VPN client and IP address conflicts (2024)

roadkill401

macrumors 6502a

Original poster

Jan 11, 2015
509
186
  • Aug 9, 2024
  • #1

I know that Apple provides no support for VPN, so I am stuck on how to get around this.

Like most everyone here, I get my internet from a service provider not by buying a T1 or some network connection from the telecom giants. So I am stuck using their broadband modem/router to connect. This dictates some things like sadly for me the IP address scope that I can use. They are a!h here and force me to use a 192.168.2.x ip address space. Not that it really makes my life horrible.

But my kid is going to university and their house has internet too and also use the 192.168.2.x ip address range. This then causes the issue that they cannot VPN back to home.

I have the VPN server setup fine inside my home and it works just great for them to connect from any other location it seems other than their house as the VPN client on the macOS doesn't work like you'd expect it should or could. I have the IPSec setup fine and even have the checkbox to 'route all traffic through the VPN' but for whatever reason, because the IP address at their house is the same as mine here, the Mac cannot see my network when connected. so if they try and connect to any of the machines inside my 192.168.2.x network, the traffic doesn't get sent over the VPN at all, and just stays local to their house. If they go to a friends house and not change a single configuration or setting, it works fine as the friends have a different ip address set like 10.0.1.x. or perhaps 192.168.1.x. it is just if the two IP address ranges are the exact same that it doesn't work.

I can't change mine, and they don't have the power to force the house to change theirs.

Does anyone know of any work around that might work?

DeltaMac

macrumors G5
Jul 30, 2003
13,656
4,517
Delaware
  • Aug 9, 2024
  • #2

Does your VPN support have any suggestions?

  • Aug 9, 2024
  • #3

I'm no network expert but some thoughts as I went through something similar. There may be other (software) solutions though.
It comes down to the complexity of your home network and if you could afford a second router/access point:
I have the main router provided by my ISP in the 192.168.2.x ip address space.
I bought a second router/access point without any expensive modem functionality but a simple WAN port. That WAN port is connected to the main router to get internet access.
Said second router/access point is configured to the 192.168.4.x ip address space and all PCs are physically connected to it and WiFi as well as VPN are set up on it.

(I'm not from the US but for what it's worth, I use a 70€ FritzBox 4040 for that. https://en.avm.de/products/fritzbox/fritzbox-4040/)

Edit: For VPN to work on the second router, I had to forward the ports: 500, 4500 and 1701.

Last edited:

roadkill401

macrumors 6502a

Original poster

Jan 11, 2015
509
186
  • Aug 9, 2024
  • #4

DeltaMac said:

Does your VPN support have any suggestions?

what VPN support? I installed a VPN server at my house, and configured the vpn client on my kids Mac. The VPN server software say that nothing is wrong on their end. If the client doesn't direct the network packets to the server then what can they do about it? The problem is on the client end and as I sad Apple refuses to take any support for network issues seriously. they suggest that you post to the apple suggestion site and they will consider it. like as if that will ever happen

roadkill401

macrumors 6502a

Original poster

Jan 11, 2015
509
186
  • Aug 9, 2024
  • #5

arw said:

I'm no network expert but some thoughts as I went through something similar. There may be other (software) solutions though.
It comes down to the complexity of your home network and if you could afford a second router/access point:
I have the main router provided by my ISP in the 192.168.2.x ip address space.
I bought a second router/access point without any expensive modem functionality but a simple WAN port. That WAN port is connected to the main router to get internet access.
Said second router/access point is configured to the 192.168.4.x ip address space and all PCs are physically connected to it and WiFi as well as VPN are set up on it.

(I'm not from the US but for what it's worth, I use a 70€ FritzBox 4040 for that. https://en.avm.de/products/fritzbox/fritzbox-4040/)

Edit: For VPN to work on the second router, I had to forward the ports: 500, 4500 and 1701.

that is then doing double NAT that in network terms is considered a rather bad thing to do. what I am stuck is either on how to get the Apple built in client to function correctly. Or more likely how to force MacOS to properly handle the network correctly. if the issue is that the MacOS can't insert the VPN to act as the primary network interface and still allow it to then repackage all network requests into encrypted bundles and forward them off to the physical network interface that is connected to the wifi/ethernet then there isn't much that can be done. if its a MacOS limitation then even a third party vpn client won't do much.

Bigwaff

Contributor
Sep 20, 2013
2,346
1,637
  • Aug 9, 2024
  • #6

roadkill401 said:

I can't change mine, and they don't have the power to force the house to change theirs.

Does anyone know of any work around that might work?

You need 1:1 NAT enabled on the VPN tunnel... if your VPN implementation supports it.

Marco Klobas

macrumors 6502
Jul 14, 2017
458
915
Italy
  • Aug 9, 2024
  • #7

No network expert here too. AFAIK double NAT isn't bad per se: you just have to know what are you doing – taking into account that usually every setup is done twice (say, a port forwarding).

Back to your issue: maybe a tool like Tailscale could help.

  • VPN client and IP address conflicts (8)

Reactions:

gilby101

G

gilby101

macrumors 68030
Mar 17, 2010
2,763
1,534
Tasmania
  • Sunday at 9:55 PM
  • #8

Marco Klobas said:

Back to your issue: maybe a tool like Tailscale could help.

Tailscale is so much easier than VPN for remote access for a group of people.

You must log in or register to reply here.

VPN client and IP address conflicts (2024)
Top Articles
Destiny 2: The Best Hunter Solar 3.0 Build
Best Destiny 2 Hunter Builds Today (Episode 1 Meta)
Funny Roblox Id Codes 2023
Www.mytotalrewards/Rtx
San Angelo, Texas: eine Oase für Kunstliebhaber
Golden Abyss - Chapter 5 - Lunar_Angel
Www.paystubportal.com/7-11 Login
Steamy Afternoon With Handsome Fernando
fltimes.com | Finger Lakes Times
Detroit Lions 50 50
18443168434
Newgate Honda
Zürich Stadion Letzigrund detailed interactive seating plan with seat & row numbers | Sitzplan Saalplan with Sitzplatz & Reihen Nummerierung
978-0137606801
Nwi Arrests Lake County
Missed Connections Dayton Ohio
Justified Official Series Trailer
London Ups Store
Committees Of Correspondence | Encyclopedia.com
Jinx Chapter 24: Release Date, Spoilers & Where To Read - OtakuKart
How Much You Should Be Tipping For Beauty Services - American Beauty Institute
How to Create Your Very Own Crossword Puzzle
Apply for a credit card
Unforeseen Drama: The Tower of Terror’s Mysterious Closure at Walt Disney World
Ups Print Store Near Me
How Taraswrld Leaks Exposed the Dark Side of TikTok Fame
University Of Michigan Paging System
Dashboard Unt
Access a Shared Resource | Computing for Arts + Sciences
2023 Ford Bronco Raptor for sale - Dallas, TX - craigslist
Healthy Kaiserpermanente Org Sign On
Restored Republic
Progressbook Newark
Lawrence Ks Police Scanner
3473372961
The Latest: Trump addresses apparent assassination attempt on X
In Branch Chase Atm Near Me
Appleton Post Crescent Today's Obituaries
Craigslist Red Wing Mn
American Bully Xxl Black Panther
Ktbs Payroll Login
Jail View Sumter
Thotsbook Com
Funkin' on the Heights
Caesars Rewards Loyalty Program Review [Previously Total Rewards]
Marcel Boom X
Www Pig11 Net
Ty Glass Sentenced
Michaelangelo's Monkey Junction
Game Akin To Bingo Nyt
Ranking 134 college football teams after Week 1, from Georgia to Temple
Latest Posts
Article information

Author: Mrs. Angelic Larkin

Last Updated:

Views: 5653

Rating: 4.7 / 5 (47 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Mrs. Angelic Larkin

Birthday: 1992-06-28

Address: Apt. 413 8275 Mueller Overpass, South Magnolia, IA 99527-6023

Phone: +6824704719725

Job: District Real-Estate Facilitator

Hobby: Letterboxing, Vacation, Poi, Homebrewing, Mountain biking, Slacklining, Cabaret

Introduction: My name is Mrs. Angelic Larkin, I am a cute, charming, funny, determined, inexpensive, joyous, cheerful person who loves writing and wants to share my knowledge and understanding with you.