DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Lan to Lan VPN 2862 to 2860
- Leslie
- Topic Author
- Offline
- New Member
Less
More
- Posts: 3
- Thank you received: 0
18 Sep 2024 16:19 #103876
by Leslie
Lan to Lan VPN 2862 to 2860 was created by Leslie
I successfully set up a dial-out SSL connection from my 2862 to a dial-in 2866.
I'm now trying to replicate that from my 2862 to a 2860 router.
The two routers do not have exactly the same setup pages but I think I have followed the original setting carefully - obviously using a different user name.
It is failing to connect. Looking at the Syslog Explorer the error I see is
SSLTunnel (VPN-2, DAtoZS) <== Protocol:CHAP(c223) Failure Identifier:0x01 E=691 R=1 C=91459A7187858891B585BEF9ABF59CE9 V=0 M=Good luck! ##
CHAP Login Failed (VPN : L2L Dial-out, Profile index = 2, Name = DAtoZS, ifno = 12)
[SSL TUNNEL][L2L][2:DAtoZS][@xx.xx.143.232] CHAP failure: username/password error
I am certain the user/password settings are the same on both. I have even tried to change both users/passwords to simply AAAA/123456 with the same result.
Are the two routers compatible?
I'm now trying to replicate that from my 2862 to a 2860 router.
The two routers do not have exactly the same setup pages but I think I have followed the original setting carefully - obviously using a different user name.
It is failing to connect. Looking at the Syslog Explorer the error I see is
SSLTunnel (VPN-2, DAtoZS) <== Protocol:CHAP(c223) Failure Identifier:0x01 E=691 R=1 C=91459A7187858891B585BEF9ABF59CE9 V=0 M=Good luck! ##
CHAP Login Failed (VPN : L2L Dial-out, Profile index = 2, Name = DAtoZS, ifno = 12)
[SSL TUNNEL][L2L][2:DAtoZS][@xx.xx.143.232] CHAP failure: username/password error
I am certain the user/password settings are the same on both. I have even tried to change both users/passwords to simply AAAA/123456 with the same result.
Are the two routers compatible?
Please Log in or Create an account to join the conversation.
- andew
- Offline
- Junior Member
Less
More
- Posts: 20
- Thank you received: 0
24 Sep 2024 16:28 #103919
by andew
Replied by andew on topic Lan to Lan VPN 2862 to 2860
Hi
In the routers system maintenance, under management what does it say in the TLS/SSL Encryption Setup section. Are the same versions of ssl selected?
Regards
Andrew
In the routers system maintenance, under management what does it say in the TLS/SSL Encryption Setup section. Are the same versions of ssl selected?
Regards
Andrew
Please Log in or Create an account to join the conversation.
- Leslie
- Topic Author
- Offline
- New Member
Less
More
- Posts: 3
- Thank you received: 0
24 Sep 2024 17:34 #103922
by Leslie
Replied by Leslie on topic Lan to Lan VPN 2862 to 2860
Both ends have TLS 1.0/1.1/1.2 ticked.
I have set up a VPN using IPsec Tunnel IKEv2 but would prefer to get SSL working.
I have set up a VPN using IPsec Tunnel IKEv2 but would prefer to get SSL working.
Please Log in or Create an account to join the conversation.
- HodgesanDY
- Offline
- Member
Less
More
- Posts: 207
- Thank you received: 16
25 Sep 2024 10:33 - 25 Sep 2024 10:35 #103925
by HodgesanDY
Replied by HodgesanDY on topic Lan to Lan VPN 2862 to 2860
Hi Leslie,
How comes you’re opting for SSL over IPSec?
IPSec is more secure and faster, and also DrayTek’s recommended method between their routers (@AES256):
https://www.draytek.com/solutions/working-from-home-vpn-solutions/
But obviously other factors may apply to your circumstance; just mentioning.
How comes you’re opting for SSL over IPSec?
IPSec is more secure and faster, and also DrayTek’s recommended method between their routers (@AES256):
https://www.draytek.com/solutions/working-from-home-vpn-solutions/
But obviously other factors may apply to your circumstance; just mentioning.
Last edit: 25 Sep 2024 10:35 by HodgesanDY.
Please Log in or Create an account to join the conversation.
- Leslie
- Topic Author
- Offline
- New Member
Less
More
- Posts: 3
- Thank you received: 0
25 Sep 2024 12:52 #103926
by Leslie
Replied by Leslie on topic Lan to Lan VPN 2862 to 2860
I bow to your superior knowledge.
Some time back I also had issues setting up and was advised to use SSL.
I'm happy to leave it as is.
One thing that surprises me about IPSec is that there seems to be only a single shared-secret at the incoming end.
So if there are several different sites setting up VPNs to the incoming server they all use the same secret.
Have I misunderstood it?
Some time back I also had issues setting up and was advised to use SSL.
I'm happy to leave it as is.
One thing that surprises me about IPSec is that there seems to be only a single shared-secret at the incoming end.
So if there are several different sites setting up VPNs to the incoming server they all use the same secret.
Have I misunderstood it?
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek