Reach a local IP via VPN
Solved
tmartin
Posted messages
185
Status
Member
-
brupala Posted messages 111154 Registration date Status Member Last intervention -
brupala Posted messages 111154 Registration date Status Member Last intervention -
Hello,
How to reach the IP 192.168.1.1 of a Livebox via VPN (installed on DSM Synology)
P.S.: Orange not updating anything, remote access becomes impossible after browser updates that no longer allow exceptions for missing/invalid certificates, etc.
I thought that by reaching the local network via VPN... except that local IPs remain those of the calling computer.
I read somewhere there was a config per IP range... but here it’s 192.168.1.1 gateway, DHCP server... so it would be necessary to explain to the browser that we want the local “distanced” IP... or have a switch, local or remote local IP... in short... is there a way? (a way per VPN, not a workaround suggesting changing the Livebox or using an old computer, or an old browser on a portable device... 5yous)
thanks
How to reach the IP 192.168.1.1 of a Livebox via VPN (installed on DSM Synology)
P.S.: Orange not updating anything, remote access becomes impossible after browser updates that no longer allow exceptions for missing/invalid certificates, etc.
I thought that by reaching the local network via VPN... except that local IPs remain those of the calling computer.
I read somewhere there was a config per IP range... but here it’s 192.168.1.1 gateway, DHCP server... so it would be necessary to explain to the browser that we want the local “distanced” IP... or have a switch, local or remote local IP... in short... is there a way? (a way per VPN, not a workaround suggesting changing the Livebox or using an old computer, or an old browser on a portable device... 5yous)
thanks
5 answers
-
Hello,
> following updates of browsers that no longer allow exceptions for missing/invalid certificates
Browsers still allow HTTP, and also exceptions for certificates in HTTPS. This will probably always be the case because companies manage their own certificates or their own CA for internal services, so there must be a way to authorize them in the browser. It would be frowned upon to impose a list of public CAs.
But it's true that the button is better hidden; you need to develop the details when the alert appears to find it.
> except that local IPs remain those of the calling computer.
That's the problem of non-unique private networks (overlapping) like 192.168.1.0/24.
Reason enough to consider IPv6 with its unique local addresses (fdxx).
If you look at your computer's routing table, once connected to VPN, you will immediately understand what is happening. The routing to 192.168.1.0/24 continues to go through the physical network (RJ-45 or WiFi interfaces) because your computer must be able to reach the local box (192.168.1.1) to use it as a gateway to access the VPN server via Internet.
The simple solution: change the network used on one side (local) or the other so there is no longer this network overlap.
The hack solution: Instead of typing 192.168.1.1 in your browser, type 192.168.99.1 (for example, let's avoid using another popular network). Your computer will route it through the VPN. On the VPN server side, you can map between 192.168.99.x and 192.168.1.x. The mapping must be two-way: VPN -> LAN (on the VPN server side) and LAN (on the VPN side) -> VPN. https://www.frozentux.net/iptables-tutorial/iptables-tutorial.html#NETMAPTARGET -
Hi,
otherwise, IPv6 addresses are good too ...
--
and ... Voili Voilou Voila ! -
Hello,
Historically, it was enough to enter http:\\myWANIPAddress using, if needed, an IP redirector for dynamic IP addresses to access more readily, and except for a somewhat complicated setup, directly to the Box's administration page instead of the local machine we wanted to reach.
This has been considered a vulnerability, and to my knowledge there is no longer any way (except via the My Livebox app on a mobile device that verifies the Orange account credentials) to access it if the calling IP is not part of the local network, which is the case when using a VPN.
Plan B is to take control of the target computer via AnyDesk, TeamViewer or equivalent, everything then happening as if we were physically in front of that computer; I will be told that this is not possible if the Livebox is down, but in that last case, you will also not be able to access its administration interface. -
@brucine
teamviewer blocks you constantly on the pretext that you’re a pro and you don’t do anything with their complaint procedure (I tried several times and ended up uninstalling) - the others I know, like simply Windows Remote Desktop or what the staff of my professional software uses during maintenance, require being in front of the machine for activation on demand. But if you have an equivalent as flexible as TeamViewer (with monitoring included) and that doesn’t cost a hefty annual subscription to use just a few times / year ... I’m interested.
@avion-f16
We, in all the forums I’ve seen, especially Orange forums with the staff who added another layer); would be very honored if you could give us the method of the hidden button or command to indicate an exception to Chrome or Firefox for example, for now the message was "they removed it"
I’ve spent hours still adding exceptions where it was proposed, or disabling certificate checking, strictly no consequence and still this message, only informative, of access denial.
(yes I know what this "continue anyway" is, but it doesn’t concern this kind of scenario - it appears on almost all sites we try to reach with Chrome on Seven... from an old laptop I left in my RS, anyway, because with an old desktop panel under Seven, it doesn’t do that ???)
Well, with my laptop, and at work, I am under W10 with the latest browser versions and it still blocks
Orange, or rather Livebox, since with a TP Link, it works, only allows remote administration via https, with a dedicated port number ... at least until now where the Orange certificate is declared invalid or missing (under Chrome / Firefox or vice versa I don’t remember)
I’ll check your mapping tip, thanks
I also found a portable Firefox ESR that had served me to configure an IPCam under Java ... I’ll try as well, when I’m not at home anymore, so after this weekend, from work.-
All remote access software (well, almost) charge for commercial use, otherwise Teamviewer often considers it the case even when it isn't true. Anydesk is no exception to the rule, but I have never seen their billing despite professional use, and it is perfectly capable of running in silent mode once the target machine is configured during the first connection, and free of charge. I have heard good things about Ammyy; I have never used it. Different flavors of VNC are of course free, but sometimes hide unpleasant surprises behind certain boxes; in any case I could never get one to work behind a Livebox Pro.
-
The button to bypass security must be hidden if the site uses HSTS:
https://datatracker.ietf.org/doc/html/rfc6797#section-12.1
There are several ways to access the site anyway:
- Ask the browser to forget everything about the site. The next access should allow adding the exception.
- Capture the certificate by another means and add it in the browser (via the certificate manager)- ?????
I don’t see any way to hide anything, nor does removing cookies and other caches change anything (besides, using another browser doesn’t yield more results), let alone capture a certificate declared invalid or non-existent according to browsers! The problem comes from Orange which forces https without offering any other option, and up-to-date browsers which no longer allow bypassing:
in the RFC you linked, I read that indeed, the user has no recourse left!
Have you tried reaching a Livebox login page? (with an up-to-date browser)
Anyway, in my personal opinion, it’s a false sense of security, so seriously counterproductive: you cannot reach yourself under the pretext of security (?) but you can be quietly scammed on a French site, with a French mobile number that impersonates a French merchant up to the SIRET number (but what is the police doing); an example? "cycles stock" impersonating "cycles volt", or to stay in electric bikes, since these are scams running into thousands of euros, "velo market" impersonating "mon vélo électrique"… fraudulent sites are legion and all are HTTPS with a valid certificate.
Since I have you here, I don’t see how to redirect a local IP to another: I know how to declare a port number to redirect to a local IP, with or without port redirection to another... but I don’t see where to redirect a local IP to another? (trying this addressing at 99.x)
Thank you - Do not hesitate to share the remote administration access address; up to now, no certificate alert has ever prevented me from accessing a service. It is only your box’s public IP address (and the port), an address known to sites you visit (and the port can be found by scanning). It is not a security risk to share it. If you prefer, you can send it to me via a private message.
To capture the certificate, you can do it with openssl.
For example:openssl s_client -showcerts -servername forums.commentcamarche.net -connect forums.commentcamarche.net:443 </dev/null 2>/dev/null
Regarding the mapping, it should be done at the VPN server level rather than on the box. It is possible (even likely) that the feature is not available on Synology. But with an OpenVPN on Linux, it is possible via iptables.
-
-
Hello,
If you are using the Synology "VPN Server" package and you have configured an OpenVPN VPN:
Just check the box, re-export your config and reinstall it on your remote device.
Tutorial: HERE
-
Hi,
In that case, the NAS server must also know how to perform routing.
And as explained above, if the client LAN IP network is the same as the server's, routing is impossible, except by configuring static routing on a single IP address, such as
route add 192.168.1.1 masq 255.255.255.255 toward VPN server.
-