Virtual Private Networks VPN Connection between Netgear FVS318 and Draytek Vigor 2900

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
VPN Connection between Netgear FVS318 and Draytek Vigor 2900 derheinrich 10-25-05
Posted by derheinrich on October 25, 2005, 9:29 am
Please log in for more thread options


I have just managed to connect a Draytek Vigor 2900 and a Netgear
FVS318 router successfuly per VPN using 3DES encryption.

The setup is pretty easy (as it always is once you've got it running).

In this scenario the Draytek will be connecting to the Netgear router.
The Draytek router is behind our ISP's router which has a static IP and
full portforwarding towards the Draytek router enabled. Since this one
will be making the call we don't need to know which ports are needed
for VPN/IPSEC.

The Netgear router has a dynamic IP, a full qualified domain name
registered with dyndns and Dynamic DNS set up in the configuration
menu.

The Netgear-router is on a 192.168.3.0/255.255.255.0 subnet.
The Draytek-router is on a 192.168.0.0/255.255.255.0 subnet.

==================================================================
Netgear:

Go to VPN-settings and select an empty slot.

Connection Name: FeelFree
Local IPSec Identifier: 0.0.0.0
Remote IPSec Identifier: 0.0.0.0
Tunnel can be accessed from: a subnet of local address
Local LAN start IP Address: 192.168.3.0
Local LAN IP Subnetmask : 255.255.255.0

!!This is an important part. It seems that there is a bug if you tell
the router that it can access a subnet. So in this case you have to
define a range of IPs otherwise you will receive the strange "
#hahaha.... next payload type of ISAKMP Hash Payload has an unknown ...
" error in the vpn-log.

Tunnel can access
Remote LAN start IP Address: 192.168.0.1
Remote LAN finish IP Address:192.168.0.254

Remote WAN IP or FQDN: yourhost.homelinux.org

Secure Association: Main Mode
Perfect Forward Secrecy: Disabled
Encryption Protocol: 3DES
PreShared Key: YourPresharedKey
Key Life         28800
IKE Life Time         86400

NETBIOS Enable: (I turned it off)
====================================================================

====================================================================
Draytek Vigor 2900 (I'm translating this from the german menu, so some
terms might not be 100% identical to the english menu)

1. Go to VPN / LAN-LAN Connection and select an empty slot

2. Set connection to "Always on". This automatically changes the
connection-direction to "out"

3. Under connection to external LAN select "IPSec tunnel". This will
automatically activate the IPSec-Key-button.

4. Press the IPSec-Key button and type in the same IPSec-key which used
in Preshared-Key in the Netgear configuration.

5. Set Security to "High security (ESP)" and select "3DES
(authenticated)"

6. Press "Advanced" (button under high security) and
set phase 1 mode to "Main Mode"
set Phase 1 Proposal to "3DES_MD5_G1"
set Phase 1 Key lifetime to 28800
set Phase 2 Key lifetime to 86400
perfect foward secret "OFF" !!!
leave Local ID empty

7. Proceed to TCP/IP settings
set remote IP to an unused IP from the Netgear subnet (e.g.
192.168.3.51)
set remote router to the netgear router IP (e.g. 192.168.3.45)
set remote network IP to the Netgear subnet (e.g. 192.168.3.0)
set subnet mask to 255.255.255.0

=======================================================================


This worked for me.

I also downgraded the Netgear firmware to 2.3 and haven't checked if
the 2.4 will still do the job. I also find the 2.3 firmware faster than
the 2.4-version. There are quite a few negative comments concerning the
FVS318 around and they seem to have their reason. So if you read this
before buying the FVS318/FVM318 and want to use it for VPN ->don't buy
it<-.


Oliver



Similar ThreadsPosted
VPN Connection between Netgear FVS318 and Draytek Vigor 2900 October 25, 2005, 9:29 am
Vigor 2900 VPN and IPfilter October 10, 2005, 11:38 pm
NetGear FVS318 VPN connection question[s] August 17, 2006, 8:46 pm
VPN: Netgear WGT624 <-> Draytek 2500/2600? November 16, 2005, 1:52 pm
Netgear FVS318 to FVS318 - no tunnel - take a look at my settings - what am I missing? June 7, 2005, 5:59 am
Netgear FVS318 to FVS318 - no tunnel - take a look at my settings - what am I missing? June 7, 2005, 6:07 am
Netgear FVS318 w/ NetGear ProSafe 10.1 VPN client help needed please March 28, 2005, 2:38 pm
Netgear FVS318 w/ NetGear ProSafe 10.1 VPN (logon help needed) April 6, 2005, 7:15 pm
netgear fvs318 March 2, 2008, 2:29 am
Netgear FVS318 Router/VPN... March 16, 2006, 7:15 pm
NetGear FVS318- Does SEND LOG work for anybody?? April 11, 2005, 6:08 am
NetGear FVS318- Does SEND LOG work for anybody?? April 28, 2005, 9:25 pm
Netgear ProSafe VPN Firewall FVS318 July 26, 2006, 7:06 pm
cisco 1800 / netgear fvs318 May 25, 2007, 4:21 pm
Connect from a dial-up to an Netgear FVS318? July 9, 2007, 4:29 pm