DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Draytek router, Sky broadband and VPN (PPTP and IPSEC)

  • footix2
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
22 Sep 2010 16:13 #1 by footix2
Currrenty I am trying to configure a Vigor 2820Vn to establish a VPN when both ends of the connection have dynamic IP adressess. This will allow us to initiate the VPN from head office instead and provide failover should one of our two BB connections go down. CUrrently the VPN is lost should Zen fail.

We wish to do this as we want to migrate onto our backup ISP (Sky) from our current ISP Zen (which provides us with a fixed IP). The thinking behind this is as the Zen is on a BT backbone, while Sky is LLU in this area and on Easynet and when one is down, its our experience that the other usually remains unaffected. We also have Vodafone 3G has a 3rd failover, but this is next to useless for a VPN due to the proxy the employ.

Anyway.

Firstly we aquired our sky username and password and used them to establish a broadband connection on what would effectively be the remote machine. We established on its own subnet of 192.168.90 (so not clash with the 192.168.2 subnet used by the head office.

Then we acquired 2 no-ip DDNS adressses, one for each end of the conncection.

We then set-up the PPTP connection and managed to establish a connection between the two routers. However, we were unable to ping across the connection and the packets transfer between the two were minimal. It also appeared to drop out regularly.

We could however establish a VPN from Windows XP using the no-ip address and RDC across it and also RDC back to an IP semmingly given by the remote machine to allow return traffic.

Is there are problem with PPTP on this router? It seemed that XP could easily do what the router firmware couldnt.

Finally we attemped IPSEC, but it appears that this doesn work with DDNS on both ends. Our current VPNs are initiated from the remote end of the connection and come back to a fixed IP. When I attempt tp reverse this but use a DDNS instead of a fixed IP then it simply doesnt connect.

I'm pretty sure that DDNS at both ends of an IPSec connection should be viable.

Any advice would be apppreciated.

The firmware is version 3.3.3.3.

Please Log in or Create an account to join the conversation.

More
22 Sep 2010 17:35 #2 by njh
I don't have a 2820 but IPSec VPN between 2 DDNS clients is very possible. In the connection set up do not use the Dial-in Settings bit of the LAN-LAN Profile set up. Instead, the PSK goes in the IPSec General settings.

As a suggestion, use ESP and not AH and in the advanced section, allow perfect forward secrecy. Have the most stable WAN connection as your dial-in end.

2900Gi/v2.5.6; 2900/v2.5.6

Please Log in or Create an account to join the conversation.

  • footix2
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
22 Sep 2010 21:37 #3 by footix2
Yes, we use the PSK.

Please Log in or Create an account to join the conversation.

More
22 Sep 2010 22:09 #4 by njh
You'll need to post your LAN-LAN profile and IPSec General settings if you want any more help.

2900Gi/v2.5.6; 2900/v2.5.6

Please Log in or Create an account to join the conversation.