DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
lan to lan settings
- jenodorf
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 16
- Thank you received: 0
22 Aug 2009 11:33 #57354
by jenodorf
lan to lan settings was created by jenodorf
Hi
I've had several emails asking me for the settings I used to get a Lan to lan vpn working.
Have to say I'm not a VPN expert and the Lan was kindly setup by Draytek support (3 cheers) I took a screen dump so I could replicate their settings.
To save people the problem of asking I've uploaded thescreen dump of both outstation and server
Hope this helps everyone. Of course if technical assistance is required by all means email me and I'll use my vast expertise to ......;-)
http://www.edwards-micros.co.uk/download/vpn.zipx
Cheers
Ian
I've had several emails asking me for the settings I used to get a Lan to lan vpn working.
Have to say I'm not a VPN expert and the Lan was kindly setup by Draytek support (3 cheers) I took a screen dump so I could replicate their settings.
To save people the problem of asking I've uploaded thescreen dump of both outstation and server
Hope this helps everyone. Of course if technical assistance is required by all means email me and I'll use my vast expertise to ......
Cheers
Ian
Please Log in or Create an account to join the conversation.
- njh
- Offline
- Member
Less
More
- Posts: 306
- Thank you received: 0
22 Aug 2009 13:44 #57357
by njh
2900Gi/v2.5.6; 2900/v2.5.6
Replied by njh on topic lan to lan settings
Can I suggest you use a less proprietary file format for your attachment?
2900Gi/v2.5.6; 2900/v2.5.6
Please Log in or Create an account to join the conversation.
- jenodorf
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 16
- Thank you received: 0
22 Aug 2009 14:41 #57358
by jenodorf
Replied by jenodorf on topic aplogies
Hi
it appears that zipx is the new format for winzip, mine upgraded automatically and now defaults to zipx, - shades of office 2007.
Anyway I've done a save as zip so the link is
http://www.edwards-micros.co.uk/download/vpn.zip
Life is never simple
Ian
it appears that zipx is the new format for winzip, mine upgraded automatically and now defaults to zipx, - shades of office 2007.
Anyway I've done a save as zip so the link is
Life is never simple
Ian
Please Log in or Create an account to join the conversation.
- njh
- Offline
- Member
Less
More
- Posts: 306
- Thank you received: 0
22 Aug 2009 19:04 #57360
by njh
2900Gi/v2.5.6; 2900/v2.5.6
Replied by njh on topic lan to lan settings
I am surprised that Draytek have set you up like this. I would have thought they would have you using AES rather than 3DES for the IPSec Security Method. If you can it is worth exploring X509 Digital Signatures as they are better than even a strong PSK.
What advanced options did they set you up with in the IPSec Security Method?
Also your setup is only going to work if both end have fixed IP's.
What advanced options did they set you up with in the IPSec Security Method?
Also your setup is only going to work if both end have fixed IP's.
2900Gi/v2.5.6; 2900/v2.5.6
Please Log in or Create an account to join the conversation.
- jenodorf
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 16
- Thank you received: 0
22 Aug 2009 19:39 #57361
by jenodorf
Replied by jenodorf on topic Update
Hi
both ends do have a fixed IP, as to the ipsec security options
medium (AH)ticked
and DED,3des AND aes with ticks.
It also says data will be encrypted and authentic.
I assumed this was Ok? I make no claims to be an expert in this area.
What was the icing on the cake was that it was a waste of time because Sage does not runover a VPN
cheers
Ian
both ends do have a fixed IP, as to the ipsec security options
medium (AH)ticked
and DED,3des AND aes with ticks.
It also says data will be encrypted and authentic.
I assumed this was Ok? I make no claims to be an expert in this area.
What was the icing on the cake was that it was a waste of time because Sage does not runover a VPN
cheers
Ian
Please Log in or Create an account to join the conversation.
- njh
- Offline
- Member
Less
More
- Posts: 306
- Thank you received: 0
22 Aug 2009 20:06 #57362
by njh
2900Gi/v2.5.6; 2900/v2.5.6
Replied by njh on topic lan to lan settings
A bit better would be Ipsec Security Method: AES with authentication (for your Dial-out/head Office Box), and in the advanced settings, enable Perfect Forward Secrecy.
2900Gi/v2.5.6; 2900/v2.5.6
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek