• To anyone looking to acquire commercial radio programming software:

    Please do not make requests for copies of radio programming software which is sold (or was sold) by the manufacturer for any monetary value. All requests will be deleted and a forum infraction issued. Making a request such as this is attempting to engage in software piracy and this forum cannot be involved or associated with this activity. The same goes for any private transaction via Private Message. Even if you attempt to engage in this activity in PM's we will still enforce the forum rules. Your PM's are not private and the administration has the right to read them if there's a hint to criminal activity.

    If you are having trouble legally obtaining software please state so. We do not want any hurt feelings when your vague post is mistaken for a free request. It is YOUR responsibility to properly word your request.

    To obtain Motorola software see the Sticky in the Motorola forum.

    The various other vendors often permit their dealers to sell the software online (i.e., Kenwood). Please use Google or some other search engine to find a dealer that sells the software. Typically each series or individual radio requires its own software package. Often the Kenwood software is less than $100 so don't be a cheapskate; just purchase it.

    For M/A Com/Harris/GE, etc: there are two software packages that program all current and past radios. One package is for conventional programming and the other for trunked programming. The trunked package is in upwards of $2,500. The conventional package is more reasonable though is still several hundred dollars. The benefit is you do not need multiple versions for each radio (unlike Motorola).

    This is a large and very visible forum. We cannot jeopardize the ability to provide the RadioReference services by allowing this activity to occur. Please respect this.

Struggling with TRBO IP Site Connect over VPN

Dax50

Member
Joined
Oct 19, 2022
Messages
28
Hey there,
I have a problem with the installation of a simple IPSC connection. The master repeater is a DR3000. The peer is a SLR5500. The connection runs over an OpenVPN server and 4G (Latency under 90ms) . Attached is a setup diagram.
I have programmed both repeaters and also set up port forwarding in both repeaters for ports 50000 to 50010.
The actual problem seems to be that the peer repeater is not registering properly with the master.
However, I can see the master from both networks (local at the master and local at the peer) with RDAC, but no peer.

Does anyone have any idea what the problem is?
 

Attachments

  • Schema.png
    Schema.png
    51.1 KB · Views: 32

celltech25

Member
Joined
Feb 5, 2006
Messages
81
Location
Benton
Never done it over open vpn. I'm assuming you don't have a static IP at the master since you are using the VPN to get a static?.

We typically run l2tp tunnel with eoip to keep all repeaters in the same subnet and it works great.

But without more info I would think your issue is one based around a firewall
 

Firebuff880

Member
Joined
Aug 28, 2006
Messages
660
Location
Boynton Beach, FL
So the most common issue in this would likely be NAT maps between sites and between the IP Subnets of the end points.

Check out Wayne's Blog for some tips and his you tube channel for some how to videos.

 

Dax50

Member
Joined
Oct 19, 2022
Messages
28
Hey,

i‘m using openvpn, because my cellular isp usually only offer private IPs.

I use the provider mdex, which offer sim cards with integrated vpn and also a openvpn client for applications without cellular. I used this openvpn client for the Master. The peers uses sim cards with integrated VPN Connection.

I‘m Sure, that my NAT works.
Attached the Wireshark Logs.
On the left is my master recorded between router and repeater. The master has the 192.168.1.2 or the wan address 172.21.25.4.

On the right is the peer recorded between router and repeater. The peer has the internal IP 192.168.178.102 and the WAN IP 10.183.30.7.

Looks to me like the packets are going through with the correct ports.
 

Attachments

  • D997FD03-EE88-4106-A9A1-9D46103D5B55.png
    D997FD03-EE88-4106-A9A1-9D46103D5B55.png
    253.3 KB · Views: 17

TampaTyron

Beep Boop, Beep Boop
Premium Subscriber
Joined
Feb 1, 2010
Messages
1,099
Location
Phoenix, AZ
please post screenshots or send codeplugs for the repeaters, specifically the Link establishment portion of the codeplug. Are you pointing to the WAN IP? Are the repeaters on similar firmware? Are the master and peer UDP ports unique? Are the master and peer Radio IDs unique? TT
 

Dax50

Member
Joined
Oct 19, 2022
Messages
28
Sure.
The Master has a static LAN address while the peer uses dhcp.
Attached the Screenshots.
 

Attachments

  • 8A347DCC-1605-4AF0-B5C3-ACC0C74CF449.png
    8A347DCC-1605-4AF0-B5C3-ACC0C74CF449.png
    61.9 KB · Views: 16
  • AE9DD7F1-04F3-44F3-B522-0427EA1F816B.png
    AE9DD7F1-04F3-44F3-B522-0427EA1F816B.png
    153.7 KB · Views: 17
  • 68254E79-0F6D-457D-860B-D26B4CD14081.png
    68254E79-0F6D-457D-860B-D26B4CD14081.png
    62.8 KB · Views: 16

radionx

Member
Joined
May 31, 2022
Messages
150
BOTH endpoints seem to be CGNAT WAN if I am not mistaken.

172.21.25.4 and 10.183.30.7
 
Last edited:

lynchy135

Member
Feed Provider
Joined
Jul 31, 2019
Messages
150
Am I reading it correctly that on the peer you have the Master IP as the WAN IP of the Cellular router? If you have a VPN, why are you using the WAN IPs as the Master? Can 192.168.178.102 get to 192.168.1.2 directly?

Additionally, is the VPN established? Some cellular networks don't let internal users talk to each other for security reasons. If that is the case you may need to VPN peer to a public server as the convergence point.
 

Dax50

Member
Joined
Oct 19, 2022
Messages
28
Am I reading it correctly that on the peer you have the Master IP as the WAN IP of the Cellular router? If you have a VPN, why are you using the WAN IPs as the Master? Can 192.168.178.102 get to 192.168.1.2 directly?

Additionally, is the VPN established? Some cellular networks don't let internal users talk to each other for security reasons. If that is the case you may need to VPN peer to a public server as the convergence point.
Exactly. The Master WAN IP is on the Peer.
192.168.178.102 is the internal IP of the peer router. The Router is a vpn Client in the VPN WAN Network with the IP 10.183.30.7.

The Same is at the Master Site. 192.168.1.2 is the internal IP of the Master Router (Network between Master Router and Master Repeater). The Master Router also Act as a vpn Client with the vpn wan ip 172.21.25.4

VPN is established and i can ping 10.183.30.7 from the Master Router itself(172.21.25.4) and vice versa.
 

lynchy135

Member
Feed Provider
Joined
Jul 31, 2019
Messages
150
Screenshot 2023-04-11 at 12.54.42 PM.png

This is what I have in my mind. Can 192.168.178.102 get to 192.168.1.2 directly? If you have a VPN connecting the two networks you should have the two communicate with their internal IPs, not their WAN IPs.
 

Dax50

Member
Joined
Oct 19, 2022
Messages
28
View attachment 139949

This is what I have in my mind. Can 192.168.178.102 get to 192.168.1.2 directly? If you have a VPN connecting the two networks you should have the two communicate with their internal IPs, not their WAN IPs.
The VPN is only on the WAN side, so i can't ping the internal IPs.
Maybe i need a L2TP VPN on the internal site. But I can't get the routing to work for L2TP Client to Internal LAN devices.
 

Attachments

  • VPN.drawio.png
    VPN.drawio.png
    33.9 KB · Views: 7

belvdr

No longer interested in living
Joined
Aug 2, 2013
Messages
2,567
The VPN is only on the WAN side, so i can't ping the internal IPs.
Maybe i need a L2TP VPN on the internal site. But I can't get the routing to work for L2TP Client to Internal LAN devices.
The VPN is on the WAN/public side, but that is what allows you to use the internal IPs, just like they are internal to one another, as long as the VPN is configured that way.
 

lynchy135

Member
Feed Provider
Joined
Jul 31, 2019
Messages
150
The VPN is on the WAN/public side, but that is what allows you to use the internal IPs, just like they are internal to one another, as long as the VPN is configured that way.
it sounds like you are missing VPN configuration or static routing. The only other thing I would try is Port Forwarding. This isn't nearly as secure as a VPN.
 

Dax50

Member
Joined
Oct 19, 2022
Messages
28
I think VPN is not the best term. I'm using these SIM cards with static IP.

I think you can look at this as if there was no vpn.
I can reach both routers on the WAN side. This effectively creates a normal network.

Therefore I have set up port forwarding on both routers, which seems to work, see wireshark logs.
 

Dax50

Member
Joined
Oct 19, 2022
Messages
28
I think the best way would be, to initialize a L2TP connection between the routers to share the same subnet. Encryption is ensure by the openvpn "WAN VPN".
I use Teltonika Routers and successfully initialize the L2TP connection between the two routers.
I used this manual: L2TP configuration examples - Teltonika Networks Wiki

If i undestand this correct, every L2TP client gets an IP address by the L2TP server. But how can i route an ethernet interface to the virtual L2TP subnet?
 

lynchy135

Member
Feed Provider
Joined
Jul 31, 2019
Messages
150
I see what it is. It looks like you’re using a cellular provided private network. I think using port forwarding should be fine, but you should verify with cell provider that it’s actually a private backbone that connects you’re two routers together.
 

Dax50

Member
Joined
Oct 19, 2022
Messages
28
I see what it is. It looks like you’re using a cellular provided private network. I think using port forwarding should be fine, but you should verify with cell provider that it’s actually a private backbone that connects you’re two routers together.
The provider says it is a private network. Access from the Internet outside is direct not possible, but also not necessary.

I thought port forwarding is just fine, but it didn't work :-(
 

Similar threads

Top