DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Draytek 2960 - IPSEC Site to Site on WAN1, IKEV2 passthrough on WAN2

  • service_bb
  • Topic Author
  • User
  • User
More
07 May 2020 23:56 #1 by service_bb
Per the subject, we have a Draytek 2960 on fw1.5.1 with multiple IPSEC Site-to-Site tunnels connected using WAN1.

We have a need to pass through IKEv2 traffic on WAN2 to an internal server.

Under VPN and Remote Access -> IPsec General Setup -> WAN Profile we have ensured only WAN1 is selected but it appears that WAN2 is still responding to IPSEC IKEV2 requests rather than passing through internally (have confirmed this by temporarily unticking "Enable IPSEC Service" - after which IKEV2 is passed to our internal server successfully)

Is this intentional? Can anyone advise how we can achieve the desired results?

We essentially want the Draytek 2960 to only process IPSEC Site to Site Tunnels on WAN1 only and allow UDP500 and UDP4500 on WAN2 to an internal server.

Any help is greatly appreciated.

Please Log in or Create an account to join the conversation.

  • service_bb
  • Topic Author
  • User
  • User
More
08 May 2020 23:57 #2 by service_bb
Following on from this, I thought I'd instead try dedicating a public IP to it and set a DMZ host per https://www.draytek.com/support/knowledge-base/5213#linux
but the Draytek is STILL intercepting IKEv2 traffic rather than passing through!
Could this be a bug in 1.5.1 or is it the expected behaviour?

Please Log in or Create an account to join the conversation.