Cisco VPN :: WRVS4400N VPN IPsec Gateway To Gateway Setup?
Jan 29, 2012
Just bought 3 WRVS4400N, I wanted to setup gateway to gateway VPN. I followed the instructions on the WRVS4400N admin guide and VPN does not connect. I also downloaded the VPN setup wizard and that also did get the gateway connected. Everything seems to be correct. Do I have to enable anything else? Firewall setting?
Below is my config.
IPSec VPN Tunnel: Enabled
Tunnel Name: TUN01
Local Security gateway: IP only
WAN1 IP: 192.168.100.1
SUBNET: 255.255.255.0
Local Security type: subnet
LOCAL IP: 10.10.10.1
SUBNET: 255.255.255.0
Can I have use a Gateway-to-Gateway IPSec tunnel whereby a user can surf the Internet using his local Internet connection and at the same time connect through the IPSec tunnel to a remote subnet using RVS4000 routers?
I have two Cisco RV8082 Routers which I would like to setup a VPN Tunnel with Gateway to Gateway. One location is a static IP Address. The other location is a dynamic IP address.
i am trying to setup a vpn Gateway To Gateway when i setup the vpn i can ping the 2 rv042 i cant see any computer in the network places when there comect we need to see the computer in the network places so are pos will run?
Im having trouble with getting my VPN to work on my brand new WRVS4400N router. i cant find the solution to my problem, no matter how much i read about it.
WRVS4400N: Firmware Version: V2.0.0.8-ETSI
QuickVPN: Version: 1.4.1.2
The laptop im trying to connect to the gateway via VPN is a Windows 7 x64 HP Elitebook 8540p with a internal mobile broadband (HSPA+)So.The scenario is that i've installed the QuickVPN client on my Win7-machine without any trouble.I've created a user in the web-administration of the router.The router is configured to disable "Block WAN requests" in the firewall, apart from that the firewall is on.When trying to connect - with a valid certificate that i created, i get a error message after the dialog telling me "Verifying network":"The remote gateway is not responding. Do you want to wait?".
The log.txt tells me:
...2010/10/06 00:00:28 [STATUS]Verifying Network...2010/10/06 00:00:34 [WARNING]Failed to ping remote VPN Router!2010/10/06 00:00:37 [WARNING]Failed to ping remote VPN Router!2010/10/06 00:00:40 [WARNING]Failed to ping remote VPN Router!2010/10/06 00:00:43 [WARNING]Failed to ping remote VPN Router!2010/10/06 00:00:46 [WARNING]Failed to ping remote VPN Router!2010/10/06 00:00:49 [WARNING]Ping was blocked, which can be caused by an unexpected disconnect.2010/10/06 00:02:13 [STATUS]Disconnecting...
Router is a version 1.1 running with sw version V1.1.13-ETSI Quick VPN is sw version Ver 1.4.1.2
The issue is that I can't connect due to that i cant ping the internal IP, get this error message in the QVPN log [WARNING]Failed to ping remote VPN Router![URL]I have disable the "Block WAN Request" and it is possible to ping the router on the external site.So as I see it, the router blocks for ping on the internal IP via QVPN, what have I done wrong?
I've got two RV082's connected. Each has a dynamic IP (changes typically every few weeks). I've configured the tunnels on both ends with a local and remote "Remote/Local Security Gateway Type" of "Dynamic IP + Domain Name(FQDN) Authentication".If I look at the VPN Summary tunnel status, it shows an IP address of "mydomain.dyndns.org 0.0.0.0" under the "Remote Gateway" column heading. The Tunnel Test "Connect" button is N/A.I can resolve both of the mydomain.dyndns.org entries on both sides of each VPN using the Diagnostic DNS lookup tool within each router. If I hardwire a fixed IP address for the Local and Remote Gateway everything works just fine. VPN is good.
I just can't seem to get the "mydomain.dyndns.org" function to work. It appears the router can't resolve the dynamic IP from the domain names on each of the routers.
I replace our aging rv082 routers with wireless rv220w routers. The gateway to gateway vpn works great, however I am no longer able to manage our print servers port 80 management page. I can ping any host with success, and I can manage hosts that have a port 10000 or 8000 web interface - but no port 80 ones... I had no issues when using the old rv082 routers...
I picked up a pair of RV220W's and before I spent loads of time at a remote site, I figured I'd go through some VPN testing at home to make sure I could get it setup properly. What this means is I've plugged the Internet uplink into a switch, then from the switch into both routers & configured them (using unique static IP's for each) from there. For what its worth: While I have some IT experience, I don't have strong networking experience.
I setup several VLAN's on the local RV220W, and the end result is to make it so that an asset at the remote site with an IP in any of the ranges (192.168.121.0/24, 192.168.131.0/24, 192.168.141.0/24 and any future VLANs) can communicate with/access resouces at the local site. Likewise, an asset at the local site with an IP in any of the ranges (.121, .131, .141 + any future VLANs) should be able to reach the remote resources (currently just 192.168.181.0/24, but future VLANs as well).
This evening I tried to focus on the relevant VPN pages of the Administration Guide to get the VPN up. Leaving the defaults I got as far as establishing a link between both sites and it seems that things are working right: From the remote site (.181) I can access the local site (.121, .131, .141); and from the local site I can at least ping resources (a laptop) on the remote site. (Yay!)
However, when I physically connected an asset that had a 192.168.121.X, 192.168.131.X and 192.168.141.X IP addresses to the remote RV220W (which is 192.168.181.0/24), I couldn't see it from the remote or local sites.I assume this is expected. But I'm reaching out to the community to see what other possibilities might be available becuase networking is a weak area for me. I figured it might be something like a Static [or Dynamic] Route but I really am not 100% sure.
'TECHNICAL' SPECS
Local Router LAN/WAN Settings: LAN IP: 192.168.121.1 on default VLAN (1) VLAN 13 defined 192.168.131.1 with DHCP enabled; Reservations created outside of DHCP scope VLAN 14 defined 192.168.141.1 with DHCP enabled, Reservations created outside of DHCP scope Inter VLAN Routing enabled for all VLANs
I have two Cisco RV042 Routers, they are being used to connect two offices, i have created a standard gateway to gateway connection, fixed public ip addresses on both sides and everything works fine, except when the tunnel gets disconnected, it does not connect back automatically, i have to log into either router console and click the connect button to get the tunnel working again, this is really annoying since it happens once or twice a day at least.
New hardware here, requesting a bit of your knowledge, We are tryingin to setup a simple gateway to gateway VPN
HomeA Has an RV016 with a public static IP Local Group Security Gateway type is IP Only with the IP Local Security Group Type is Subnet, with the local IP class 192.160.0.0 Remote Security Gateway Type: Dynamic + Email Email address some@emailaddress.com Remote Security Group Type: Subnet IP Address 192.168.1.0 IPSec Setup as default with nice password.
HomeB has an RV082 with a dynamic ADSL link Local Group Security Gateway type is DynamicIP +Email Email address some@emailaddress.com Local Security Group Type is Subnet, with the local IP class 192.160.1.0 Remote Security Gateway Type: IP Only Remote Security Group Type: Subnet IP Address 192.168.0.0 IPSec Setup as default with nice password.
The idea is for HomeB which has a dynamic IP, to reach HomeA, which has a static IP and connect. But they just wont. I have not clue what's wrong, I followed the instructions, maybe i miss interpreted something. I could share the VPN logs for both., Im getting a lot of errors there.
I have a pair of RV082 routers and I'd like to configure gateway to gateway VPN tunnel as described in a cookbook, "How to configure a VPN tunnel that routes all traffic to the Remote Gateway," (file name Small_business_router_tunnel_Branch_to_Main.doc). I followed this cookbook and found that my while the Main office has internet connectivity, the branch subnet doesn't have internet connectivity.
Routing does behave as advertised, where all traffic does go to the main office. However, the 192.168.1.0 subnet in the branch office does not get internet connectivity. I've read in other posts that the Main office router will only provide NAT for the local subnet, not the branch office subnet. Is there a way to configure the RV082 router to provide NAT for all subnets?
If not, which Cisco product will provide the VPN Tunnel connectivity as well as the NAT for all subnets? Can the RV082 be used as part of the final solution or are my RV082s a wasted expenditure?
Following is the configuration that I'd implemented, (real IP and IKE keys are bogus).
Gateway To Gateway Remote Main Office Add a New Tunnel Tunnel No. 1 2 Tunnel Name : n1-2122012_n2-1282012 n1-2122012_n2-1282012 Interface : WAN1 WAN1
I recently swapped out an RV082 with a newer model (still RV082 but black and a different interface). I configured the Gateway to Gateway VPN exactly as it was before but none of the three other RV082's will connect. I have tried deleting the connections several times to no avail. I have aggressive mode disabled and have tried with the firewall on and off. Below are the settings (IP's have been X'd out) and the log.
Settings: IP OnlyIP Address : X0X.X0X.20.31Local Security Group Type : IPSubnetIP RangeIP Address : Subnet Mask : Remote Group Setup Remote Security Gateway Type : IP OnlyIP AddressIP by DNS Resolved : Remote Security Group Type : IPSubnetIP RangeIP Address : Subnet Mask : AES-192AES-256AES-128 AES-192AES-256 AES-128 IPSec Setup3DES Keying Mode : ManualIKE with Preshared keyPhase 1 DH Group : Group 1 - 768 bitGroup 2 - 1024 bitGroup 5 - 1536 bitPhase 1 Encryption : DES Phase 1 Authentication : MD5SHA1Phase 1 SA Life Time : secondsPerfect Forward Secrecy : Phase 2 DH Group : Group 1 - 768 bitGroup 2 - 1024 bitGroup 5 - 1536 bitPhase 2 Encryption : NULLDES3DES Phase 2 Authentication : NULLMD5SHA1Phase 2 SA Life Time : secondsPreshared Key : Minimum Preshared Key Complexity : EnableLOG:
My two RV042 , one at home and the other one at my working site, constantly lost VPN connection after successfully connected.Both Firmware are identical. [code]
we do have 2 Rv042, one in my office and one in my house.. in the office we do have static ip and at home none.. question is can i connect the two RV042?
We have a VPN setup between two Cisco RV082 routers, the VPN status shows as connected however I can't ping the other network. I am unable to ping between routers, let alone ping computers behind those routers.
We have 2 branches, branch 1 is on a static IP and branch 2 is Dynamic. I am able to connect via QuickVPN from Branch 2 to Branch 1 and remote desktop to computers, however have yet to VPN/remote desktop in the opposite direction.
To me it seems like a firewall issue at branch 2, but what's causing this. Also they are currently running 2 differnet firmware version not sure if this would cause a problem.
I am trying to set up a gateway to gateway VPN connection between a RV042G (central site) and a RV110W (newest firmware) which is used for presentation purposes on various customer's sites. The RV042G has a static IP. The RV110W has different IPs, depending on where it is used.
Basic VPN settings are clear to me (we have another VPN between two RV042G with static IPs). I set up the VPN connection on the RV042G wth the following settings for "Remote Group Setup":
Remote Security Gateway Type : IP + Domain Name (FQDN) Authentication IP by DNS resolved: mydomain.no-ip.org Domain Name: router12345
The value "router12345" is what I have configured in the RV110W as "Host name" in the network settings.
This configuration does not work so I am obviously doing something wrong. Do I have to use "router12345.mydomain.local" instead if I configured "mydomain.local" as the domain name in the RV110Ws network settings? For my tests the RV110W has a WAN-IP of 192.168.178.100 because it is located behind a DSL-Router. The external IP of this DSL-router is 178.0.x.x. The resolved IP from mydomain.no-ip-org is 192.168.178.100 but when I look in the RV042G log I see the requests coming withg the external IP (178.0.x.x). Is this the problem? The last message I see in the log is "no connection has been authorized with policy=PSK".
Or can I use "IP + Email Address (USER FQDN) Authentication" instead (where can I enter this email address in the RV110W?). Or do I have to use "Dynamic IP"?
I have an RV082 and a RV042. I have been able to successfully establish a gateway to gateway vpn connection between them both, and I can remotely administer each router through the VPN connection, but I am unable to ping computers from one side of the connection to the other. For example, a computer in the 10.10.1.0 subnet can't see / ping / communicate with a computer in the 192.168.1.0 subnet.
Below are the configurations for each. Aside from the static IP configurations and the VPN configurations, no other changes were made to the routers. RV082 DHCP Enabled Tunnel Status: Connected Local Group Setup
IP Only: X.X.X.66Local Security Group Type: SubnetIP Address: 10.10.1.0Subnet Mask: 255.255.255.0Remote Group Setup
Can a router using OSPF propagate that he is a router with default-information originate... at the same time when he got an own gateway of last resort to an IP-adress? If so, how? I can't get it to work.
I try to install a Gateway to Gateway VPN between a RV042G router (LAN1) and a 1721 router (LAN2). The VPN is connected. I can ping the devices from a LAN to the other in the two way.
But otherwise I can't access to the devices of LAN2 from LAN1 like with telnet, HTTP, mstsc, ....
And it is OK to access to the devices of LAN1 from LAN2....
Normally I access to all the resources of LAN2 with the Cisco VPN Client but i try to change it with this router. The firewalls are off on all the computers I look.
I exchanged a RV042 v1.2 (Firmware 1.3.13.02) by a new RV042G v3. (Firmware 4.2.1.02).
My problem is now the following: The old RV042 established the Gateway to gateway VPN connection as soon as an IP- address of the remote location was requested. The new RV042G stays on „Waiting for connection“ all the time and does nothing at all. The connection works by clicking „CONNECT“ or by ticking Keep-Alive in the advanced tunnel settings but NOT automatically as before. Is this a firmware issue or have I to configure something additional?
I've configured a VPN IPSEC on my ASA5510. It Assigned IP/NETMASK/Gateway via a DHCP Server on the LAN.The problem is that when a client is connected to the VPN , it takes the right IP and NETMASK. ( 192.168.1.109 / 255.255.255.0) but the Default Gateway is wrong ( 192.168.1.1). It should be the default Gateway of my LAN router ( 192.168.1.229).
I have a side client who's recently upgraded their internet service from a single T1 to a 100mb fiber line. TW Telecom brought the fiber line into their building and run it through a Cisco 3400 which hands it off to TW Telecom's Adtran 4430. If I take my laptop and assign it the appropriate IP and subnet and plug straight into the Adtran I get close to full speeds so I can rule out the ISP (I think).
It comes out of the Adtran to a Cisco RVS4000 setup as a gateway and then feeds off to a Cisco SG200-50 and Cisco 248G switches. Anything from the RVS4000 and beyond on the customer side will only receive a quarter of the speeds I get if I plug straight to the Adtran. I talked to the tech from TW Telecom and they have confirmed the Adtran is hard coded for 1GB Full Duplex speeds so I'm going to assume the RVS4000 needs to match that. I'm not 100% sure on how to make sure the RVS4000 is set to that. In the Admin GUI for the RVS I've gone under the L2 Switch Port Settings and set them to match the Adtran but it makes no difference.
I'm getting some sort of port duplex conflict and need to figure out where to make adjustments.
I gave setup a vpn gateway between two cisco RV120W. The connection is established.
Active IPsec Security Association Table: Policy NameEndpointPacketsKBytesStateActionRxTxRxTxVPN-INTERDIO87.65.38.62000.000.00IPsec SA Established Poll Interval: (Seconds)
The problem is that there is no trafic. Even ping te remote internal nework is not working. For testing i have disabeld at both sites te firewall and have configured both with an access rule any to any.
So i am trying to Set up a wireless repeater so i can have a better signal in my back yard but i could not set the configurations for my repeater because the gateway (ip address? Not really sure what it is called) would not work when i entered it into the browser. So i went into command prompt to make sure i had the right gateway and it did not even exist.
I am trying to setup the following. We have an RV042 Router and are using it as our gateway at the office. In the office we are using a Windows Domain abc.lan with DHCP of 10.0.0 - 10.0.0.254. The Router/Gateway is setup with a Static IP of 10.0.0.100.A couple of our office employees would like to work from home via VPN using their laptops. With the many options available for this router, I am not clear as to which options and what settings I should set.
I've just installed a standard Cisco wireless install (5508, 3502i, local and flexconnect setups) all working swimmingly.
The customer has asked for a new WLAN for a particular group of staff that will route to a different gateway than the general wireless staff.
The 5508 is connected to a older Avaya L3 switch that is the customers core swtich, but it isn't capable of PBR so it routes on desitnation only and its default route is not where I need the new WLAN traffic to route to. An ASA will be connected to the Avaya switch (which is the alternate gateway I need to get the new WLAN users to). So my question is probably routing 101, but if the ASA interface, the Avaya swtich and the WLAN interface all reside in the same VLAN, can I give the wireless clients the ASA as their gateway via DHCP and successfully get their traffic to the ASA?
I have a Linksys WAG200G wireless ADSL router. So it has one ADSL(phone) line input port , 4 Ethernet ports and wireless router. My router is fine and works well on ADSL connections. But as I have switched to Comcast DOCSIS modem based internet connection now, I want to to setup this router as "Home Gateway" only and not the modem. My intention is to use- use 1 of the 4 ethernet ports at the back of router as an INPUT . I want to put the ethernet output of the DOCSIS modem into this INPUT- and then i want to use the remaining 3 Ethernet ports as OUTPUT ports from the router.- I also want to work my router as Wireless router.
My query is- Is this possible ? Basically use 1 port as an input and 3 as output.- I have tried different things - Using Bridge mode only. DHCP disabled but sometimes only wireless works and other times only LAN bridge setup works but both do not work together.- Also at times, one Ethernet port will work as an INPUT and 1 as an OUTPUT but other two remain disabled.
We can not find the gateway on our Dell Latitude D810 we were able to locate the IP address and Subnet Mask however the Gateway info does not come up we have tried various times to connect to a hotspot no problem with our Dell Latitude D620 and the Function Key plus the F4 key does not bring up the wireless prompt.
Issue with my Gateway to Gateway VPN connection. I have outlined the settings for both sites and I feel I should mention that this was an established connection that was working until I came in this morning. Nothing has changed (as far as I know) but for some reason I am not able to reconnect. Can you see any reason why this would be? Of course I've changed the WAN IPs and Shared Key for security purposes.
WRVS4400N Version V2.0.0.7.I have been attempting for weeks to connect an IPSEC tunnel between a Cisco ASA 5510 Version 8.0(2) and a WRVS4400N . Phase one seems connect okay, where as phase two always give me the errors below. This as far as I have got, I tried disabling keep alive monitor, the device never attempted phase 2. I have read endless documentation on both devices and tried almost every combination of setting that I am aware of. The best case scenario answer would be detailed steps on how to setup the IPSEC VPN (linksys) & the site to site VPN (CISCO) as I cannot find any reference material for this combination .