DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Routing over IPSec Tunnel
- msimonds
- Topic Author
- Offline
- New Member
Less
More
- Posts: 8
- Thank you received: 0
12 May 2021 13:56 #99258
by msimonds
Routing over IPSec Tunnel was created by msimonds
Afternoon all, was wondering if someone would assist with a routing issue I am have.....?
Some background of the setup
Site A - Draytek 2960
IP Range - 192.168.97.0/24
Site B - Cisco ASA-5516
IP Range - 10.82.187.16/32, 10.82.187.17/32, 10.82.187.18/32
I can get the IPSec tunnel to connect/handshake but no traffic...
Under the Basic Tabs on VPN Profile should i be setting the Remote IP/Subnet Mask as
10.82.187.0 | 255.255.255.128/25
or
10.82.187.16 | 255.255.255.255/32
10.82.187.17 | 255.255.255.255/32
10.82.187.18 | 255.255.255.255/32
Both options bring the tunnel up but no data is passing....
Some background of the setup
Site A - Draytek 2960
IP Range - 192.168.97.0/24
Site B - Cisco ASA-5516
IP Range - 10.82.187.16/32, 10.82.187.17/32, 10.82.187.18/32
I can get the IPSec tunnel to connect/handshake but no traffic...
Under the Basic Tabs on VPN Profile should i be setting the Remote IP/Subnet Mask as
10.82.187.0 | 255.255.255.128/25
or
10.82.187.16 | 255.255.255.255/32
10.82.187.17 | 255.255.255.255/32
10.82.187.18 | 255.255.255.255/32
Both options bring the tunnel up but no data is passing....
Please Log in or Create an account to join the conversation.
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank you received: 0
13 May 2021 02:36 #99260
by hornbyp
Replied by hornbyp on topic Re: Routing over IPSec Tunnel
Maybe the answer to this, is the "Create Phase 2 SA for each subnet " option? ...
See:
https://www.draytek.co.uk/support/guides/kb-vpn-multiplesa
See:
The "Create Phase 2 SA for each subnet" does not need to be ticked unless one of the site is non-DrayTek router which requires any traffic to exactly match the IPSEC security association. If the device (eg a Cisco) requires traffic to match the security assocation then a Phase 2 SA must be created for each subnet. In this case, enable the Create Phase2 SA for each subnet.(IPsec) option.
Please Log in or Create an account to join the conversation.
- msimonds
- Topic Author
- Offline
- New Member
Less
More
- Posts: 8
- Thank you received: 0
14 May 2021 12:19 #99276
by msimonds
Replied by msimonds on topic Re: Routing over IPSec Tunnel
many thanks for the suggestion, i will look to find the option as its different on the 296/ linux OS device
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek