DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Mixing Client to Site and Site to Site VPN's

  • lsystems
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
23 Sep 2008 15:19 #1 by lsystems
Hi All,

Currently we have a Draytek 2900 router (via a single NAT'd IP address) and run various types (Cisco, Nortel etc) of IP-Sec based VPN clients (using pass though) behind the firewall to provide remote access to our customers.

We would like if possible to also be able to set IP-Sec based Site to Site VPN's where customers request it so no client software is required. Am I correct in thinking that this is not possible with our single box solution as IP-Sec traffic is either passed through or not...?

Would it perhaps be possible to introduce a VPN server behind the firewall (in a DMZ?) to support the site to site VPN's without interfering with the existing client to site VPN's we already have running via pass-through behind the firewall.

Any advice/experiences would be most welcome.

Regards,

David

Please Log in or Create an account to join the conversation.

More
23 Sep 2008 18:13 #2 by j.baker
Replied by j.baker on topic Mixing Client to Site and Site to Site VPN's
I do not know the specs of the 2900, but if you can create multiple lan-lan IPSEC tunnels, then it should do what you want.

However, each locations must be of a separate IP address subnet on their LAN. The LAN-LAN tunnel set are setup, and then an IP route is setup to go over the tunnel.

If anyone knows different, please correct me.

Regards

John Baker


Vigor2820 series with firmware 3.3.5.2_RC2
ADSL

Please Log in or Create an account to join the conversation.

More
26 Sep 2008 20:38 #3 by louis-m
Replied by louis-m on topic Mixing Client to Site and Site to Site VPN's
john's right. you need to make sure your remote site is on a different subnet. if not, you will have to make a change to the network at one site. then its as simple as making an ipsec site to site vpn which will be transparent to the end users.
you can then use an ipsec/pptp client for mobile devices that are outside the lan subnets. drayteks will perform this with ease.

2820 = 3.3.2_RC5
2950 = 3.2.4

Please Log in or Create an account to join the conversation.

  • lsystems
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
09 Aug 2010 15:35 #4 by lsystems
Replied by lsystems on topic Mixing Client to Site and Site to Site VPN's
Just got round to testing this and am having little success. I'm testing with a Draytek 2820 running 3.3.3_232201. The details I've been given to connect with are:-

IP-Sec: Site to Site
Peer Gateway IP: A public IP
Pre-shared Key: As agreed

Phase 1
Encryption: AES-256
Hash : SHA1
Group: DH2
Lifetime : 1440 (minutes)

Phase 2
Encryption: AES-256
Hash : SHA1
Group: DH2
Lifetime : 3600 Secs

I have set this up as follows:-

VPN and Remote Access >> LAN to LAN
Call Direction : Dial Out

Dial Out Settings
Type: IPSec Tunnel
Server IP/Host Name: Peer Gateway IP as shown above

IKE Authentication Method
Pre-Shared Key : key as agreed above

IPSec Security Method
High(ESP): AES With Authentication

Advanced
IKE phase 1 mode : Main Mode
IKE phase 1 proposal : AES256_SHA1_G2
IKE phase 1 key lifetime : 86,400
IKE phase 2 key lifetime : 3600
Perfect Forward Secret : No
Local ID :

TCP/IP Network Settings
My WAN IP : 0.0.0.0
Remote Gateway IP : Peer Gateway IP as shown above
Remote Network IP : IP of the server we want to connect to
Remote Network Mask : 255.255.255.255
RIP Direction: Disable
From 1st subnet : Route

If we open up a connection via RDP to the Remote Network IP, the VPN Log using syslog, shows:-

Dialing Node(Name): Peer Gateway IP as shown above

And that is it, nothing else gets written to the log. The VPN hardware I'm connecting to is a Checkpoint Firewall apparently. I suspect a problem with the Remote Network IP and mask, but I'm entering the values I've been given. Any suggestions would be most welcome.

Regards,

David

Please Log in or Create an account to join the conversation.