Dense persons guide to VPN on a Netgear Router

Hirize

Young grasshopper
Joined
Jul 8, 2017
Messages
36
Reaction score
17
First off this only covers my use with a Netgear Nighthawk AC1900 Model R7000.
This was purchased in late 2017. Installed after the cable modoem and then connected to a switch with POE (Power Over Ethernet) for the cameras. All cameras are connected directly to this switch.
I do not use a DVR all recordings are done to the MicroSD card inside the cameras.

I do think that most of the Netgear routers which support VPN as a "VPN server" would work the same way but remember I'm one of the 'Dense' people :)


The included instructions with the router do not really cover the VPN thing so find the users guide online. This gives a good step by step giude except on one thing and it is confusing to us dense people in a few other areas.

This is from what I have learned, I'm NO EXPERT and am still playing around on how some things work.

So the VPN creates a secure connection to the VPN Server (Netgear router). In this case it is your router at home/office.
With this secure connection you can connect to your home network from any internet connection, even where it may not be a safe connection like a Starbucks or a hotel wifi.
My cousin's husband works for a top 100 Corporation in the world in the computer security dept. He told me any free/open wifi connection like hotels are the first place hackers setup to steal login and passwords so a VPN is actually good practice for anyone who travels and connects to work or home networks while on the road.

Enough of that!!

Basic steps.

a) Activate the VPN server on the router
b) Download the configuration files from the router
c) Download and install the OpenVPN Client softwater
d) Extract and place the configuration files in the correct OpenVPN folder.
e) Rename the TAP network connection
f) Go outside of your home network and try connecting.

So when you use the VPN and connect you can login to the Netgear router or any other things attached to the home network like a printer, cameras, computer (if setup for it) or network storage device. (I'm still exploring all this but the cameras work great!!!)

First login to the router and follow the instructions to find the VPN area and to turn "ON" the VPN server. My router used the "OpenVPN" software.

1) I would suggest as far as mine went to check the "Enable VPN Service" and then click on the "Apply" button. I think this was my first mistake.

2) Now go to the "OpenVPN configuration package download" and click on the one you need. I use Win 10 so any other way from here on out is not what I'm doing.
When you get the download just place it in a folder to keep safe as you may want to use it for more than one device or you may need to update it anytime you make changes to your routers configuration. Keep this in mind!!!


3) Go here and download the correct file. I used the one pointed to with the red arrow. This is the "Stable" version as far as I can tell and it is the 64 bit version. In the area shown pick the correct one for your system.


4) Install this on your computer. I used all the default settings and like it says in the instructions just allow everything it asks for including the TAP Network Adapter.

5) If you have a choice do not allow it to start when Windows starts, no need to have this running when not in use.

6) Now you have to deal with this TAP network adaptor which really messed me up as it is not real clear. Here are the steps I took.
a) Start, Windows system, control panel
b) Network and Internet

c) View network status and tasks

d) Change adapter settings

e) Highlight the TAP-windows adapter and then click on "Rename this connection"
f) Rename it to what it says in the user guide. For me it was "NETGEAR-VPN

g) Close out all of the windows.
h) At this point and it may not ne required but I rebooted my computer so do what you like here.

7) You now need to take the zipped configuration files from step 2. Go to extract the files and place them in the c://Program Files/OpenVPN/config folder
On this one the Netgear instructions from the router tell you to place them in one location but the users guide tells you to place them where I just did. I used the first location and it did not work then the location from the users guide and POOF! it worked!!!

8) From what I know you cannot use the VPN service when connected to your own network. You will need to connect to a neighbors or go to a Starbucks. I actually was not able to test it until I got back to CA but once I tried it it worked GREAT!

So here is how you start the OpenVPN service and connect. (The instructions in the user guide are correct here but don't tell you everything clearly)

1) I had the icon for the OpenVPN client on my desktop and I right click it and choose "Run as administrator"
What this does is start the client which resides on the windows task bar (Lower bottom right of the windows screen) It may be hidden so you need to show it.

2) Right click on the task bar icon and choose "Connect"

3) a box will pop up on the screen and scroll through a bunch of stuff and the last line should be your routers IP address. If you see red lines scroll by or an ending error message you have issues......sorry!

4) Once connected the box will disappear after a few seconds and you can view your devices on the home network via file explorer. You can also open a browser and put in your routers IP address (internal and normally 192.168.1.1) to log into the router.

5) When you are done go back to the icon on the task bar, right click and choose "Disconnect". I like to right click again on it and choose "Exit" which closes the OpenVPN client. No need to have it running when not in use eh?

Now go explore and see what you can do and please as you find things report it here!!

That's my story and I'm sticking with it!! Pete
 

BubbaJoe

Getting the hang of it
Joined
Nov 29, 2017
Messages
96
Reaction score
21
Hahaha good write up. I got issues. As it loads after clicking connect I get a cert not enabled message. No idea what kind of cert or how to turn it on. Google is little help. One day ill figure it out.
 

Hirize

Young grasshopper
Joined
Jul 8, 2017
Messages
36
Reaction score
17
The zip file you download from the router in step 2 and place them in the folder noted in step 7.
Now I'm not real good at this so if you have done that and its not working then maybe something in your setup needs the files somewhere else?????
Also make sure that if you make any changes to the VPN section on the router you must download a new zip file and place the unzipped files in the same folder again overwriting the old ones.
Good luck!
 

flynreelow

Known around here
Joined
Dec 12, 2016
Messages
1,257
Reaction score
1,144
Hahaha good write up. I got issues. As it loads after clicking connect I get a cert not enabled message. No idea what kind of cert or how to turn it on. Google is little help. One day ill figure it out.
You need to make sure you are not connected to your home network via wifi or ethernet when trying to connect. Also, on the cell phone, make sure you are not connected to your home wifi, while at the same time trying to connect to the VPN
 

Hirize

Young grasshopper
Joined
Jul 8, 2017
Messages
36
Reaction score
17
Almost forgot that. My mistake the first time around. Go to a local Starbucks or some other place with wifi. Remember with a VPN you are secure in the connection.
 

achalmersman

Pulling my weight
Joined
Jan 26, 2017
Messages
267
Reaction score
116
Location
Delaware USA
Nice write up. I have this same router and just never took the time to do this. I dont have BI at my house, but there are other things it would be useful for.

Sent from my VS990 using Tapatalk
 

BubbaJoe

Getting the hang of it
Joined
Nov 29, 2017
Messages
96
Reaction score
21
How do I get the netgear phone client file to my phone?
 
Last edited:

Tizeye

Getting the hang of it
Joined
May 31, 2017
Messages
103
Reaction score
34
Location
Orlando, FL
Good advice going to an outside network to test. While successful at Starbucks, my work office network, and even overseas back to the States, have NEVER been able to connect from the local public library free wifi. Just as a guess, the administrator may be putting a security block on VPNs or at least known VPN client programs such as Tunnelblick as they limit patron browsing (i.e. porn browse/download concerns). So if you can't connect externally, try another site as it may not be you.
 

looney2ns

IPCT Contributor
Joined
Sep 25, 2016
Messages
15,643
Reaction score
22,911
Location
Evansville, In. USA
Good advice going to an outside network to test. While successful at Starbucks, my work office network, and even overseas back to the States, have NEVER been able to connect from the local public library free wifi. Just as a guess, the administrator may be putting a security block on VPNs or at least known VPN client programs such as Tunnelblick as they limit patron browsing (i.e. porn browse/download concerns). So if you can't connect externally, try another site as it may not be you.
You might try port 443 instead of the default. Most wouldn't be blocking this port as it's used for HTTPS.
 

Tizeye

Getting the hang of it
Joined
May 31, 2017
Messages
103
Reaction score
34
Location
Orlando, FL
The other nice thing about VPN's when away, in addition to checking cameras - particularly when getting and email/text alert - you can also bypass local blocks in the region where located. An NFL game (ESPN etc) may not be available for streaming in Europe, but the VPN tells it you are located at your home in the States and no problem with the broadcast. Likewise where programs shift to their sister site based on where you are (.uk, .de etc) and you want the US site (.com), it tricks it into thinking you are in the US.
 

BubbaJoe

Getting the hang of it
Joined
Nov 29, 2017
Messages
96
Reaction score
21
No luck. Got the file to my phone but still getting the same message. Changed the port and downloaded the new files but still same problem. No server cert enabled. Gotta try a different route. Openvpn is just not working for me. Thx for the help guys.
 

flynreelow

Known around here
Joined
Dec 12, 2016
Messages
1,257
Reaction score
1,144
No luck. Got the file to my phone but still getting the same message. Changed the port and downloaded the new files but still same problem. No server cert enabled. Gotta try a different route. Openvpn is just not working for me. Thx for the help guys.
You made sure your wifi is turned off first? And u are just on cell 3g or 4g?
 

BubbaJoe

Getting the hang of it
Joined
Nov 29, 2017
Messages
96
Reaction score
21
You made sure your wifi is turned off first? And u are just on cell 3g or 4g?
Yeah I made sure I was on 4g only. Triple checked everything, still no go. The server is behind a verizon 4g router. Im guessing the double nat screwed up the hand shake.
 

achalmersman

Pulling my weight
Joined
Jan 26, 2017
Messages
267
Reaction score
116
Location
Delaware USA
Is anybody experiencing an issue where OpenVPN / Negear is issuing a 192.168.254.x IP address to Android Clients even though the LAN is 192.168.1.x? This makes VPN pointless for me. Any idea how I can fix this? Quick googlefu seems as though its got to do with Android / TUN and idk how to fix it. Anyone with any ideas? Thanks

Sent from my VS990 using Tapatalk
 

bigredfish

Known around here
Joined
Sep 5, 2016
Messages
17,588
Reaction score
48,905
Location
Floriduh
I had the exact same problem.
VPN Primer for Noobs

What I did that I think fixed it

1- Chose the option "All sites on the internet and Home Network"
2- Rebooted the router and then after it came back up, rebooted the DVR
3- Connected via VPN and then opened a browser on my iphone and surfed the Interwebs

Then I opened iDMSS (gDMSS for you) and it worked!
 

achalmersman

Pulling my weight
Joined
Jan 26, 2017
Messages
267
Reaction score
116
Location
Delaware USA
I had the exact same problem.
VPN Primer for Noobs

What I did that I think fixed it

1- Chose the option "All sites on the internet and Home Network"
2- Rebooted the router and then after it came back up, rebooted the DVR
3- Connected via VPN and then opened a browser on my iphone and surfed the Interwebs

Then I opened iDMSS (gDMSS for you) and it worked!
Yea it hasn't worked for me. Ive tried Auto, Home Network Only, and All Sites on the internet and home network. It connects, but the android device is assigned a 192.168.254.x address
 

achalmersman

Pulling my weight
Joined
Jan 26, 2017
Messages
267
Reaction score
116
Location
Delaware USA
I think I got it figured out / fixed. I would prefer it be on the same subnet but I think this is working....I added a static route in the R8000 router. Seems to be working for now.
Destination IP: 192.168.254.0
Subnet Mask: 255.255.255.0
Gateway IP: 192.168.1.1
Metric: 2
 

Pilot04

Pulling my weight
Joined
Aug 1, 2017
Messages
281
Reaction score
163
I think I got it figured out / fixed. I would prefer it be on the same subnet but I think this is working....I added a static route in the R8000 router. Seems to be working for now.
Destination IP: 192.168.254.0
Subnet Mask: 255.255.255.0
Gateway IP: 192.168.1.1
Metric: 2
I tried your fix config with a static route on my R7000 but unfortunately, it didn't work for me on my ios device.
 

achalmersman

Pulling my weight
Joined
Jan 26, 2017
Messages
267
Reaction score
116
Location
Delaware USA
I tried your fix config with a static route on my R7000 but unfortunately, it didn't work for me on my ios device.
What is the ip scheme / subnet of your main network, and what is the ip being assigned to your ios device?

Sent from my VS990 using Tapatalk
 
Top