?
Solved

VPN between Netgear router and Zyxel firewall

Posted on 2012-09-17
4
Medium Priority
?
2,348 Views
Last Modified: 2012-09-23
Hello, I have a big problem on a new network I'm managing.

I need to create a VPN between the network's firewall (a Zyxel USG-50) and my office router (Netgear DGND3700).

The Zyxel is 192.168.1.254 on the Lan, and it is 192.168.0.2 on the Wan.

The Netgear is 192.168.0.1 on the Lan. Dynamic ip, but I'm using a Dyn Dns service.

I will show you the configurations I'm using (some data is obviously fake):

Netgear:
Netgear config
Zyxel:
Zyxel VPN configZyxel VPN gateway config
Here's also a sample of the logs.

Netgear:
Mon, 2012-09-17 20:55:12 - [*] initiating Main Mode to replace #24 
Mon, 2012-09-17 20:55:22 - [*] STATE_MAIN_I1: retransmission; will wait 20s for response 
Mon, 2012-09-17 20:55:42 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response 
Mon, 2012-09-17 20:56:22 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response 
Mon, 2012-09-17 20:57:02 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response 
Mon, 2012-09-17 20:57:12 - [*] initiating Main Mode to replace #25 
Mon, 2012-09-17 20:57:22 - [*] STATE_MAIN_I1: retransmission; will wait 20s for response 
Mon, 2012-09-17 20:57:42 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response 
Mon, 2012-09-17 20:58:22 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response 

Open in new window


Zyxel:
LOG
I don't know what I'm doing wrong, this is my first VPN...
0
Comment
Question by:Daniele Brunengo
  • 3
4 Comments
 
LVL 16

Expert Comment

by:Syed_M_Usman
ID: 38408837
Dear,

i would like to have below info;

1) Zyxel USG-50---- is this Main office or Site Office?
2) Netgear DGND3700---- is this Main office or Site Office?
3) how many Static ip address you have on each location?
4) what are the LAN address on each site...

just for your info the VPN can work if;

|-----------------------Site A------------------------------||-----------------------Site B------------------------------|
                Zyxel USG-50                                                    DGND3700
                  |-->WAN (Public IP)                                            |WAN (Public IP or Dynamic
                  |                                                                            |
              LAN                                                                          LAN
    192.168.1.0/24                                                              192.168.0.0/24

you just need to make sure both LAN subnets are different.
0
 

Author Comment

by:Daniele Brunengo
ID: 38410969
Zyxel is in the site's office, Netgear in my main office.

I have 4 static ips in my main office, about 20 in the site's office.

The site has 192.168.1.0, my office 192.168.0.0.

The site though also has a wan handled by the firewall. The wan's router has an ip of 192.168.0.1 and the firewall 192.168.0.2. The firewall is 192.168.1.254 in the lan.
0
 

Accepted Solution

by:
Daniele Brunengo earned 0 total points
ID: 38411203
I have solved it. The problem was in my office lan ip 192.168.0.0 being the same as the wan ip used by the firewall (while the firewall's lan ip is different 192.168.1.0). I had to change my office ips so that it's different from both. So I set it to 192.168.2.0 and now it works.
0
 

Author Closing Comment

by:Daniele Brunengo
ID: 38426037
I solved it, didn't get much help though, aside from that answer from somebody who doesn't really seem to have fully read the question.
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question