DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

lan2lan vpn for 2820n

  • bandicoot
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
26 Apr 2011 14:25 #67454 by bandicoot
lan2lan vpn for 2820n was created by bandicoot
I have set these up in the past but this one isnt working. Both are 2820n and configured as follows:

Profilename lan2lan
Enabled
Dial Out
Always On
Keep alive by 10.1.12.10 (remote server)
PPTP
Username - lan2lan
Password ***
PAP/CHAP
VJ Compression ON
Server IP - xxx.dyndns.org (resolves fine)
MyWan 0.0.0.0
Remote GW 0.0.0.0
Remoet Network IP 10.1.12.0
Remote Network Mask 255.255.255.0
RIP Direction - Disabled
From first subnet to remote network you have to Route

Profilename lan2lan
Enabled
Dial In
PPTP
Username - lan2lan
Password ***
VJ Compression ON
MyWan 0.0.0.0
Remote GW 0.0.0.0
Remoet Network IP 10.1.11.0
Remote Network Mask 255.255.255.0
RIP Direction - Disabled
From first subnet to remote network you have to Route

In the VPN Connection Management, I get a connection listed, but cant ping the remote network from either direction.

Any ideas?

The alternative is to get the VPN Lan 2 Lan going the other way but 10.1.11.10 server is running VPN so it would have to be a Draytek to Windows Server VPN. Is there any how to on this one?

Please Log in or Create an account to join the conversation.

More
26 Apr 2011 20:23 #67463 by nobody
Replied by nobody on topic Re: lan2lan vpn for 2820n
maybe "but 10.1.11.10 server is running VPN" this has something to do with your problem ?
If a server inside the 10.1.11.0 network is running PPTP-VPN you might have redirected ports/services to this machine, which will most likely make it impossible for the 2820 to serve as a VPN dial-up server.

Suggestion:
Disable the PPtP service of the vigor in the 10.1.11.0 network (it does not work anyway)
setup a Lan2Lan connection using an IPSec tunnel between the two sites.
If the site which dials the connection is on a dynamic IP Address:
(on the site, which dials the connection, enable aggressive mode, and PFS, enter some random credentials for the identification, on the site in 10.1.11.0 network, specify these credentials under "peer ID", under Preshared key enter some random string >20 bytes size)

Please Log in or Create an account to join the conversation.

  • bandicoot
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
27 Apr 2011 15:12 #67476 by bandicoot
Replied by bandicoot on topic Re: lan2lan vpn for 2820n
the 10.1.11.1 router has all vpn options in remote access control disabled since it isnt receiving any connections. I have configured this router to dial out to the 10.1.12.1 router via pptp and it does connect, but I dont seem to be able to get any traffic through?

Please Log in or Create an account to join the conversation.

More
27 Apr 2011 19:23 #67487 by nobody
Replied by nobody on topic Re: lan2lan vpn for 2820n
I never tried this variation, however, I think If you disable any VPN service, the router will most likely be unable use it, regardless, if it is the initiator or the responder.

Why dont use PPtP for the dial-up networking of the Windows server, and use IPSec for the Lan2Lan connections via the draytek ?

Please Log in or Create an account to join the conversation.

  • bandicoot
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
03 May 2011 09:01 #67547 by bandicoot
Replied by bandicoot on topic Re: lan2lan vpn for 2820n
I think that using the server and the VPN server and the draytek as the VPN client is working. I will try with the client later and report back.

Please Log in or Create an account to join the conversation.

  • bandicoot
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
03 May 2011 14:39 #67555 by bandicoot
Replied by bandicoot on topic Re: lan2lan vpn for 2820n
nope, it isnt working, shows as connected, but no ping replies

Please Log in or Create an account to join the conversation.

Moderators: ChrisSami