VPN connection between Vigor Router and Vigor3900 - IKEv2

Support Model : Vigor3900Vigor2960Vigor2862 SeriesVigor2860 Series

Modified from the previous version IKEv1, IKEv2 is a new VPN protocol and has lots of improvements than the former. It is more stable, more secure and faster connection establishing speed. It supports newer and more complicated secure ciphers to make the connection more secure. Using new connection progress and discarding the PPP, IKEv2 provides the faster establishing speed.

Vigor Router starts to support IKEv2 VPN tunnel since firmware version 3.8.5 or 1.3.0 for Vigor3900/2960. This article demonstrates LAN to LAN IKEv2 VPN between Vigor router and Vigor3900/2960 by the following topology. Vigor Router and Vigor3900/2960 can both be the VPN server and client, therefore, we separate this article into two parts, to demonstrate how to establish the IKEv2 VPN connection between Vigor Router and Vigor3900/2960, when using one of them as VPN server respectively.

   

Before the VPN configuration, please make sure the IPSec service is enabled in VPN and Remote Access >> Remote Access Control page on the router takes up the role as the VPN server.

Enable IPsec VPN Service on Vigor3900     Enable IPsec VPN Service on Vigor Router    

 

 

Part A: Take Vigor Router as VPN server

Vigor Router Setting (Dial-in)

1. Go to VPN and Remote Access Control >> IPsec General Setup,

  1. Enter Pre-Shared Key
  2. Click OK
Enter Pre-Shared Key on IPsec General Setup page    

Go to VPN and Remote Access Control >> LAN to LAN and click an available index,

2. Common Settings

  1. Give a Profile Name
  2. Enable this profile
  3. Select Dial-in as Call Direction
Common Settings of LAN to LAN VPN.PNG    

3. Dial-In Settings

Allow IPsec dial-in

VPN Dial-In Settings for IPsec VPN    

4. TCP/IP Network Settings

  1. Enter Vigor3900's LAN in Remote Network IP/Mask
  2. Click OK
TCP IP Network Settings.PNG    

Vigor3900 Setting (Dial-out)

5. Go to VPN and Remote Access >> VPN Profiles, and click Add in IPsec tab,

  1. Give Profile name and Enable the profile
  2. Select the WAN interface used to dial out
  3. Enter Vigor3900's LAN in Local IP/Subnet Mask
  4. Enter Vigor router's WAN IP or domain in Server IP/Host Name
  5. Enter Vigor Router's LAN in Remote IP/Subnet Mask
  6. Select IKEv2 as IKE Protocol
  7. Enter Preshared Key
  8. Click Apply
23-IKEv2 VPN Profile on Vigor3900.PNG    

Now we can go to VPN and Remote Access >> Connection Management to dial the VPN.

Initiating IKEv2 VPN from Connection Management Page    

After VPN is connected successfully, we can see the connection status below.

IKEv2 VPN established successfully    

 

 

Part B: Vigor3900 as VPN server

Vigor3900 Setting (Dial-in)

1. Go to VPN and Remote Access >> IPsec General Setup,

  1. Enter Preshared key
  2. Click Apply
IKEv2 VPN Dial-In Setup on Vigor3900    

2. Go to VPN and Remote Access >> VPN Profiles, and click Add in IPsec tab,

  1. Give Profile name and Enable the profile
  2. Enter Vigor3900's LAN in Local IP/Subnet Mask
  3. Enter Vigor Router's LAN in Remote IP/Subnet Mask
  4. Select IKEv2 as IKE Protocol
  5. Click Apply
Set up Vigor3900 as IKEv2 VPN Server    

Vigor Router Setting (Dial-out)

Go to VPN and Remote Access Control >> LAN to LAN and click an available index,

3. Common Settings

  1. Give a Profile Name
  2. Enable this profile
  3. Select Dial-out as Call Direction

4. Dial-Out Settings

  1. Select IPsec and IKEv2 as dial-out type
  2. Enter Vigor3900's WAN IP or domain in Server IP/Host Name
  3. Enter Pre-Shared Key
  4.  Select ESP(High), AES with Authentication as IPSec Security Method
Set up Vigor Router as IKEv2 VPN Client    

 5. TCP/IP Network Settings

  1. Enter Vigor3900's LAN in Remote Network IP/Mask
  2. Click OK
TCP IP Network Settings on Vigor Router    

Now we can go to VPN and Remote Access >> Connection Management to dial the VPN.

Initiating IKEv2 VPN from Vigor Router    

After VPN is connected successfully, we can see the connection status below.

IKEv2 VPN established successfully    

 

 

See also:

Was this article helpful?