VPN connection between Vigor Router and Vigor3900 - IKEv2

Support Model : Vigor3900Vigor2960Vigor2862 SeriesVigor2860 Series
  • Tags :

Modified from the previous version IKEv1, IKEv2 is a new VPN protocol and has lots of improvements than the former. It is more stable, more secure and faster connection establishing speed. It supports newer and more complicated secure ciphers to make the connection more secure. Using new connection progress and discarding the PPP, IKEv2 provides the faster establishing speed.

Vigor Router starts to support IKEv2 VPN tunnel since firmware version 3.8.5 or 1.3.0 for Vigor3900/2960. This article demonstrates LAN to LAN IKEv2 VPN between Vigor router and Vigor3900/2960 by the following topology. Vigor Router and Vigor3900/2960 can both be the VPN server and client, therefore, we separate this article into two parts, to demonstrate how to establish the IKEv2 VPN connection between Vigor Router and Vigor3900/2960, when using one of them as VPN server respectively.

   

Before the VPN configuration, please make sure the IPSec service is enabled in VPN and Remote Access >> Remote Access Control page on the router takes up the role as the VPN server.

       

 

 

Part A: Take Vigor Router as VPN server

Vigor Router Setting (Dial-in)

1. Go to VPN and Remote Access Control >> IPsec General Setup,

  1. Enter Pre-Shared Key
  2. Click OK
   

Go to VPN and Remote Access Control >> LAN to LAN and click an available index,

2. Common Settings

  1. Give a Profile Name
  2. Enable this profile
  3. Select Dial-in as Call Direction
   

3. Dial-In Settings

Allow IPsec dial-in

   

4. TCP/IP Network Settings

  1. Enter Vigor3900's LAN in Remote Network IP/Mask
  2. Click OK
   

Vigor3900 Setting (Dial-out)

5. Go to VPN and Remote Access >> VPN Profiles, and click Add in IPsec tab,

  1. Give Profile name and Enable the profile
  2. Select the WAN interface used to dial out
  3. Enter Vigor3900's LAN in Local IP/Subnet Mask
  4. Enter Vigor router's WAN IP or domain in Server IP/Host Name
  5. Enter Vigor Router's LAN in Remote IP/Subnet Mask
  6. Select IKEv2 as IKE Protocol
  7. Enter Preshared Key
  8. Click Apply
   

Now we can go to VPN and Remote Access >> Connection Management to dial the VPN.

   

After VPN is connected successfully, we can see the connection status below.

   

 

 

Part B: Vigor3900 as VPN server

Vigor3900 Setting (Dial-in)

1. Go to VPN and Remote Access >> IPsec General Setup,

  1. Enter Preshared key
  2. Click Apply
   

2. Go to VPN and Remote Access >> VPN Profiles, and click Add in IPsec tab,

  1. Give Profile name and Enable the profile
  2. Enter Vigor3900's LAN in Local IP/Subnet Mask
  3. Enter Vigor Router's LAN in Remote IP/Subnet Mask
  4. Select IKEv2 as IKE Protocol
  5. Click Apply
   

Vigor Router Setting (Dial-out)

Go to VPN and Remote Access Control >> LAN to LAN and click an available index,

3. Common Settings

  1. Give a Profile Name
  2. Enable this profile
  3. Select Dial-out as Call Direction

4. Dial-Out Settings

  1. Select IPsec and IKEv2 as dial-out type
  2. Enter Vigor3900's WAN IP or domain in Server IP/Host Name
  3. Enter Pre-Shared Key
  4.  Select ESP(High), AES with Authentication as IPSec Security Method
   

 5. TCP/IP Network Settings

  1. Enter Vigor3900's LAN in Remote Network IP/Mask
  2. Click OK
   

Now we can go to VPN and Remote Access >> Connection Management to dial the VPN.

   

After VPN is connected successfully, we can see the connection status below.

   

 

 

See also:

Was this article helpful ?
65VPN connection between Vigor Router and Vigor3900 - IKEv2 has been viewed------ 65 ------times.