry is added to the above Host IP configuration and all other remains the same

Ethernet adapter Local Area Connection* 12:

Connection-specific DNS Suffix . : ******
Description . . . . . . . . . . . : Juniper Network Connect Virtual Adapter
Physical Address. . . . . . . . . : 00-FF-B0-1B-55-07
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 10.11.244.125(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.255
Lease Obtained. . . . . . . . . . : Monday, February 16, 2015 2:20:56 PM
Lease Expires . . . . . . . . . . : Monday, February 23, 2015 2:20:55 PM
Default Gateway . . . . . . . . . :
DHCP Server . . . . . . . . . . . : 10.200.200.201
DNS Servers . . . . . . . . . . . : 155.16.44.30
204.148.236.3
Primary WINS Server . . . . . . . : 155.16.44.24
NetBIOS over Tcpip. . . . . . . . : Enabled

After VPN the ping to 192.168.119.103(Guest) stops working and ping to 192.168.119.1(Host) also stops working.

Re: Connectivity Between Host OS & Guest OS gets lost on VPN

Posted: 21. Feb 2015, 02:34
by noteirak
That's not an issue. It's a feature of the Juniper client (or other corporate targeted VPN solution like Cisco) and the point of VPN.
Basically, all your traffic (even replies) is sent in the VPN tunnet. You can confirm by sniffing the VPN interface with wireshark. To disable this, there is usually a setting called "Split Tunneling" which you need to enable.
This is only a matter of configuring appropriately the Juniper client or server.