DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

connecting Draytek 2830 via Point to point Lease connection

  • sjltech.uk
  • User
  • User
More
14 Nov 2016 17:56 #7 by sjltech.uk
tried replicating this setup with a pair of spare 2920s, and got the same problem.
I trace from a PC on LAN of router 1, to the WAN gateway on router 1, get to the WAN gateway on router 2, then it fails to get to the LAN on router 2.
Still working on it 'cos I can't see why it shouldn't work, but I've never hooked up 2 Drayteks like this - only using a VPN.
Cheers
Simon

Please Log in or Create an account to join the conversation.

  • sjltech.uk
  • User
  • User
More
15 Nov 2016 21:32 #8 by sjltech.uk
Well, I gave up trying to do it this way, and have chucked an aged 2955 in the middle and started making some progress.
I had to COMPLETELY disable the firewall functions on the 2955 to make this work, so I'm wondering if that's part of the problem with the direct back-to-back connection.
Ran out of time today to complete testing and write it up, but hopefully by the weekend.
Cheers
Simon

Please Log in or Create an account to join the conversation.

  • sjltech.uk
  • User
  • User
More
18 Nov 2016 01:00 #9 by sjltech.uk
After trying various things and extra "bits" in the middle, I decided to go back to basics.
Router set-up:
Site A:
LAN: IP=192.168.11.1/24 DHCP=192.168.11.101 pool of 50
WAN1: IP=192.168.101.1/24 GW=192.168.101.2 (IP of WAN1 on Site B)

Site B:
LAN: IP=192.168.12.1/24 DHCP=192.168.12.101 pool of 50
WAN1: IP=192.168.101.2/24 GW=192.168.101.1 (IP of WAN1 on Site A)

Then, set-up a LAN-to-LAN IPsec VPN connection.
LAN-to-LAN VPN:
Site A: set-up as Dial-In VPN (Server)
Site B: set-up as Dial-Out VPN (Client)Client
(selected options to keep the link up on both)

All firewall stuff left at default settings, DoS Defense not enabled (can't remember if this is default or not - sorry)

Straight through ethernet between both WAN1 ports on the two routers

Checked in VPN Connection management to verify VPN had come up correctly.

Plugging a PC into Site A: router gets an IP address and traces/pings etc. all work as I'd hoped for (likewise plugging the PC into Site B: router)

This seems to be about the most "elegant" solution I can come up with as it doesn't require any extra hardware, no additional static routes to add/maintain, but I'd be very interested to hear any other suggestions.
Cheers
Simon

Please Log in or Create an account to join the conversation.

  • sjltech.uk
  • User
  • User
More
30 Jan 2017 02:15 #10 by sjltech.uk
I know it's been a while, but as a result of a (data) cabinet reshuffle, I decided to revisit this one.
The bit that was bugging me was that I just couldn't get LAN -> LAN routing working between the routers.
So, what I ended up with was a pair of factory reset 2920s, latest firmware, no real WAN connections - this was just to prove the LAN -> LAN side of things.
After MUCH messing about, I got it working and what was tripping me up was I was using the "routing" LAN port as just that, and not using the "For NAT Usage" option !
Here's the configuration in brief:
2920-1
LAN1 = 192.168.11.1 DHCP as normal
LAN ports 1-3 in LAN1
LAN2 = 192.168.13.1/24 Enable and For NAT Usage checked, DHCP Disable Server checked
LAN port 4 in LAN2 only

LAN >> Static Route Setup
Dest IP = 192.168.12.0
Sub mask = 255.255.255.0
Gateway IP Address = 192.168.13.2
Network Interface = LAN2

2920-2
LAN1 = 192.168.12.1 DHCP as normal
LAN ports 1-3 in LAN1
LAN2 = 192.168.13.2/24 Enable and For NAT Usage checked, DHCP Disable Server checked
LAN port 4 in LAN2 only

LAN >> Static Route Setup
Dest IP = 192.168.11.0
Sub mask = 255.255.255.0
Gateway IP Address = 192.168.13.1
Network Interface = LAN2

connected both port 4s together with straight through cable.

Now I can ping and trace through from either side, so I called it a night :o
Cheers
Simon

Please Log in or Create an account to join the conversation.