DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

2930 and multiple VPN nodes

  • oliverm
  • Topic Author
  • User
  • User
More
12 Jul 2011 13:09 #1 by oliverm
2930 and multiple VPN nodes was created by oliverm
We have a tricky VPN question.

We have two sites. HQ and Office1. Office1 has a 2930 and the HQ has a watchguard. Both are VPN'd and working well.

We now have a 3rd office, Office2 which only has VPN access to the HQ site. Users in Office2 also need to access Office1. So...

Office1 <-> HQ <-> Office2

The watchguard supports this as does Office2. However I'm told that the 2930 only supports this if the other nodes are also Drayteks. You can view the VPN properties in the 2930 and click the MORE button under the remote network IP settings and add more IPs however they don't kick in unless speaking to other 2930s.

Is that correct? Anyone got this working?

Olly

Please Log in or Create an account to join the conversation.

  • nealuk
  • User
  • User
More
12 Jul 2011 16:01 #2 by nealuk
Replied by nealuk on topic Re: 2930 and multiple VPN nodes
We have, for example:

Small Office England <-> Head Office England <-> Europe Office

The Draytek in the Small Office, under Advanced VPN, knows that the Europe Office IP Range is reachable through the VPN to the Head Office.

So I think you should be able to get your Draytek working too, since, in this example, the Head OFfice and Europe office are using different manufacturers equipment (non-Draytek).

Regards, Neal

Please Log in or Create an account to join the conversation.

  • oliverm
  • Topic Author
  • User
  • User
More
12 Jul 2011 16:20 #3 by oliverm
Replied by oliverm on topic Re: 2930 and multiple VPN nodes
Hi Neil,

And can you confirm, on the draytek, have you just added the Europe Office IP range to the MORE section of the remote network IP section in the VPN settings?

Olly

Please Log in or Create an account to join the conversation.

  • nealuk
  • User
  • User
More
13 Jul 2011 13:41 #4 by nealuk
Replied by nealuk on topic Re: 2930 and multiple VPN nodes
Hi Olly, yes that is exactly it.

However, there may be need to be some settings on the next Firewall to allow throughput (in my example the Head Office).

Is there something in your watchguards to do this? (this kind of thing is beyond my current understanding, sorry)

Do you get any clues as to how far things are getting by using Draytek syslog and watchguard syslog, with some pings?

Please Log in or Create an account to join the conversation.