Question

How to configure Linksys Quick VPN software with Linksys RVS4000

Asked by: doulos777

Here is the setup.

We have a DSL connection with 1 Static IP address and are using a Linksys RVS4000 VPN Router.  The router is working great as far as DSL connectivity and we have been able to successfully open ports to allow access to the web server.

Question:  I now would like to setup the Linksys Quick VPN software to connect to the router for VPN access.  The documentation that came with the router did not tell me much about how I need to setup the router to get it to work properly with the software that I have setup on my laptop.  Can anyone tell me what I need to setup on the router in order for the Quick VPN software to connect to my network?

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2007-03-04 at 14:14:05ID22427172
Tags

linksys

,

rvs4000

,

vpn

Topics

Network Routers

,

Virtual Private Networking (VPN)

Participating Experts
4
Points
500
Comments
8

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Creating VPN on Linksys Router?
    I have a Linksys Firewall Router with a VPN Endpoint built-in to it. What do I have to do in order to setup a VPN network with the Router? Do I have to setup a server that will not be in my house?
  2. Port forwarding with a DSL modem and a Linksys router tha…
    What ports do I need forwarded for the VPN gateway to accept incoming request if my DSL is running NAT and my LINKSYS gateway is the VPN server. It looks like this: Internet Public NAT DSL modem: 71.128.93.77 --> NAT DSL modem Private: 192.168.2.1 --> LINKSYS VPN Ga...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: LucFPosted on 2007-03-04 at 15:41:23ID: 18651618

Hi doulos77,

Setting up QuickVPN is rather simple, please read the walkthrough on Linksysinfo at http://www.linksysinfo.org/modules.php?name=Forums&file=viewtopic&t=11664
(This one is for an WRV54G, but the main part is the same)
Make sure you're running the latest version of QuickVPN, and have the most current firmware on your RVS4000.

If you're connecting from a XP computer, make sure the windows firewall is disabled, otherwise it'll get stuck at "verifying network", still, QuickVPN will normally work nicely through a NAT router.

Best regards,

LucF

 

by: RobWillPosted on 2007-03-04 at 17:17:29ID: 18651938

The RVS4000 is slightly different than the earlier models, but just as easy.
- Go to the VPN page and then click the VPN client accounts tab
-add a user name, password, and click the add button
-mark as active and click save settings at the bottom of the page
-On the connecting client install the QuickVPN client software
-make sure it is the latest version (important) ver 1.1.0 It is available on the Linksys site;
http://www.linksys.com/servlet/Satellite?c=L_CASupport_C2&childpagename=US%2FLayout&cid=1169671133867&pagename=Linksys%2FCommon%2FVisitorWrapper&displaypage=nodata#versiondetail
-right click on the client icon (lower right) and choose connect
-you can name the connection whatever you like, then enter you RVS4000's WAN/external static IP, your user name, and password, and click connect
-done

One note the 2 sites need to use different subnets. As an example if the main site uses 192.168.1.x then the remote site must use something else like 192.168.2.x Because of the potential conflicts with mobile clients using similar subnets at hotels and such try to use something less common at the RVS4000 site if possible, like 192.168.123.x
Another point is sometimes name resolution doesn't work over VPN's. Though this is usually "fixable" try connecting to resources by IP if having problems, such as:
\\192.168.123.123\ShareName

 

by: doulos777Posted on 2007-03-04 at 18:01:41ID: 18652114

I upgraded the Quick VPN software, but I can still not connect on either port and get an error.  I even disabled the port forwarding that sent HTTPS traffic to my server and disabled VPN passthrough.

I have the router firmware up to the latest version.

Any ideas?

 

by: RobWillPosted on 2007-03-04 at 18:19:10ID: 18652157

The reason I suggested you used the newest client is because of th potential HTTPS conflict but that should be resolved by using the port 60443 option, even if you didn't disable you port forwarding.
VPN pass-through on the RVS4000 should be turned off, but may help on the client router if it is an option.

The QuickVPN can be finicky some times. One thing I find is though with some routers NAT-T (Network Address Translation-Traversal) is supposed to be supported it doesn't work all the time.
a) is the static IP on the RVS4000)'s WAN interface a true public IP, i.e. not 192.168.x.x, 10.x.x.x, or 172.16-31.x.x  It needs to be a true public IP.
b) on the client PC, as a test only, try connecting it directly to the modem as a test. Make sure the Windows firewall is enabled, and Windows and virus updates are current.

You might want to have a look at the following VPN check list:
From:
http://www.linksysinfo.org/modules.php?name=Forums&file=viewtopic&t=11664
QUICKVPN CONNECTION FOR WRV54G/RV0XX SERIES ROUTERS

NOTE: There may be variances in some areas of web interface, but this document is proven to work!  

ON THE WRV54G/RV0XX ROUTERS:
1) Setup Page

Internet Connection Type: Automatic Configuration (DHCP)

MTU: Auto

DHCP Server: Disable

Time Setting: (GMT) England [Obviously set this to your own zone or leave at default]

NOTE: If your ISP has recently changed from “data” to “ipstream” you may have to change the MTU from “auto” to “manual” in order to allow vpn data transfer. A common symptom of change in Ethernet technology is when you try to transfer information across a tunnel and you get “Network is no longer available.” In this instance, the MTU is set “too high” (i.e., 1492) and isn’t able to “pass through” the segment at the distant end. Think of a 6 foot tall man trying to fit through a door made for a 4 foot child. By adjusting the MTU to suit the situation, you now have a means of assuring data gets through. (Doc/1 Aug 05)

2) Security ---> VPN Page

Ipsec: Enable
PPTP: Enable
L2TP: Disable

NOTE: This goes away from previous advice I’ve given but we’re trying something new. People were able to connect before, so this slight change really shouldn’t alter that much. Furthermore, the 50 vpn tunnels that come with the WRV54G/RV0XX routers are designed to work with third party vpn clients (i.e., SSH Sentinel, Greenbow, Logmein, etc...) and "not" with quickvpn. Quickvpn handles all aspects of negotiation by itself (now that the mystery is solved, it's a clever little tool to me  )
Also, in the WRV54G/RV0XX manual, where it shows you how to create an IPSEC policy, if you're using quickvpn, this, by default of installation is already done for you by Quickvpn (look in the Program Files\Linksys\Linksys VPN Client directory on your computer and you will see this.) If you are "not" going to use Quickvpn, you could try this (yes, some people have been able to do it). Also, as noted by Chris Watts (a..k.a. Chris547), quickvpn uses a randomly created pre shared key everytime it connects. I think I may love quickvpn now...

Remaining settings on this page should be disabled.

3) Access Restrictions:

- Start off by using a simple name and password combination such as

username: test
password: tester

4) Apps & Gaming

"NO" vpn port forwarding settings of any kind (500, 1701, 1723, etc...) are required for quickvpn to work. It establishes its own tunnel.

Additionally:

- Try using firmware 2.37.13, 2.38 (you can download 2.38 from linksysinfo.org), or 2.38.6. I’m currently using the 50 user license upgrade from Linksys (firmware version 2.37E) and it works perfectly!

- SNMP & UPNP are disabled.

- Make sure the ipsec service under settings is started. If you’ve ever loaded SSH Sentinel, SSH knocks ipsec offline and you never even know it unless you happen to be checking services to see why your tunnel doesn’t come up (I found this information out surfing forums).

- "DO NOT" have any other vpn application "LOADED" on your machine other than quickvpn; even if you have another vpn application loaded and its process is shut off in the back ground, quickvpn still "will--not--run" if it's loaded. If you happen to be able to do this, you're quite fortunate, otherwise, load quickvpn only to avoid conflict.

- Disable any firewall that you currently have running for the moment (again, we're establishing a baseline). I use Norton Internet Security 2003 and can connect to Dave's vpn segment with my firewall up so you might want to consider a new firewall in the event you can't connect with your current firewall running. Incidentally, when I’m at a wireless internet café, I have to drop my firewall on my laptop to make the connection to vpn, but I’m sure this is just something to do with how the router policies of that local business’s router are enforced. Other than that, I connect to a remote vpn host (from my home”) with my firewall up. Once you’ve made the connection, just turn your firewall back on.

- Copy and paste this link into your browser to get your WAN IP address if you don’t know it for sure (http://remote.12dt.com/rns/) to place in quickvpn's "Server Address" field.

Here's one more thing. Copy and paste this link into your browser (http://www.dslreports.com/drtcp). This application will allow you to adjust the MTU setting of your NIC "on the fly" if you bump into a problem with the MTU causing tunnel drops. Make your MTU setting "On The Client" 1458 “if” there are problems with tunnel connectivity.



REASONS YOU CANNOT CONNECT WITH QUICKVPN (NEW)

1. The quickvpn client is not the only vpn client loaded on the client machine.

2. MTU on the WRV54G you are connecting to isn't set at "auto" and/or the packets being sent from the client computer are too large (should this be the case, download "DrTCP" and set the MTU of the client's NIC to 1458). Additionally, it doesn't hurt to check and see if the MTU on the client router is set at "auto" also.

3. You are trying to connect through a dialup or ISDN connection.
NOTE: I have never been able to connect from a dialup/ISDN connection with quickvpn. More power to those who can.

UPDATE: Recently, someone was able to connect over dialup in a highly "unusual" manner Basically, when connecting over ISDN, quickvpn hangs at “verifying network” but it will still negotiate the ip security portion and allow you access to your LAN. The only way to close the connection is to terminate it through task manager.

4. The firewall software on your computer is registering the "ACK" conversation from the distant-end device (wrv54g) as an "Invalid ICMP Type." In this instance you can either "shut down" the firewall for the session or, as I've done, uninstalled my firewall software (NIS 2004) and quickvpn, then reinstalled both (Norton first followed by quickvpn). After that, launch quickvpn, and once Norton detects it, it establishes all the proper rules to allow it to pass through the firewall. Hopefully your firewall software should do the same.

In the case of #4, I never caught this until I noticed after reloading one of my computers, I had to drop the firewall on one of them to access "the same damn share" as the others, but I didn't have to bring the firewall down on any of the others except that one particular machine.

5. IPSEC Passthru is not enabled on the client/distant end router.

6. You have communication software loaded that is preventing quickvpn authentication with the wrv54g router

Note: I loaded software from motorola cellphone that installed its own "liveupdate" software that blocked quickvpn from talking to my wrv54g router. I knew there was a program I'd recently loaded that was most likely the problem because I had just used quickvpn an hour prior.

7. You have installed two nic’s on the client computer and quickvpn is trying to utilize the connection that is not assigned an ip address. Simply disable the card that is not being used.

8. IPSEC is not running on the client computer you’re connecting with. To remedy this, go into control panel, administrative tools, then click on services. If IPSEC isn’t started, set it to automatic and start the service. If you’ve ever used ssh sentinel, this knocks your ipsec out and you have to go into windows services to restart it.

9. The user account and password is not created or has not been typed in correctly.

10. Large downloads will disrupt the routers tables causing quickvpn to not respond every so often.

11. Quickvpn terminates in the middle of a quickvpn session. Just like #10, this hoses up the routing tables for vpn. The answer is to delete all existing accounts and recreate them (don’t create the same username and passwords twice) or reset the router to factory default and start from scratch.

These configurations are just what I’ve noticed when having quickvpn problems. People world wide have been following this guide with and have had success with the WRV54G, RV042 and the RV082 routers. Again, this is just a baseline. When you figure out what you need, just vary things as needed.


 

by: LucFPosted on 2007-03-05 at 10:08:13ID: 18656115

Hi doulos777,

You said: "but I can still not connect on either port and get an error. "
What's the error message you're getting? It might help in figuring out what's the issue with your connection.

Best regards,

LucF

 

by: wcbagleyPosted on 2007-09-19 at 13:15:33ID: 19924039

QuickVPN makes the following proposals to the RVS4000 in the phase-1 IKE:
1) 3DES,SHA1,DH2,PSK,SA Lifetime=28800 sec
2) 3DES,MD5,DH2,PSK,SA Lifetime=28800 sec
3) DES,MD5,DH1,PSK,SA Lifetime=28800 sec
Try these settings on the RVS4000

VPN access apparently will not work if a DMZ is configured. I have not found this documented anywhere.

I hope this helps!

 

by: tlamoniaPosted on 2007-09-30 at 19:44:20ID: 19988635

There's a known interoperability issue with the QuickVPN software and the RVS4000.  This is an excerpt from the QuickVPN release notes:

Known Issues:
     
1. There is a known issue with Windows XP SP2 Firewall - ICMP packets are always dropped by the Firewall when the Firewall is enabled. The issue will cause the QuickVPN Client not being able to establish a tunnel with the remote QuickVPN Server successfully. Microsoft has released a patch to fix this issue. Once you install the patch, the issue should be resolved.
http://support.microsoft.com/kb/889527/en-us

2. QuickVPN Client v1.2.5, when running on Vista, has an interop issue with RVS4000 firmware v1.1.09 and v1.1.11 (beta). The interop issue was fixed by firmware v1.1.13 (beta).

3. QuickVPN Client v1.2.5, when running on Vista, has an interop issue with WRVS4400N firmware v1.0.12, v1.0.13 and v1.0.15 (beta). The interop issue was fixed by firmware v1.0.16.

4. Users need to have the administrative rights in order to use QuickVPN Client. This is a constraint posed by the Windows operating systems.

This issue is also apparent in Windows XP Pro SP2, which I'm running on my laptop.  The RVS4000 1.1.13 Beta code is available on http://www.linksysinfo.org.  Use it at your own risk!!

The primary issue that I've seen is that the client hangs on "Verifying Network" although the VPN connection is active.  So it's really just an annoyance and should not affect the perform or connectivity of your QuickVPN connection.
-Todd

 

by: tlamoniaPosted on 2007-10-06 at 07:59:30ID: 20027681

Got it to work thanks to Linksys.
Windows XP Users:
Download and install QuickVPN version 1.1.0
Windows Vista Users:
Download and install QuickVPN version 1.2.6
Software can be found on the Linksys website in the support section for the RVS4000.

http://www.linksys.com/servlet/Satellite?c=L_CASupport_C2&childpagename=US%2FLayout&cid=1169671133867&pagename=Linksys%2FCommon%2FVisitorWrapper&lid=3386737314B161&displaypage=nodata

Don't forget to copy your client PEM file (not the Admin PEM file) into the installation directory!  I'm running RVS4000 firmware version 1.1.13 Beta.
-Todd

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...