Solved

Connecting two Drayteks over IPSec

Posted on 2016-07-20
2
51 Views
Last Modified: 2016-07-25
We are currently aiming to connect a Draytek VigorPro 5510 with a Draytek Vigor 3900 using an IPSec tunnel.  The 5510 is the dial out router and the 3900 the dial in.

The configs are as follows:
IKE Phase1 Proposal: AE128 G1
Authentication: SHA1/MD5
Phase2 Proposal 3DES without auth
Auth: All
Perfect forward Secret: Disabled

The error I can see in the Syslog are: Payload malformed and Payload malfornmed after IV

Were stumped on this one and would appreciate some input

Cheers
0
Comment
Question by:itd-helpdesk
2 Comments
 
LVL 22

Accepted Solution

by:
David Atkin earned 500 total points
ID: 41721321
According to this:
http://www.thegreenbow.com/support_flow.html?page=121058

The message "Payload Malformed" was received during the IKE exchange. It means the Phase 1 algorithms doesn't match the gateway configuration.

Change the proposal on Phase1 to something else (on both Drayteks) and re-test.

There is a well written article by Draytek for IPSEC VPN Connections - See here:
http://www.draytek.co.uk/support/guides/kb-lantolan-ipsec

You will have to register to view the article.
1
 

Author Comment

by:itd-helpdesk
ID: 41727701
Thanks for the reply, I definatly have a good way forward from this.

Cheers
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Do you have an old router lying around the house that you don’t know what to do with? Check the make and model, then refer to either of these links to see if its compatible. http://www.dd-wrt.com/site/support/router-database http://www.dd-wrt.c…
Overview Often, we set up VPN appliances where the connected clients are on a separate subnet and the company will have alternate internet connections and do not use this particular device as the gateway for certain servers or clients. In this case…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now