Networking Forums

Networking Forums > Computer Networking > Broadband > adsl vpn ipsec passthru

Reply
Thread Tools Display Modes

adsl vpn ipsec passthru

 
 
Mark Anyon
Guest
Posts: n/a

 
      11-27-2003, 10:30 AM
Hi, I have three sites connected to internet via pppoA adsl.
I am using draytek 2600 vigor routers, but behind each of those is a
watchguard soho 6tc which i need to connect all three via vpn.
The external interface on the watchguard does not have a pppoA client
much to my disapointment!
I need to configure the draytek to pass thru ipsec traffic to the
watchguard.
I have followed the instructions on draytek support site:

http://www.draytek.com.tw/applicatio..._1_b_ipsec.php


But still no luck.
Watchguard have remoted into my sohos and said the vpn config is fine
but i should be using a public ip on the external interface.

Any help greatly appreciated!!
 
Reply With Quote
 
 
 
 
Graham
Guest
Posts: n/a

 
      11-28-2003, 05:52 AM
On Thu, 27 Nov 2003 03:30:33 -0800, Mark Anyon wrote:

> Hi, I have three sites connected to internet via pppoA adsl. I am using
> draytek 2600 vigor routers, but behind each of those is a watchguard soho
> 6tc which i need to connect all three via vpn. The external interface on
> the watchguard does not have a pppoA client much to my disapointment!
> I need to configure the draytek to pass thru ipsec traffic to the
> watchguard.
> I have followed the instructions on draytek support site:
>
> http://www.draytek.com.tw/applicatio..._1_b_ipsec.php
>
>
> But still no luck.
> Watchguard have remoted into my sohos and said the vpn config is fine but
> i should be using a public ip on the external interface.
>
> Any help greatly appreciated!!



What is actually happening is watchguard is on an internal network with an
internal ip address. It forwards this address to the distant watchguard
which tries to reply to it and gets nowhere.

There are a couple of possible solutions to this:

1. Get your ISP to allocate a block of ip addresses so the watchguard can
be allocated a 'real' ip address.

2. The watchguard broadcasts its internal address in an unencrypted UDP
packet (according to their own site). This would allow an intelligent
router to change this address to it's own external address as it passes
through it Can the Draytek 2600 do this?

A third option could be (although the watchguard site does not mention it)
is can the watchguard transmit your external address instead of it's own
internal address?

Hope this helps.

graham

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Ipsec tunnel mode vs ip in ip with ipsec transport Reji Linux Networking 1 09-20-2011 04:29 PM
IPSec is very slow over ADSL connection George Valkov Windows Networking 13 08-09-2009 03:30 PM
IPv6 + IPsec + ipsec-tools 0.6.[4567] + scope:link = no SA established phil-news-nospam@ipal.net Linux Networking 0 07-25-2007 09:01 PM
Draytek router and VPN passthru for Windows Server 2003 Karl Rhodes Windows Networking 0 10-25-2006 10:52 PM
Virgin.net ADSL and IPSEC VPN Clients banzai Broadband 3 11-23-2005 07:50 PM



1 2 3 4 5 6 7 8 9 10 11