1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

WRV54G to WRV54G VPN Tunnel

Discussion in 'Other Linksys Equipment' started by rplankenhorn, Sep 22, 2006.

  1. rplankenhorn

    rplankenhorn LI Guru Member

    I am trying to connect two routers over the internet using the Remote Gateway VPN Tunnel feature. Both routers have firmware version 2.39.2. I have configured the routers according the little information I have found on this topic. Below is my configuration on my routers Security/VPN page:

    VPN Passthrough:
    All enabled

    VPN Tunnel: Enabled
    Tunnel Name is the same on both routers.

    Local Secure Group: (Flipped on other router)
    Subnet
    192.168.1.0
    255.255.255.0

    Remote Secure Group:
    Subnet
    10.0.0.0
    255.255.255.0

    Remote Secure Group:
    I have Dynamic DNS and I have tried entering the IP and using the FQDN feature.

    Encryption: 3DES
    Authentication: MD5

    Key Management:
    Key Exchange Method: Auto
    PFS: Enabled
    Using Pre-shared key that is identical on both routers. Have tried it disabled.
    Key Lifetime: 28000

    Any help is much appreciated.
     
  2. cactusfazer

    cactusfazer Network Guru Member

    You must change your MTU : i have 1420 but you can calc with the faq of linksys. Disable smtp and if you can, change your lan adress: 192.168.0.x is not recommanded.
    One of remote gateway have to be "ANY" and the other must have the wan adress.
     
  3. DocLarge

    DocLarge Super Moderator Staff Member Member

    Need Logging Stats

    Are you running any type of logging application (i.e., Wall Watcher or Link Logger)? That would help in order to see what the errors are. I run WRV54g to WRV54G tunnels all the time with 2.37.13 software and the connections are solid.

    Both routers have dynamic ip addresses but I utilize the following scheme:

    Local Secure Group : Subnet
    Remote Secure Group: Subnet
    Remote Secure Gateway: IP Address

    Never fails... :)

    Additionally, it will help to post questions like these for the WRV54G in the VPN router forum.

    Jay
     
  4. DocLarge

    DocLarge Super Moderator Staff Member Member

    I'd meant to mention earlier that I've seen some people get away with using the WRV54G's default MTU value (1492), but realistically, having to adjust your MTU is reliant upon the connection you have from your ISP and whether it's ip/data stream.

    The WRV54G's performance varies from connection to connection; Before I moved overseas, my WRV54G was on a dynamic cable modem connection and never had an issue with ip refresh or mtu; when I got over her to England and put it on an ADSL connection, the router would lose connectivity every 72hrs because it would never renew the dhcp reservation. As a result, I've had to put another router in front of it (Pix 501) and hang it off of it in order to gain functionality. Incidentally, I was still able to bring up a vpn tunnel with my WRV54G "behind" another router (Netgear DG934G) and connect to another WRV54G router for a vpn tunnel-to-tunnel connection; it worked fine. :)

    Additionally, if you put the WRV54G behind a NAT-T compliant router, you can actuall use third party vpn clients on the WRV54G segment that will connect through the first router (in my case, the DG834G) and out to the vpn endpoint. I happened to have stumbled across this about a year ago; running my WRV54G like this makes me a happy sumbatch because running it as the only router doesn't allow you to use third party vpn clients :)

    Jay
     
  5. cactusfazer

    cactusfazer Network Guru Member

  6. rplankenhorn

    rplankenhorn LI Guru Member

    Still Not Working

    I changed the MTU on both routers 1494 and it still doesn't work. I tried to change one of the routers remote gatweway setting to any and it still didn't work. Is there anything else that I should try?
     
  7. cactusfazer

    cactusfazer Network Guru Member

    This is my configuration :
    MTU=1420 on both

    WRV200 is the endpoint,WRV54G the ipsec client.

    *WRV200 config:
    ----------------
    VPN Passthrough:
    All enabled

    VPN Tunnel: Enabled

    Local Secure Group: (Flipped on other router)
    Subnet
    192.9.250.0
    255.255.255.0

    Remote Secure Group:
    Subnet
    192.9.204.0
    255.255.255.0

    Remote Secure Group: ANY

    Encryption: 3DES
    Authentication: MD5

    Key Management:
    Key Exchange Method: Auto IKE,3DES,MD5
    PFS: Enabled
    Key : mykey
    In advanced settings:
    phase 1: 3DES,MD5,1024B,lifetime=28800
    phase 2: 3DES,MD5,1024B,lifetime=3600

    *WRV54G config:
    ----------------
    VPN Passthrough:
    All enabled

    VPN Tunnel: Enabled

    Local Secure Group: (Flipped on other router)
    Subnet
    192.9.204.0
    255.255.255.0

    Remote Secure Group:
    Subnet
    192.9.250.0
    255.255.255.0

    Remote Secure Group: theotherrouter.dyndns.og

    Encryption: 3DES
    Authentication: MD5

    Key Management:
    Key Exchange Method: Auto IKE,3DES,MD5
    PFS: Enabled
    Key : mykey
    In advanced settings:
    phase 1: 3DES,MD5,1024B,lifetime=28800
    phase 2: 3DES,MD5,1024B,lifetime=3600


    I have also read somewhere in faq of linksys that the domain name in basic setup must be filled with something even if not exist: toto1.com for one et toto2.com for the other.
    Be carreful to set the advancing setting with the same parameters on both router.
    One time on a week, i must disable vpn endpoint and enable for "init" it.
    If you want, we can test vpn between your router to mine and my routeur to your's.
     
  8. rplankenhorn

    rplankenhorn LI Guru Member

    I tried copying your config and it still doesn't work. I have some screenshots that I can email you if you give me an email address. Thanks again for all of your help.
     
  9. cactusfazer

    cactusfazer Network Guru Member

    mail sent you in your private message
     
  10. DocLarge

    DocLarge Super Moderator Staff Member Member

    Hmmm,

    have you tried setting your lifetimes to the same exact settings? I normally set the phase I and the phase II with the same timeouts (i.e., 28800)

    Other than that, I don't see to much wrong with your configuration.

    Jay
     

Share This Page