DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Mixing Client to Site and Site to Site VPN's
- lsystems
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 11
- Thank you received: 0
23 Sep 2008 15:19 #52053
by lsystems
Mixing Client to Site and Site to Site VPN's was created by lsystems
Hi All,
Currently we have a Draytek 2900 router (via a single NAT'd IP address) and run various types (Cisco, Nortel etc) of IP-Sec based VPN clients (using pass though) behind the firewall to provide remote access to our customers.
We would like if possible to also be able to set IP-Sec based Site to Site VPN's where customers request it so no client software is required. Am I correct in thinking that this is not possible with our single box solution as IP-Sec traffic is either passed through or not...?
Would it perhaps be possible to introduce a VPN server behind the firewall (in a DMZ?) to support the site to site VPN's without interfering with the existing client to site VPN's we already have running via pass-through behind the firewall.
Any advice/experiences would be most welcome.
Regards,
David
Currently we have a Draytek 2900 router (via a single NAT'd IP address) and run various types (Cisco, Nortel etc) of IP-Sec based VPN clients (using pass though) behind the firewall to provide remote access to our customers.
We would like if possible to also be able to set IP-Sec based Site to Site VPN's where customers request it so no client software is required. Am I correct in thinking that this is not possible with our single box solution as IP-Sec traffic is either passed through or not...?
Would it perhaps be possible to introduce a VPN server behind the firewall (in a DMZ?) to support the site to site VPN's without interfering with the existing client to site VPN's we already have running via pass-through behind the firewall.
Any advice/experiences would be most welcome.
Regards,
David
Please Log in or Create an account to join the conversation.
- j.baker
- Offline
- Junior Member
Less
More
- Posts: 55
- Thank you received: 0
23 Sep 2008 18:13 #52058
by j.baker
Regards
John Baker
Vigor2820 series with firmware 3.3.5.2_RC2
ADSL
Replied by j.baker on topic Mixing Client to Site and Site to Site VPN's
I do not know the specs of the 2900, but if you can create multiple lan-lan IPSEC tunnels, then it should do what you want.
However, each locations must be of a separate IP address subnet on their LAN. The LAN-LAN tunnel set are setup, and then an IP route is setup to go over the tunnel.
If anyone knows different, please correct me.
However, each locations must be of a separate IP address subnet on their LAN. The LAN-LAN tunnel set are setup, and then an IP route is setup to go over the tunnel.
If anyone knows different, please correct me.
Regards
John Baker
Vigor2820 series with firmware 3.3.5.2_RC2
ADSL
Please Log in or Create an account to join the conversation.
- louis-m
- Offline
- Member
Less
More
- Posts: 131
- Thank you received: 0
26 Sep 2008 20:38 #52103
by louis-m
2820 = 3.3.2_RC5
2950 = 3.2.4
Replied by louis-m on topic Mixing Client to Site and Site to Site VPN's
john's right. you need to make sure your remote site is on a different subnet. if not, you will have to make a change to the network at one site. then its as simple as making an ipsec site to site vpn which will be transparent to the end users.
you can then use an ipsec/pptp client for mobile devices that are outside the lan subnets. drayteks will perform this with ease.
you can then use an ipsec/pptp client for mobile devices that are outside the lan subnets. drayteks will perform this with ease.
2820 = 3.3.2_RC5
2950 = 3.2.4
Please Log in or Create an account to join the conversation.
- lsystems
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 11
- Thank you received: 0
09 Aug 2010 15:35 #63241
by lsystems
Replied by lsystems on topic Mixing Client to Site and Site to Site VPN's
Just got round to testing this and am having little success. I'm testing with a Draytek 2820 running 3.3.3_232201. The details I've been given to connect with are:-
IP-Sec: Site to Site
Peer Gateway IP: A public IP
Pre-shared Key: As agreed
Phase 1
Encryption: AES-256
Hash : SHA1
Group: DH2
Lifetime : 1440 (minutes)
Phase 2
Encryption: AES-256
Hash : SHA1
Group: DH2
Lifetime : 3600 Secs
I have set this up as follows:-
VPN and Remote Access >> LAN to LAN
Call Direction : Dial Out
Dial Out Settings
Type: IPSec Tunnel
Server IP/Host Name: Peer Gateway IP as shown above
IKE Authentication Method
Pre-Shared Key : key as agreed above
IPSec Security Method
High(ESP): AES With Authentication
Advanced
IKE phase 1 mode : Main Mode
IKE phase 1 proposal : AES256_SHA1_G2
IKE phase 1 key lifetime : 86,400
IKE phase 2 key lifetime : 3600
Perfect Forward Secret : No
Local ID :
TCP/IP Network Settings
My WAN IP : 0.0.0.0
Remote Gateway IP : Peer Gateway IP as shown above
Remote Network IP : IP of the server we want to connect to
Remote Network Mask : 255.255.255.255
RIP Direction: Disable
From 1st subnet : Route
If we open up a connection via RDP to the Remote Network IP, the VPN Log using syslog, shows:-
Dialing Node(Name): Peer Gateway IP as shown above
And that is it, nothing else gets written to the log. The VPN hardware I'm connecting to is a Checkpoint Firewall apparently. I suspect a problem with the Remote Network IP and mask, but I'm entering the values I've been given. Any suggestions would be most welcome.
Regards,
David
IP-Sec: Site to Site
Peer Gateway IP: A public IP
Pre-shared Key: As agreed
Phase 1
Encryption: AES-256
Hash : SHA1
Group: DH2
Lifetime : 1440 (minutes)
Phase 2
Encryption: AES-256
Hash : SHA1
Group: DH2
Lifetime : 3600 Secs
I have set this up as follows:-
VPN and Remote Access >> LAN to LAN
Call Direction : Dial Out
Dial Out Settings
Type: IPSec Tunnel
Server IP/Host Name: Peer Gateway IP as shown above
IKE Authentication Method
Pre-Shared Key : key as agreed above
IPSec Security Method
High(ESP): AES With Authentication
Advanced
IKE phase 1 mode : Main Mode
IKE phase 1 proposal : AES256_SHA1_G2
IKE phase 1 key lifetime : 86,400
IKE phase 2 key lifetime : 3600
Perfect Forward Secret : No
Local ID :
TCP/IP Network Settings
My WAN IP : 0.0.0.0
Remote Gateway IP : Peer Gateway IP as shown above
Remote Network IP : IP of the server we want to connect to
Remote Network Mask : 255.255.255.255
RIP Direction: Disable
From 1st subnet : Route
If we open up a connection via RDP to the Remote Network IP, the VPN Log using syslog, shows:-
Dialing Node(Name): Peer Gateway IP as shown above
And that is it, nothing else gets written to the log. The VPN hardware I'm connecting to is a Checkpoint Firewall apparently. I suspect a problem with the Remote Network IP and mask, but I'm entering the values I've been given. Any suggestions would be most welcome.
Regards,
David
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek