DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Draytek 2955 - L2TP vulnerability causing reboots?
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank you received: 0
16 Nov 2018 01:27 #93383
by hornbyp
The Main v. Aggressive mode choice is only to be found in a Dial-out site-to-site profile (advanced section) ... i.e. when the Vigor is acting as the
initiator (or client as I put it earlier - probably not a good choice of phrase).
The exact algorithm it uses at the far end seems a bit airy-fairy to say the least (as to whether it matches the Global PSK, or looks for a match in an inbound profile). I've had it match a key set in a profile - even though the option to use it isn't ticked! (I've seen that on both the 2830 and the 2860).
I think that ticking "Specify Remote VPN Gateway" is the key setting, that makes it ignore the Global PSK and start considering the profile settings instead.
Replied by hornbyp on topic Re: Draytek 2955 - L2TP vulnerability causing reboots?
Does the global key do anything then? It would be weird to take note of the Main v. Aggressive mode config in the global IPSEC config, while ignoring the shared key which is entered in the same box.peter-h wrote:
The Main v. Aggressive mode choice is only to be found in a Dial-out
initiator (or client as I put it earlier - probably not a good choice of phrase).
The exact algorithm it uses at the far end seems a bit airy-fairy to say the least (as to whether it matches the Global PSK, or looks for a match in an inbound profile). I've had it match a key set in a profile - even though the option to use it isn't ticked! (I've seen that on both the 2830 and the 2860).
I think
Please Log in or Create an account to join the conversation.
- peter-h
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 60
- Thank you received: 0
16 Nov 2018 09:51 #93386
by peter-h
Replied by peter-h on topic Re: Draytek 2955 - L2TP vulnerability causing reboots?
OK; I used a text string here
although perhaps entering the IP at the other end might have been more secure.
It appears that you can enter both... what would that do?
although perhaps entering the IP at the other end might have been more secure.
It appears that you can enter both... what would that do?
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek