Post by Graham J[snip]
Post by David WadeThe 7530 does do Lan-2-Lan. In fact I am sending this using a pair of
7530s configured for lan to lan access using Wireguard. I swapped a
remote Draytek for a second 7530 after moving to Zen FTTP because the
Drayteks I used to use had poor VPN throughput (check the figures).
Please can I ask your advice?
I have a V2860 in my office and a FRITZ!Box 7530 AX at a nearby location
and would like to set up a VPN between the two. Both locations have
static public IPs.
The V2860 uses IPSec IKEv1 with a pre-shared key, and has the local and
remote IP address configured. I typically use this configuration to
communicate with other Vigor routers.
For this test I have Dial-in only configured, and "Alternative Subject
Name First", Security method Medium (AH), High(ESP DES, 3DES, AES all
checked.
The FRITZ!Box runs FRITZ!OS 7.80. I configured the option "Setting up
an IPSec VPN between two FRITZ!Box networks". So I provide the
pre-shared key and set up the relevant IP addresses, and have "Hold VPN
connection permanently".
<141>May 22 15:00:28 V2860n: Responding to Aggressive Mode from <Remote_IP>
<141>May 22 15:00:28 V2860n: Accept Phase1 proposals : ENCR
OAKLEY_AES_CBC, HASH OAKLEY_SHA
<141>May 22 15:00:31 V2860n: IKE ==>, Next Payload=ISAKMP_NEXT_HASH,
Exchange Type = 0x5, Message ID = 0x4dd30efe
<141>May 22 15:00:31 V2860n: IKE <==, Next Payload=ISAKMP_NEXT_HASH,
Exchange Type = 0x5, Message ID = 0x244ae727
<141>May 22 15:00:34 V2860n: IKE ==>, Next Payload=ISAKMP_NEXT_HASH,
Exchange Type = 0x5, Message ID = 0x434a0c5a
<141>May 22 15:00:34 V2860n: IKE <==, Next Payload=ISAKMP_NEXT_HASH,
Exchange Type = 0x5, Message ID = 0x473a2008
<141>May 22 15:00:36 V2860n: IKE ==>, Next Payload=ISAKMP_NEXT_HASH,
Exchange Type = 0x5, Message ID = 0x1e8f5eba
<141>May 22 15:00:36 V2860n: IKE <==, Next Payload=ISAKMP_NEXT_HASH,
Exchange Type = 0x5, Message ID = 0xf8611671
etc.
This sequence appears to repeat indefinitely, from which I conclude that
the FRITZ!Box is continually trying to gain access. The Vigor sees
this, sends an IKE message, then receives an IKE message. But nothing
more happens.
I don't think I can offer much help...
I have have a VPN as I have a house in Spain and so its useful to have a
VPN back through my UK setup. The Spanish setup is a pain as its CGNAT
and the router is direct into the Fibre.
In the UK I had Plusnet FTTC/VDSL with a 2862 and fixed IP.
After having some success with client VPNs to the Vigour I thought
Lan2Lan would be good, bought a TP-Link router which supports the same
VPN technology, took it to Spain but it would never connect.
As I am supposed to be enjoying myself when in Spain I didn't do much
debugging.
When I asked around no one seemed to have a solution, but as luck would
have it someone offered an older Vigour on Freecycle which I managed to
grab, took that to Spain and all worked well while I had VDSL.
When I moved to ZEN FTTP I initially routed all in-bound traffic from
their Fritz!box to the Draytek, the VPN continued to work but
performance was dire. Checking the specs for the routers showed why.
So I took the cowards way out, bought a second Fritz!box on E-Bay, took
it to Spain, replaced the Draytek and everything worked. I can even set
the VOIP up so I have a DECT that links back to router in the UK.
The fritz is lacking quite a bit of the functionality of the vigour, it
mostly suffices, and its not critical if it dies when i am not there...
Post by Graham JAny ideas as to how I should get the VPN to work? TIA.
Perhaps ask on the Fritz support forums. They seem more helpful than Vigour.
Dave