Quantcast
Channel: EdgeRouter topics
Viewing all articles
Browse latest Browse all 20028

Site-to-site VPN

$
0
0

Hello,

 

I'm trying to setup a site-to-site VPN and a L2TP server between 2 EdgeRouter.

I have already set-up a L2TP server and it's working perfectly, however my site-to-site VPN isn't working.

 

Configuration on R1

 auto-firewall-nat-exclude enable
 esp-group FOO0 {
     proposal 1 {
         encryption aes128
         hash sha1
     }
 }
 ike-group FOO0 {
     proposal 1 {
         dh-group 14
         encryption aes128
         hash sha1
     }
 }
 ipsec-interfaces {
     interface eth0
 }
 nat-networks {
     allowed-network 0.0.0.0/0 {
     }
 }
 nat-traversal enable
 site-to-site {
     peer 0.0.0.0 {
         authentication {
             mode pre-shared-secret
             pre-shared-secret XXXXXXXXXXX
         }
         connection-type respond
         description "VPN IPsec "
         ike-group FOO0
         local-address X.X.X.X
         tunnel 1 {
             esp-group FOO0
             local {
                 prefix 192.168.226.0/22
             }
             remote {
                 prefix 192.168.1.0/24
             }
         }
     }
 }
[edit]
admin@recherche# show vpn l2tp remote-access
 authentication {
     local-users {
         username test1 {
             password XXXXXXXX
         }
         username test2 {
             password XXXXXXXX
         }
     }
     mode local
 }
 client-ip-pool {
     start 192.168.226.0
     stop 192.168.226.9
 }
 dns-servers {
     server-1 8.8.8.8
     server-2 8.8.4.4
 }
 ipsec-settings {
     authentication {
         mode pre-shared-secret
         pre-shared-secret XXXXXXXX
     }
 }
 mtu 1492
 outside-address X.X.X.X

 

Configuration on R2 :

auto-firewall-nat-exclude enable
 esp-group FOO0 {
     proposal 1 {
         encryption aes128
         hash sha1
     }
 }
 ike-group FOO0 {
     proposal 1 {
         dh-group 14
         encryption aes128
         hash sha1
     }
 }
 ipsec-interfaces {
     interface eth1
 }
 nat-networks {
     allowed-network 0.0.0.0/0 {
     }
 }
 nat-traversal enable
 site-to-site {
     peer X.X.X.X {
         authentication {
             mode pre-shared-secret
             pre-shared-secret XXXXXXXXXXXX
         }
         connection-type initiate
         description "VPN"
         ike-group FOO0
         local-address any
         tunnel 1 {
             esp-group FOO0
             local {
                 prefix 192.168.1.0/24
             }
             remote {
                 prefix 192.168.226.0/22
             }
         }
     }
 }

I don't know what is wrong. When I check the logs, I have the following lines :

 

Jan 1 07:09:10 00[DMN] Starting IKE charon daemon (strongSwan 5.2.2, Linux 3.10.20-UBNT, mips64)
Jan 1 07:09:11 07[IKE] <peer-X.X.X.X-tunnel-1|1> initiating Main Mode IKE_SA peer-X.X.X.X-tunnel-1[1] to X.X.X.X

When i type show vpn ipsec status :

VPN.PNG

 

Looks like IPsec is running but IKE exchange is not working... Anyone has the same issue ?

 

Thanks,

 


Viewing all articles
Browse latest Browse all 20028

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>