Link to home
Start Free TrialLog in
Avatar of Daniele Brunengo
Daniele BrunengoFlag for Italy

asked on

VPN between Netgear router and Zyxel firewall

Hello, I have a big problem on a new network I'm managing.

I need to create a VPN between the network's firewall (a Zyxel USG-50) and my office router (Netgear DGND3700).

The Zyxel is 192.168.1.254 on the Lan, and it is 192.168.0.2 on the Wan.

The Netgear is 192.168.0.1 on the Lan. Dynamic ip, but I'm using a Dyn Dns service.

I will show you the configurations I'm using (some data is obviously fake):

Netgear:
User generated image
Zyxel:
User generated imageUser generated image
Here's also a sample of the logs.

Netgear:
Mon, 2012-09-17 20:55:12 - [*] initiating Main Mode to replace #24 
Mon, 2012-09-17 20:55:22 - [*] STATE_MAIN_I1: retransmission; will wait 20s for response 
Mon, 2012-09-17 20:55:42 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response 
Mon, 2012-09-17 20:56:22 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response 
Mon, 2012-09-17 20:57:02 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response 
Mon, 2012-09-17 20:57:12 - [*] initiating Main Mode to replace #25 
Mon, 2012-09-17 20:57:22 - [*] STATE_MAIN_I1: retransmission; will wait 20s for response 
Mon, 2012-09-17 20:57:42 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response 
Mon, 2012-09-17 20:58:22 - [*] STATE_MAIN_I1: retransmission; will wait 40s for response 

Open in new window


Zyxel:
User generated image
I don't know what I'm doing wrong, this is my first VPN...
Avatar of Syed Muhammad Usman
Syed Muhammad Usman
Flag of Bahrain image

Dear,

i would like to have below info;

1) Zyxel USG-50---- is this Main office or Site Office?
2) Netgear DGND3700---- is this Main office or Site Office?
3) how many Static ip address you have on each location?
4) what are the LAN address on each site...

just for your info the VPN can work if;

|-----------------------Site A------------------------------||-----------------------Site B------------------------------|
                Zyxel USG-50                                                    DGND3700
                  |-->WAN (Public IP)                                            |WAN (Public IP or Dynamic
                  |                                                                            |
              LAN                                                                          LAN
    192.168.1.0/24                                                              192.168.0.0/24

you just need to make sure both LAN subnets are different.
Avatar of Daniele Brunengo

ASKER

Zyxel is in the site's office, Netgear in my main office.

I have 4 static ips in my main office, about 20 in the site's office.

The site has 192.168.1.0, my office 192.168.0.0.

The site though also has a wan handled by the firewall. The wan's router has an ip of 192.168.0.1 and the firewall 192.168.0.2. The firewall is 192.168.1.254 in the lan.
ASKER CERTIFIED SOLUTION
Avatar of Daniele Brunengo
Daniele Brunengo
Flag of Italy image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I solved it, didn't get much help though, aside from that answer from somebody who doesn't really seem to have fully read the question.