Daniele Brunengo
asked on
VPN between Netgear router and Zyxel firewall
Hello, I have a big problem on a new network I'm managing.
I need to create a VPN between the network's firewall (a Zyxel USG-50) and my office router (Netgear DGND3700).
The Zyxel is 192.168.1.254 on the Lan, and it is 192.168.0.2 on the Wan.
The Netgear is 192.168.0.1 on the Lan. Dynamic ip, but I'm using a Dyn Dns service.
I will show you the configurations I'm using (some data is obviously fake):
Netgear:
Zyxel:
Here's also a sample of the logs.
Netgear:
Zyxel:
I don't know what I'm doing wrong, this is my first VPN...
I need to create a VPN between the network's firewall (a Zyxel USG-50) and my office router (Netgear DGND3700).
The Zyxel is 192.168.1.254 on the Lan, and it is 192.168.0.2 on the Wan.
The Netgear is 192.168.0.1 on the Lan. Dynamic ip, but I'm using a Dyn Dns service.
I will show you the configurations I'm using (some data is obviously fake):
Netgear:
Zyxel:
Here's also a sample of the logs.
Netgear:
Mon, 2012-09-17 20:55:12 - [*] initiating Main Mode to replace #24
Mon, 2012-09-17 20:55:22 - [*] STATE_MAIN_I1: retransmission; will wait 20s for response
Mon, 2012-09-17 20:55:42 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response
Mon, 2012-09-17 20:56:22 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response
Mon, 2012-09-17 20:57:02 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response
Mon, 2012-09-17 20:57:12 - [*] initiating Main Mode to replace #25
Mon, 2012-09-17 20:57:22 - [*] STATE_MAIN_I1: retransmission; will wait 20s for response
Mon, 2012-09-17 20:57:42 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response
Mon, 2012-09-17 20:58:22 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response
Zyxel:
I don't know what I'm doing wrong, this is my first VPN...
ASKER
Zyxel is in the site's office, Netgear in my main office.
I have 4 static ips in my main office, about 20 in the site's office.
The site has 192.168.1.0, my office 192.168.0.0.
The site though also has a wan handled by the firewall. The wan's router has an ip of 192.168.0.1 and the firewall 192.168.0.2. The firewall is 192.168.1.254 in the lan.
I have 4 static ips in my main office, about 20 in the site's office.
The site has 192.168.1.0, my office 192.168.0.0.
The site though also has a wan handled by the firewall. The wan's router has an ip of 192.168.0.1 and the firewall 192.168.0.2. The firewall is 192.168.1.254 in the lan.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
I solved it, didn't get much help though, aside from that answer from somebody who doesn't really seem to have fully read the question.
i would like to have below info;
1) Zyxel USG-50---- is this Main office or Site Office?
2) Netgear DGND3700---- is this Main office or Site Office?
3) how many Static ip address you have on each location?
4) what are the LAN address on each site...
just for your info the VPN can work if;
|-----------------------Si
Zyxel USG-50 DGND3700
|-->WAN (Public IP) |WAN (Public IP or Dynamic
| |
LAN LAN
192.168.1.0/24 192.168.0.0/24
you just need to make sure both LAN subnets are different.