Link to home
Start Free TrialLog in
Avatar of mcse2007
mcse2007Flag for Australia

asked on

DrayTek Vigor 2820n

Hi EE,

Does anyone has experienced setting up the VPN on DrayTek Vigor 2820n?

I've setup the VPN and Remote Access>Remote Dial In User with dial in type below then setup a VPN connection from my notebook with pre-shared key using protocol L2TP with IPSec BUT it ain't connecting:

PPTP
IPsec Tunnel
L2TP with IPSec Policy (None)

Do I need to enable the below also:
Specify Remote Node
Remote Client IP
Assign Static IP Address

Appreciate your time and help.
Avatar of mcse2007
mcse2007
Flag of Australia image

ASKER

What I discovered was, I can connect to the VPN from my phone using its network data carrier BUT I cannot connect to VPN when connected to the internet access point which is the DrayTek Vigor 2820n?

Is it normal that you cannot connect to VPN while you are connected to the internet via your own internet access point which is also the VPN appliance/ DSL router/ firewall?
ASKER CERTIFIED SOLUTION
Avatar of Alan Hardisty
Alan Hardisty
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
cheers
Glad you got it working - they can be "fun" to configure, but once done, they work like a charm.

I was setting two 2830n's yesterday and creating a site-to-site VPN between the two.  Once it was up and running, the link was solid, fast and reliable.

Thanks for the points.

Alan
excellent...didnt even such router existed until few day ago.

my issue at the moment is cannot ping the router ip address once I managed to connect using ipsec tunnel protocol...my vpn client ip is the same subnet as my router.

I have two sites to roll out such router and one with remote off site backup
You need different Subnet's for VPN to work happily.

If they are the same - you can't communicate properly as your local netowrk will look locally for resources that are remote and won't find them.

If you can change your IP Addessing so that one site is something like 192.168.0.0/24 and the other 192.168.1.0/24 then it will work happily.
will the router takes care of the routing if the remote user has diffirent iip address when you ping the router remotely? or you need to add route manually imside the router?
Router should take care of it.

Make sure you enable the router to be pinged (System Maintenance> Management) - it is disabled by default so the lack of ping might be simply a tick box that needs to be unchecked.
I managed to connect to Vigor 2820n using IPsec Tunnel with preshared key by following your link using DrayTek Smart VPN client. The Smart VPN client has settings identical with those of the DrayTek Vigor 2820n. BUT, when I ping from my notebook, I get the below reply,

Negotiating IP security.
Negotiating IP security.
Negotiating IP security.
Negotiating IP security.

The smart VPN client from my notebook connects to the VPN router using  IPsec Tunnel  but I cannot reach any of the servers from the LAN either by ping or RDP etc.

Do I have to create some filter etc, so I can allow incoming traffic to reach the LAN?

Isn't the VPN setup will takes care of the routing without needing to create filter policy?

DrayTek 2820n is easy to setup the VPN but it is harder to make it work properly???

How do you normally do your VPN client to VPN router set up?
Do you have the same internal IP Range where you are connecting from as the Office LAN IP Range?
is it on different subnet of my LAN