Microsoft
Software
Hardware
Network
Question : Problem: VPN Connection Problem (ATTN: CCOMLEY)
Good Morning:
I am trying to set up a VPN between two of our offices. I have a ZyXEL Prestige 662HW-61 at each end. The wireless network is working fine and all units behind the routers have internet access.
I have set up the VPN policy as follows:
IPSec Setup
Active YES Keep Alive YES NAT Traversal NO
UNIT 1 UNIT 2
Name: LYNWOOD CENTRAL
IPSec Key Mode IKE IKE
Negotiation Mode Main Main
Encapsulation Mode Tunnel Tunnel
DNS Server (for IPSec VPN) 0.0.0.0 0.0.0.0
Local:
Local Address Type RANGE RANGE
IP Address Start 192.168.1.40 192.168.2.33
End/Subnet Mask 192.168.1.49 192.168.2.39
Remote:
Local Address Type RANGE RANGE
IP Address Start 192.168.2.33 192.168.1.40
End/Subnet Mask 192.168.2.39 192.168.1.49
Address Information:
Local ID Type IP IP
Content BLANK BLANK
My IP Address WAN IP Address WAN IP Address
Peer ID Type IP IP
Content BLANK BLANK
Secure Gateway Address UNIT 2 WAN IP Address UNIT 1 WAN IP Address
Security Protocol:
VPN Protocol ESP ESP
Pre-Shared Key ABCDEFGH ABCDEFGH
Encryption Algorithm DES DES
Authentication Algorithm MD5 MD5
I have all firewalls off.
I enter 192.168.2.33 in UNIT 1 Internet Explorer Address Bar and I can not connect.
I enter 192.168.1.40 in UNIT 2 Internet Explorer Address Bar and I can not connect.
What must I do to enable connection?
P.S. CCOMLEY may help as he suggested these ZyXEL units.
Thanks, Russ
Answer : Problem: VPN Connection Problem (ATTN: CCOMLEY)
Shouldn't be anything to set up in Widows or mappings at this point. Once you are sure you have a connection you may have to configure any software firewalls such as the Windows firewall, and depending on what you want to accomplish you may want to map some drives.
In the mean time to confirm a connection just try pinging the LAN side of the remote router. Or try connecting to the router using it's LAN IP address rather than the public/WAN address. This would have to go through the tunnel to work, confirming a connection.
You mentioned "I have since found out that I can get into the remote router by putting it's IP Address into any Internet Explorer address bar." If that is with the LAN IP then the tunnel is working.
When you do have it running you won't see any computers when browsing unless you have WINS configured. Depending on your configuration you may not be able to connect to a computer by name either. That we can fix, but you should be able to connect by IP. So, to access a remote share you would use something like:
\\192.168.1.123\ShareName
Random Solutions
Problem: Lynksys, Microsoft, had both had problems with both.
Problem: Netgear Wireless Adapter Gone to Crap (low signal strength, slow speed, cut-offs)
Problem: WTF's up with my iSCSI network config ???
Problem: Commercial Grade Wireless Access Point
Problem: Multiple Site to Site VPNs / dynamic vs. static routing
Problem: Upgrading CPU - Athlon 3500+ to Opteron 185?
Problem: Change BIOS splash screen on bootup
Problem: $Mft Writeback errors on new WD160gig HD
Problem: Configure multiple Wireless Access Points
Problem: Think Pad locked