What's new

Asus RT-AC87U remote access question

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Ojee

Occasional Visitor
I have an RT-AC87U running the latest MerlinWRT on it, and I'm very happy with it. When I'm out the door, I use a NAS with a VPN server running on it to connect to my network, and check in on my router.

This works fine with the setting "Allow only specified IP address" switched to NO under "Remote Access Config" on the Systems tab.

To increase security, I would like to switch it on. However when I do, I can't access the router anymore through my VPN as I used to. I tried adding the dynamic IP assigned by the VPN to the list, but it still won't allow me access. I feel like I'm missing something. What am I doing wrong?
 
Just to be clear.... Your VPN server is running on your NAS not the router. Correct?

The Remote Access Config in the router's GUI only applies to accessing the router GUI. Not anything else, like your NAS.
 
My VPN is running on my NAS, and I'm trying to access my router over the local network. However, it won't let me. I can access the router from the local network just fine, just not through my VPN.
 
OK.

What IP address does your VPN client appear to have and how does that compare to your LAN address range? For example, is your client 10.8.0.3 and your LAN 192.168.1.x.
 
Yeah that sounds about right. But when I add a rule allowing 10.x.x.x access, it does not work.
 
OK I'll have to think about this.

On the router under Remote Access Config can you try also enabling Web Access from WAN. You'll have to use HTTPS instead of HTTP if that is what you've been using. I'm just wondering if the router is classifying your VPN client as "web" because it's IP address doesn't match the LAN.
 
OK I'll have to think about this.

I'm just wondering if the router is classifying your VPN client as "web" because it's IP address doesn't match the LAN.
But if it were classifying it as as web, then it shouldn't work regardless if "Allow only specified IP address" switched to NO or YES? But it does with it switched to NO.
 
But if it were classifying it as as web, then it shouldn't work regardless if "Allow only specified IP address" switched to NO or YES? But it does with it switched to NO.
Logically yes. But I was just speculating that the logic might be broken when you select that option. Just thought it was worth a try, that's all.

There was a slightly similar discussion here. IIRC in that case the NAS which was running the VPN server was masquerading the incoming connections so that instead of the client having a 10.8.0.x address it had the VPN server's address. Perhaps your VPN server has that option?
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top