DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Unable to get DHCP over IPSEC

  • biohazard79
  • Topic Author
  • Offline
  • New Member
  • New Member
More
29 Aug 2007 05:15 #1 by biohazard79
Unable to get DHCP over IPSEC was created by biohazard79
I am trying to get a teleworker vpn to work using IPSEC. I want the teleworker to get a DHCP address from our DHCP server. Under LAN-> General Setup, i have marked the circle for Relay Agent: 1st subnet, and have specified the DHCP Server IP Address for Relay Agent. I try to create the VPN connection on the teleworker, but it fails with the following being printed in the log:


[2007 August 29 13:59:57] ** Status: Active DHCP policy
[2007 August 29 14:00:02] ** Status: DHCP conversation...
[2007 August 29 14:00:22] ** Status: Releasing assigned IP...
[2007 August 29 14:00:22] ** Status: Inactive DHCP & IPSec SA
[2007 August 29 14:00:23] ** Status: DHCP timeout
[2007 August 29 14:00:23] ** DHCP Timeout

Any idea's?

Thanks
BioHazard

Please Log in or Create an account to join the conversation.

More
10 Oct 2007 13:59 #2 by joolzhaines
Replied by joolzhaines on topic Same problem
Hi,

I am having the same problem did this ever get fixed?

Regards

Joolz

Please Log in or Create an account to join the conversation.

More
26 Oct 2007 18:07 #3 by scrinf
Replied by scrinf on topic Same problem
Hi! the same problem no dhcp trough ipsec? for teleworkers.

Please Log in or Create an account to join the conversation.

More
25 Aug 2009 11:39 #4 by spudster
Replied by spudster on topic Unable to get DHCP over IPSEC
Same issue on my 2820n.

Followed this guide http://www.draytek.com/user/SupportAppnotesDetail.php?ID=136

Have enabled virtual IP (on the draytek vpn client) and set to automatically obtain IP. I was hoping this would query the drayteks DHCP pool and lease an address from there over the VPN. However the DHCP conversation over the VPN doesn't work and follows the same points as those listed in the original post.

Any help?

Please Log in or Create an account to join the conversation.

More
26 Aug 2009 10:42 #5 by macavity
Replied by macavity on topic DHCP over IPSEC / NAT Traversal
With the Vigor2820 the VPN Client needs to not be behind NAT. ie it needs to have a public IP Address.

The reason is that DHCP over IPSEC isn't compatible with NAT-T.

Please Log in or Create an account to join the conversation.

Moderators: Sami