Solved

I have a DLINK DSR-250n, Need to setup Software VPN to it.

Posted on 2013-01-05
5
6,429 Views
Last Modified: 2013-01-08
Does anyone have any detailed instructions on how to setup an IPSEC VPN on a DLink DSR-250n Router to ShrewSoft VPN Client (the only one that is free and runs on Windows 7)
I'm having problems translating settings from one to another.

The DLink DSR models are supposed to be all the same.

ShrewSoft VPN Settings (These are not my settings, This is just showing settings screen)
ShrewSoft VPN 1ShrewSoft VPN 2
DLink DSR-250n router vpn settings (I want to know where these settings correspond to settings of the ShrewSoft VPN, and if any of these settings need changed)

DLink DSR-250n VPN Dropdown boxes choices:
Policy Type: Auto Policy / Manual Policy
IPSec Mode: Tunnel Mode / Transport Mode
Select Local Gateway: Dedicated WAN
Remote Endpoint: FQDN / IP Address
Protocol: AH / ESP
Local IP: Any / Single / Range / Subnet
Remote IP: Any / Single / Range / Subnet
Exchange Mode: Main / Aggressive
Direction/Type: Initiator / Responder / BothSelect Local Gateway:
Select Local Gateway:
Local Identifier Type: Local WAN IP / FQDN / User FQDN / DER ASN1 DN
Remote Identifier Type: Remote WAN IP / FQDN / User FQDN / DER ASN1 DN
Authentication Method: Pre-shared Key / RSA Signature
Diffie-Hellman (DH) Group: Group1(768bit) / Group2(1024bit) / Group5(1536) /         DH_Group14 (2048bit) / DH_Group15(3072bit) / DH_Group16(4096bit) / DH_Group17(6144bit) / DH_Group18(8192bit)
PFS Key Group: Group1(768bit) / Group2(1024bit) / Group5(1536) /         DH_Group14 (2048bit) / DH_Group15(3072bit) / DH_Group16(4096bit) / DH_Group17(6144bit) / DH_Group18(8192bit)

DLink Screen Shot1Dlink Screen Shot2Dlink Screen Shot3Dlink Screen Shot4Dlink ScreenShot5
0
Comment
Question by:ekurelowech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 69

Accepted Solution

by:
Qlemo earned 500 total points
ID: 38748846
I don't know the D-Links very well. But the ShrewSoft settings should be straightforward. You might want to read ftp://ftp.dlink.es/DFL/Ejemplos_de_Configuracion_NetDefend/How_to_configure_VPN_IPSec_with_FREE_Shrew_Vpn_software.pdf
for a simplified setup example.

In addition to that:
1. D-Link screenshot is ok as-is. The first tab of Shrew corresponds to that, you will have to enter the D-Link pulic IP, and (probably) set Auto Configuration to either disabled or "ike config push". Adapter Mode should be "Use a virtual ..". You might have to flip the "Obtain Automatically" setting and then provide a manual (remote) IP address for the VPN.
2. You will have to make sure you use local and remote ID in reverse order on Shrew, tab "Authentication" set to "Mutual PSK" - ShrewSoft "Local" is D-Link "Remote" and vice versa.
3. In Shrew "Authentication", "Credentials", just enter the same PSK as on D-Link
    In "Phase 1" do not use any AUTO settings, instead set to exactly the same as on D-Link:
       aggressive, group 2, AES, 128, sha12, 28800, 0
4./5. Are for Shrew "Phase 2" settings. Again, don't use Auto and match exactly.
AFAI have seen configs, you will need to set the Shew "Policy" level to unique or shared, and provide the remote network manually in the list box.
0
 

Author Comment

by:ekurelowech
ID: 38749676
It looks like alot more than I had. Wish I had a PDF with my exact Model .
I'll try it tomorrow,
On the 1st page of the shrewsoft,it has a port setting, is that the port that all vpn's use.
Or is there different ports used on different manufacturers, I don't see anything on the Dlink DSR-250n configuration.
0
 
LVL 69

Expert Comment

by:Qlemo
ID: 38750127
IPSec always uses 500/udp for first contact. It may switch to 4500/udp (NAT-T) if negotiated, or 10000/tcp for Cisco NAT-T. There are also some other proprietary ports, but in general, you only need to care about 500 and 4500.
0
 

Author Comment

by:ekurelowech
ID: 38753381
you were right on, the main problem was, I didn't reverse the FQDN's.
But I can't seem to get any DHCP working, The VPN works great if I configure the IP.
You have any ideas how to enable that to come from the router.
My router doesn't DHCP, my server does. Is this why it's not working.
On Dlink router Under GENERAL / Enable DHCP: I enable, but don't know where the DHCP is coming from.
On Shrewsoft Under GENERAL, I have AUTO CONFIGURATION: I tried all different settings.
All I get is DHCP timed out.
0
 
LVL 69

Expert Comment

by:Qlemo
ID: 38753899
The D-Link has to act as the DHCP server for this to work, or run a DHCP Relay Agent service. I really can't help much on implementing a dynamic IP method here, as it is highly depending on the device used whether it works at all, and how it needs to be configured.

Enabling DHCP Relay should be easy, if I read the manuals correctly. In DHCP settings on the D-Link you should be able to add a DHCP Relay; just enter the DHCP Server's IP here.

You will then need to enable Mode Config in the VPN settings (first screenshot). If you are lucky, that's all to make it work.
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question