DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

ASA TO DRAYTEK 2820VN VPN

  • c2zer0
  • Topic Author
  • Offline
  • New Member
  • New Member
More
23 Sep 2011 12:55 #1 by c2zer0
ASA TO DRAYTEK 2820VN VPN was created by c2zer0
Hi

Im having problems with a LAN-LAN between an ASA and Draytek router. The VPN phase1 and 2 complete successfully, but then Im unable to pass traffic, from either end.
Both ends send and encryp traffic but the traffic is not decrypted at the other side. I have made this work between a Cisco router and 2820, with no problems.
Has anyone seen this issue with ASA's and Draytek routers before?

Please Log in or Create an account to join the conversation.

More
26 Sep 2011 09:24 #2 by frag
Replied by frag on topic Re: ASA TO DRAYTEK 2820VN VPN
Maybe perfect forward secret is enabled on one of the routers?

Also you need to make sure that both phases match. In addition if you are using a host name in place of an IP address (DDNS for example) then you need to ensure that the VPN is set to aggressive mode.

Please Log in or Create an account to join the conversation.

  • nealuk
  • User
  • User
More
26 Sep 2011 10:07 #3 by nealuk
Replied by nealuk on topic Re: ASA TO DRAYTEK 2820VN VPN
Using the Draytek Syslog utility what entries do you have when the connection is being established? I usually find this very helpful in determining what needs tweaking.

Please Log in or Create an account to join the conversation.