I have a Linksys to Linksys Firewall that works fine. After installing a new Sonicwall, with VPN functionlality, I thought that it might be better to make the AVPN run from Linksys to Sonicwall. The question is: can it be done or not.
Here is the Linksys Config:
Home Office Linksys Router:
Sonicwall Public UP is 192.168.168.250; Private IP 192.168.200.1
Linksys Router to Internet (VPN device) Private IP 192.168.168.2
Public IP 24.XX.XXX.XX
Remote Network: 192.168.1.0
Linksys Router to Internet (Remote VPN Device) Private ip 192.168.1.1
PUBLIC ip 66.YY.YYY.YYY
The pertinent Remote VPN Settings are:
Remote Secure Group: 192.168.200.0 (this is the WAN IP of the Sonicwall)
Mask: 255.255.255.0
Is this correct? or should the remote group be the router, which is 192.168.168.2?
Can I run the remote Linksys VPN be connected to the Sonicwall VPN, i.e. are
they compatible? Or do I need a Sonicwall client or firewall box on the other
side?
The entire remote VPN Settings on the Linksys are:
Tunnel Name: BCC
Local Secure Group IP 192.168.1.0 Mask 255.255.255.0
Remote Secure Group: IP 192.168.200.0 Mask 255.255.255.0
Remote Security Gateway: IP 24.XX.XXX.XX
Encryption: 3DES
Autherntication: MD5
IKE Key Management
PFS
Pre-shared Key: xxxxxxxxxxxxxxxxx
Key Lifetime: 3600 seconds
Phase 1: Agressive Mode
Proposal 1: 3DES Encryption
Authentication: MD5
Group: 768-bit
Key Lifetime: 28800 Seconds
Phase 2: #DES
MD5
PFS: On
Group 768 bit
Key Lifetime: 3600 seconds
Netbios broadcast On
Keep-Alive
How does this translate to the Sonicwall VPN settings that have some different terminology? I have guessed at the serttings below:
General:
IPSec Keying Mode: IKE using Preshared Key
Name: Warner
IPSec Primary Gateway: 192.168.168.250
IPSec Secondary Gateway: blank
Shared Secret: BetterCostControl1234
Destination Network: 192.168.1.0 Mask 255.255.255.0
Proposals:
IKE Phase 1:
Exchange: Aggressive Mode
DH Group: Group 1
Encrytion: 3DES
Auth: MD5
Lifetime: 28800
Ipsec Phase 2
Protocol: ESP or AH ????
Encryption: 3DES
Auth: MD5
Enable Perfect Forward Secrecy
DH Group: Group 1 ???????
Life Time: 28800
Advanced:
Enable Keep Alive
Default LAN Gateway: 192.168.200.1
Thanks for any advice and assistance