Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

LAN-LAN VPN via Draytek 2200 routers ?

Status
Not open for further replies.

Jolyon

Programmer
Sep 19, 2002
3
GB
Hi - as a total VPN newbie I am trying to connect 2 LANs via a pair of Draytek 2200-series routers. Have followed the setup instructions in the book and can establish an L2TP/IPSec connection between the routers, but the only thing I can ping on the remote LAN is the router itself.

Does anyone have experience of (successfully!) setting up a VPN with this hardware ? I'd appreciate any tips, known problems etc. The supplied documentation is OK for the basics but has no troubleshooting stuff.
 
Yes i setup a LAN-LAN Dialer Profile and managed to get a vpn connection, however not all traffic is allowed through the tunnel, the web config is the first place to setup, then you need to telnet into the router and add the static commands to the vpn interface, dont work using the web config for some reason.

I would advise you dont use lan to lan, user to vigor will work on most configs, but lan to lan is poor.
 
OK, thanks for the help. When you say "then you need to telnet into the router and add the static commands to the vpn interface, dont work using the web config for some reason", what static commands do you mean ? I agree the web configurator is flaky (seems to need a reboot before doing it) but don't know what oter setup is needed. Do you mean static routes ?

Cheers,

Jolyon

 
Do you not need the machines on the other end to have the Router on their end as a gateway ?
 
Both LANs have their own local routers set up as gateways - you pretty much have to do that to make any Internet access work. What I don't know is whether I have to set up any static routes of any kind, e.g. between the routers. When the tunnel is established, each end can see the router at the other end, but nothing else.
 
You need to add static routes using telnet because the web config editor cannot add static routes to IF4 (the vpn tunnel) using this method you can send traffic through the vpn tunnel and onto another router/device
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top