Question

Linksys RVS4000 vpn setup

Asked by: jasonkk

I was trying to setup a VPN on RVS4000.

I configured a below VPN setting on RVS4000 but the status says it is down.

Can anyone tell me what is wrong and how to configure correctly?

 

Thanks


Local Group Setup  Local Security Gateway Type:   IP Only

IP address: xxx.xxx.160.99
Local Security Group Type:  Subnet
IP Address:  192.168.0.1  
Subnet Mask:  255.255. 255.0    
--------------------------------------------------------------------------------

Remote Group Setup  Remote Security Gateway Type:   Any

Remote Security Group Type:  IP Addr

IP Address:  192.168.2.0
This Gateway accepts requests from any IP address.
Subnet Mask:  255.255.255.0    
------------------------------------------------------------------------------

IPSec Setup  Keying Mode:  IKE with Preshared keyl
Phase 1:
Encryption:  3DES  
Authentication:  MD5
Group:  768-bit
Key Life Time:   28800Sec.

Phase 2:

Encryption:  3DES  
Authentication:  SHA1  
Perfect Forward Secrecy:  Enable


Status  Down

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-04-02 at 11:57:40ID24289884
Topic

Virtual Private Networking (VPN)

Participating Experts
2
Points
250
Comments
21

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Can a Sonicwall Hardware VPN Tunnel to a Linksys VPN R…
    I have a Linksys to Linksys Firewall that works fine. After installing a new Sonicwall, with VPN functionlality, I thought that it might be better to make the AVPN run from Linksys to Sonicwall. The question is: can it be done or not. Here is the Linksys Config: Home Offic...
  2. IPSec Gateway to Gateway Linksys RVS400 VPN
    I am unable to establish a gateway to gateway VPN using Linksys RVS4000 boxes at each end. I am using IPsec. At one end I have a cable modem that is passing a public static IP directly to the linksys box. From the outside world I am unable to ping this public IP. On the o...
  3. VPN Trouble - Linksys WRV4400N and Cisco 3030 …
    I am trying to set up a IPSEC VPN tunnel between a linksys WRVS4400N and a cisco 3030 concentrator. The 3030 on the distant end is seeing traffic. And I am seeing traffic in my logs. Phase 1 doesnt come up. Our preshared key has been verified. The IPs at both ends have b...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: SysExpertPosted on 2009-04-02 at 12:46:46ID: 24053751

IP Address:  192.168.0.1    should be

IP Address:  192.168.0.0  probably

I hope this helps !

 

by: jasonkkPosted on 2009-04-02 at 13:07:15ID: 24053955

No, it still doesn't work.
Do you think all the setting that I mentioned above are correct?

 

by: SysExpertPosted on 2009-04-02 at 13:21:57ID: 24054099

1) did you ping from a 2.x address to a 0.x address or the reverse.

Tunnels only come up when there is traffic or you use a connect button ( if there is one )



Are both ends set up the same way ( revesed Local IPs though )


 

by: jasonkkPosted on 2009-04-02 at 13:35:22ID: 24054229

Actually the 2.x is not real one I just put the number since it was mandatory field even though I selected the Any for gateway type.

Here is what I'm trying to do.
This RVS4000 router is in the office(T1) and I want to connect to the office network from my home(DSL).

RVS4000 IP: xxx.xxx.160.99 (Wan)
RVS4000 IP: 192.168.0.1 (Lan)
Home 192.168.1.8 (Lan)

Thanks

 

by: RobWillPosted on 2009-04-03 at 15:46:49ID: 24064991

IP Address:  192.168.2.0
                     0.0.0.0  = any
I would change that.

As SysExpert stated it will show status down unless a remote user is connected.
Based on your configuration I assume you are using an IPSec VPN client for remote users to connect. If so which client? Your configuration is not for use with Linksys Quick VPN or Windows clients, nor another remote VPN router. The only one I know that will work for sure is www.TheGreenBow.com
Instructions: http://www.thegreenbow.com/doc/tgbvpn_cg_Linksys_RVS4000_en.pdf

 

by: jasonkkPosted on 2009-04-03 at 15:58:06ID: 24065035

Thanks for your reponse.
I thought nobody is going to answer my question.
Fiirst, there is a summary status screen that shows connect button which it will change to disconnect after the connection so I think something is wrong with my setting.
Second, to use Quick VPN how the configuration need to be changed.

Thanks

 

by: RobWillPosted on 2009-04-03 at 16:30:57ID: 24065174

None of that page need be configured for the QuickVPN client. It is on a different configuration page and basically only needs a user name and password. You must also use the matching version of the QuickVPN client.
From the RVS4000 manual:
1.Click the VPN tab.
2. Click the VPN Client Accounts tab.
3. Enter the username in the Username field.
4. Enter the password in the Password field, and enter it again in the Re-enter to confirm field.
5. Click the Add/Save button.
6. Click the Active checkbox for VPN Client No. 1.
Click the Save Settings button.

 

by: jasonkkPosted on 2009-04-03 at 16:41:15ID: 24065221

I already setup the VPN client account page but I still can't connect.
I still think vpn setting on RVS4000.
Maybe I have to change the firewall setting too?

 

by: RobWillPosted on 2009-04-03 at 17:00:57ID: 24065317

All you have to do on the RVS4000 is username and password. I have done lots of them.
However the QuickVPN client is the most troublesome VPN client available today. There are pages of blogs outlining potential issues.
For starters:
-The RVL4000 must have a public IP assigned to it
-The client can only be behind a single routing device. i.e. it cannot be behind a modem that is a combined modem and router, in conjunction with a standard router
-it does not work at all behind some routers
-the site from which you are connecting cannot use the same subnet as the suite to which you are connecting
-the VPN client must match the version of the firmware on the router. Some versions require exporting a certificate from the router and installing on the client
http://www.linksys.com/servlet/Satellite?c=L_CASupport_C2&childpagename=US%2FLayout&cid=1169671133867&pagename=Linksys%2FCommon%2FVisitorWrapper&lid=3386737314B161&displaypage=nodata#versiondetail
-the traffic can be blocked by software such as Symantec anti-virus with Internet worm protection enabled, McAfee security suite, ZoneAlarm, Windows Live One Care, and others.

Some sample sites:
http://www.experts-exchange.com/Hardware/Networking_Hardware/Routers/Q_22427172.html?cid=237#a20027681
http://www.linksysinfo.org/forums/showthread.php?t=47114
http://www.linksysinfo.org/forums/showthread.php?t=35652

 

by: jasonkkPosted on 2009-04-06 at 14:06:13ID: 24081718

I've tried and still doesn't work.

 

by: RobWillPosted on 2009-04-06 at 18:09:20ID: 24083250

It is very difficult for us to isolate the problem. As mentioned though the QuickVPN works well there can be many issues that can block the VPN traffic. The links provided earlier list dozens of possible causes It is a case of addressing each one at a time. Also "still doesn't work" doesn't give us much to go on.

 

by: SysExpertPosted on 2009-04-06 at 19:58:44ID: 24083625

WHat do the logs on each side say. They should provide info regarding the VPN, and what is wrong.

 

by: jasonkkPosted on 2009-04-07 at 08:15:29ID: 24088189

In the log "home" cannot initiate the connection without knowing peer ip address.
And from the summary screen, the tunnel test button remains "connect" after I click.

And My answers for RobWill


-The RVL4000 must have a public IP assigned to it - Yes
-The client can only be behind a single routing device. i.e. it cannot be behind a modem that is a combined modem and router, in conjunction with a standard router - Tried at work and home
-it does not work at all behind some routers - ???
-the site from which you are connecting cannot use the same subnet as the suite to which you are connecting - Tried different subnet
-the VPN client must match the version of the firmware on the router. Some versions require exporting a certificate from the router and installing on the client - Tried both xp and vista version
-the traffic can be blocked by software such as Symantec anti-virus with Internet worm protection enabled, McAfee security suite, ZoneAlarm, Windows Live One Care, and others. - Disabled all

Some sample sites: - I've tried belows before I post the question here.
http://www.experts-exchange.com/Hardware/Networking_Hardware/Routers/Q_22427172.html?cid=237#a20027681
http://www.linksysinfo.org/forums/showthread.php?t=47114
http://www.linksysinfo.org/forums/showthread.php?t=35652

Thanks for your help

 

by: RobWillPosted on 2009-04-08 at 05:14:52ID: 24096251

>>"In the log "home" cannot initiate the connection without knowing peer ip address."
Sounds as if the RVS4000 public IP is not accessible.
-Is it possible it is not assigned a true public IP ( you mention it is) or it is behind a router or modem that is a combined modem and router?
-The client is using the wrong IP?
-The client is using a FQDN that does not properly resolve to the correct IP?

>>"the VPN client must match the version of the firmware on the router."
By this I mean the Quick VPN has multiple version numbers such as 1.1.10, 1.2.8 They must be the appropriate version for your router and firmware. I would make sure you have the latest firmware for your router and matching VPN client from:
http://www.linksys.com/servlet/Satellite?c=L_CASupport_C2&childpagename=US%2FLayout&cid=1169671133867&pagename=Linksys%2FCommon%2FVisitorWrapper&lid=3386737314B161&displaypage=nodata#versiondetail

>>"the traffic can be blocked by software such as Symantec anti-virus "
Some, I don't recall have to be uninstalled, not just disabled. Also it will not work if many of the other IPSec VPN clients are installed on the same machine.

 

by: jasonkkPosted on 2009-04-08 at 08:40:00ID: 24098500

My answers are in Bold.

Sounds as if the RVS4000 public IP is not accessible. - It is accessable since port forwarding is working.
-Is it possible it is not assigned a true public IP ( you mention it is) or it is behind a router or modem that is a combined modem and router? - I'm using T1 Cisco 1720 router.
-The client is using the wrong IP? - What do you mean wrong IP?
-The client is using a FQDN that does not properly resolve to the correct IP? - I don't get it. why FQDN is related with this issue since we are using IP

 

by: RobWillPosted on 2009-04-08 at 08:53:51ID: 24098677

>>"I'm using T1 Cisco 1720 router"
Why not use the Cisco VPN client to connect to that directly?

I assume then you have Internet=>Cisco=>Linksys. VERY doubtful  this will work.

>>"What do you mean wrong IP?"
The IP in the client needs to match the public IP of the RVS4000.

>>"why FQDN is related with this issue since we are using IP"
Correct if not using FQDN for client it doesn't matter.

 

by: jasonkkPosted on 2009-04-08 at 09:07:01ID: 24098844

Currently, I don't have any information on this Cisco 1720 because the person who installed left nothing.
And I don't have the password to check what kind of settings we have.
Currently we don't use Cisco 1720 as a router we're using is as T1 modem I think.
But 5 public IPs are assigned to this Cisco 1720 and I'm using one of them for Linksys RVS4000.
 

 

by: RobWillPosted on 2009-04-08 at 09:53:33ID: 24099399

I am not sure if the Cisco will pass through the IPSec traffic to RVS4000, I don't know them well enough. I know the QuickVPN client is very fussy about multiple routers being in place.

 

by: jasonkkPosted on 2009-04-08 at 11:18:12ID: 31565940

Thank you !
I guess it has something to do with Cisco 1720

 

by: jasonkkPosted on 2009-04-08 at 11:19:05ID: 24100205

Do you think "cannot initiate the connection without knowing peer ip address." related with Cisco router?

 

by: RobWillPosted on 2009-04-08 at 11:23:45ID: 24100264

It could be if it is blocking the connection through it to the RVS4000's public IP.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...