DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
L2TP w/IPSec VPN - Specify Remote Node - Peer ID - Where?
- routintooter
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 20
- Thank you received: 0
15 Dec 2018 18:01 #93556
by routintooter
L2TP w/IPSec VPN - Specify Remote Node - Peer ID - Where? was created by routintooter
Hi.
Router/VPN server:
Model Name : Vigor2850n
Firmware Version : 3.8.8.2_232201
Build Date/Time : May 21 2018 14:21:05
Client tool:
Draytek SmartVPN client 4.3.3.3
and
Draytek SmartVPN client 5.0.0.0
OS:
Win 7 Pro SP1 x86
XP Pro SP3 x86
Connection:
3G cellular data via TMobile/EE dongle.
I have set up a Remote dial in (tele-worker) L2TP with IPSec vpn.
This was set up using a pre shared key as found in the screen: VPN IKE/IPsec General Setup
All works fine.
I am trying to set up a similar dial-in user but using the "Specify Remote Node " / "Peer ID " option found on the "Remote Dial-in User" setup page, and thereby specify a specific pre-shared key (rather than using the "global one", detailed above).
All goes tickity-bo if I fill in "Remote Client IP" with the client's IP address - it seems to connect just fine.
However, I can't see a way of using the "Peer ID " feature/identifier (E.g. "mypeerid@somewhere.net ") - there doesn't seem to be an option to enter this in the Draytek SmartVPN client interface.
As the client will have a dynamic IP, I can't use the IP address.
In the past, IIRC, I've got it to work (using a "Peer ID") with the Shrewsoft VPN client but I cant get the Shrewsoft client to work at all at the moment (doesn't seem to get past phase 1), and I would rather stick with the SmartVPN client, if possible.
I had a look in the config file the client tool creates but nothing jumped out as being pertinent to "Peer ID ".
Any help greatly appreciated.
C
Router/VPN server:
Model Name : Vigor2850n
Firmware Version : 3.8.8.2_232201
Build Date/Time : May 21 2018 14:21:05
Client tool:
Draytek SmartVPN client 4.3.3.3
and
Draytek SmartVPN client 5.0.0.0
OS:
Win 7 Pro SP1 x86
XP Pro SP3 x86
Connection:
3G cellular data via TMobile/EE dongle.
I have set up a Remote dial in (tele-worker) L2TP with IPSec vpn.
This was set up using a pre shared key as found in the screen: VPN IKE/IPsec General Setup
All works fine.
I am trying to set up a similar dial-in user but using the "Specify Remote Node
All goes tickity-bo if I fill in "Remote Client IP" with the client's IP address - it seems to connect just fine.
However, I can't see a way of using the "Peer ID
As the client will have a dynamic IP, I can't use the IP address.
In the past, IIRC, I've got it to work (using a "Peer ID") with the Shrewsoft VPN client but I cant get the Shrewsoft client to work at all at the moment (doesn't seem to get past phase 1), and I would rather stick with the SmartVPN client, if possible.
I had a look in the config file the client tool creates but nothing jumped out as being pertinent to "Peer ID
Any help greatly appreciated.
C
Please Log in or Create an account to join the conversation.
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank you received: 0
16 Dec 2018 02:25 #93558
by hornbyp
I've played around in this area recently...
I failed miserably in my attempts to use that "Peer ID" field in a Remote Dial-in User entry on my 2860 . (It does work in Lan-to-Lan VPN entries.)
I think it is only used for IPSec "Aggressive Mode", and I couldn't find any way of getting the Windows client (or SmartVPN) to do this - it always uses "Main Mode".
I did find a way to make an Android Client use "Aggressive Mode" - but I can't make any combination of "Peer ID" and per-user "Pre-shared key" work. (My 2860 gets further than my 2830 , which fails at its earliest possible opportunity!).
The only way I could achieve "Per-user " IPSec authentication, was to use X.509 certificates. (The L2TP part is always authenticated "per-user ", but (if used) happens after the IPSec connection has been established).
Replied by hornbyp on topic Re: L2TP w/IPSec VPN - Specify Remote Node - Peer ID - Where
Routintooter wrote:
I am trying to set up a similar dial-in user but using the "Specify Remote Node" / "Peer ID " option found on the "Remote Dial-in User" setup page, and thereby specify a specific pre-shared key (rather than using the "global one", detailed above).
However, I can't see a way of using the "Peer ID" feature/identifier (E.g. " mypeerid@somewhere.net ") - there doesn't seem to be an option to enter this in the Draytek SmartVPN client interface.
I've played around in this area recently...
I failed miserably in my attempts to use that "Peer ID" field in a Remote Dial-in User entry on my 2860
I think
I did
The only way I could achieve "Per-user
Please Log in or Create an account to join the conversation.
- routintooter
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 20
- Thank you received: 0
16 Dec 2018 09:51 #93561
by routintooter
Replied by routintooter on topic Re: L2TP w/IPSec VPN - Specify Remote Node - Peer ID - Where
Thanks for the info.
In the before time, in the long, long ago, when the Shrewsoft client was working, I had set to use Aggressive mode - which seems to correlate with your experience.
In the before time, in the long, long ago, when the Shrewsoft client was working, I had set to use Aggressive mode - which seems to correlate with your experience.
Please Log in or Create an account to join the conversation.
- routintooter
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 20
- Thank you received: 0
17 Dec 2018 15:50 #93567
by routintooter
Replied by routintooter on topic Re: L2TP w/IPSec VPN - Specify Remote Node - Peer ID - Where
Having had a further tinker with the Shrewsoft client, it may be the case my previous experience with it "was all a dream" - that is I dont think it supports L2TP with IPSEC - it seems to be just IPSEC.
The crib notes I found regarding setting up Shrewsoft client with a Draytek VPN specify using PSK + XAuth but if i only pick "IPSEC tunnel" in the Draytek VPN GUI (Not "L2TP with IPSEC Policy") then I cannot enter a username and password - which I thought was the Xauth "bit".
However I could be, and almost certain am, wrong.
The crib notes I found regarding setting up Shrewsoft client with a Draytek VPN specify using PSK + XAuth but if i only pick "IPSEC tunnel" in the Draytek VPN GUI (Not "L2TP with IPSEC Policy") then I cannot enter a username and password - which I thought was the Xauth "bit".
However I could be, and almost certain am, wrong.
Please Log in or Create an account to join the conversation.
- routintooter
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 20
- Thank you received: 0
21 Dec 2018 12:18 #93608
by routintooter
Replied by routintooter on topic Re: L2TP w/IPSec VPN - Specify Remote Node - Peer ID - Where
As what has been said above, really:
Contacted Draytek UK support - Response was you cannot currently enter the Peer ID field into the SmartVPN client.
No suggestion it was "on the list", or "not on the list".
Contacted Draytek UK support - Response was you cannot currently enter the Peer ID field into the SmartVPN client.
No suggestion it was "on the list", or "not on the list".
Please Log in or Create an account to join the conversation.
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank you received: 0
21 Dec 2018 17:17 #93609
by hornbyp
Replied by hornbyp on topic Re: L2TP w/IPSec VPN - Specify Remote Node - Peer ID - Where
Looking on the bright side, our experiments seem to be showing the same thing
I thought I'd precis a few points, that I believe to be facts ...
Out of characters ... TBC
I thought I'd precis a few points, that I believe to be facts
From:
3.7 Other Information
There is no way to configure Windows to use IKEv1 aggressive mode. Only main mode is supported
and
Note: When the RAS IPsec VPN is configured to use L2TP/IPsec (also known as IKEv1), then IKEv1 Phase 1 negotiation operates in main mode only; aggressive mode operation is not supported and cannot be configured.
See:
Same sort of thing here:
Aggressive mode is typically used for remote access VPN’s (remote users). Also you would use aggressive mode if one or both peers have dynamic external IP addresses.
Out of characters ... TBC
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek