# Accessing devices inside Digi Network

**URL:** <https://forums.digi.com/t/accessing-devices-inside-digi-network/22968>\
**Category:** Digi TransPort WR (Series)\
**Tags:** vpn\
**Created:** [February 24, 2022, 1:37pm UTC](https://forums.digi.com/t/accessing-devices-inside-digi-network/22968 "2022-02-24T13:37:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![NorthGuard](https://avatars.discourse-cdn.com/v4/letter/n/3be4f8/32.png) [@NorthGuard](https://forums.digi.com/u/NorthGuard)\
**Post date:** [February 24, 2022, 1:37pm UTC](https://forums.digi.com/t/accessing-devices-inside-digi-network/22968/1 "2022-02-24T13:37:45Z")

</div>

Scenario:  
HQ has firewall and LAN IP segment of 192.168.90.x

Digi WR31 in the field has static WAN IP over cellular ( Verizon ) and LAN IP segment of 10.90.33.x Eth0 on Digi is 10.90.33.5

HQ and Digi are connected via an IPSec VPN Tunnel

Issue:  
Once the tunnel is up, I can connect to the web interface of the Digi on 10.90.33.5 and can also ping that interface.

There is a switch connected to Eth0 and devices connected to that switch ( all are on the 10.90.33.x network )… but… I can’t ping any of those devices or connect to them from HQ.

If SSH into the Digi, I can ping them from inside the Digi, which tells me there is a config issue on the Digi.

Firewall is only enabled on the PPP1 interface.

---

<div class="post-metadata">

**Author:** ![NicholasYourIoT](https://sea2.discourse-cdn.com/flex016/user_avatar/forums.digi.com/nicholasyouriot/32/27_2.png) [@NicholasYourIoT](https://forums.digi.com/u/NicholasYourIoT)\
**Post date:** [March 9, 2022, 7:33pm UTC](https://forums.digi.com/t/accessing-devices-inside-digi-network/22968/2 "2022-03-09T19:33:04Z")

</div>

If you can connect to the Digi via SSH it is going to be either your near end/far end subnets in the ipsec tunnel or a gateway issue in the far end device.

You can see this by tracing ICMP on the ethernet interface of the WR31 and seeing if you get a response.

A poor mans way of testing this is by turning on “eth 0 do\_nat 2” and seeing if ping works to the end device. If that works it is 100% the end device gateway.

Nicholas Wilson  
Your IoT  
[https://www.YourIoT.com.au](https://www.YourIoT.com.au)

---

<div class="post-metadata">

**Author:** ![garridog](https://avatars.discourse-cdn.com/v4/letter/g/919ad9/32.png) [@garridog](https://forums.digi.com/u/garridog)\
**Post date:** [October 18, 2022, 7:21am UTC](https://forums.digi.com/t/accessing-devices-inside-digi-network/22968/3 "2022-10-18T07:21:40Z")

</div>

Hello,

Can you share your eroute and LAN config?
