IPsec Tunnel Aggresive Mode between DrayTek Routers

IPsec VPN in Main mode use the IP address as peer identity (ID) for Peer authentication; therefore, it's not a solution if both the VPN peers don't have static IP addresses. In such cases, can establish the IPsec VPN in Aggressive mode instead. This document introduces how to set up IPsec Tunnel in Aggressive mode between two Vigor Routers.

VPN Server Setup

1. Create a VPN LAN to LAN profile for the peer VPN client router via VPN and Remote Access >> LAN to LAN, click on an available index to add a new profile.

2. Edit the profile as follows:

  1. Check Enable this profile
  2. Select Dial-In for Call Direction
  3. Select the WAN interface that the VPN client will dial In from
  4. Change Idle Timeout to 0 second
  5. Allow IPsec Tunnel in Dial-In Settings
  6. Check Specify Remote VPN Gateway and enter the Peer ID
  7. Check IKE Pre-Shared Key and enter the Pre-shared Key
  8. Select the IPsec Security Methods that are allowed to use.
  9. At TCP/IP Network Settings, input the IP subnet used by the VPN Client for Remote Network IP and Mask
  10. Click OK to save the VPN profile.

VPN Client Setup

1. Similarly, create a profile at VPN and Remote Access >> LAN to LAN

  1. Give a Profile Name
  2. Check Enable this profile
  3. Select Dial-Out for Call Direction
  4. Select the WAN interface that the VPN client will dial out from
  5. Check Always On
  6. Select IPsec Tunnel in Dial-Out Settings
  7. Input VPN server's WAN IP or domain name at Server IP/Host Name for VPN
  8. Choose Aggressive mode
  9. Input IKE Pre-Shard Key as the same as what was configured on VPN Server
  10. Enter Local ID as same as Peer ID set on server
  11. Set phase 1’s Encryption and Authentication you want to use
  12. Set phase 2’s Security Protocol, Encryption, and Authentication you want to use
  13. Set phase 1’s and phase 2’s Key Lifetime in IKE Advanced Settings(optional)

In TCP/IP Network Settings, enter VPN Server's LAN Network in Remote Network IP and Remote Network Mask. Click OK to save the profile

After finishing the above configurations, VPN Client shall dial up the IPsec tunnel automatically. We can check the VPN status via VPN and Remote Access >> Connection Management page.

VPN Client (Dial-Out) Setup

1. Go to VPN and Remote Access >> VPN Profile >> IPsec click Add to add a new profile:

  1. In the Basic tab, enter the Profile name
  2. Check Enable
  3. Select "Enable" for Auto Dial-Out and select "Always Dial-Out"
  4. Enter Local IP / Subnet Mask as the LAN network on this router which you want to link to the remote network
  5. Enter VPN Peer's WAN IP in Remote Host
  6. Enter Remote IP/ Subnet Mask as the LAN IP of VPN peer
  7. Select Aggressive Mode
  8. Enter Local ID
  9. Enter Remote ID
  10. Enter Pre-Shared Key  (It must match the Pre-Shared Key on the VPN Peer)
  11. Click Apply to save the profile
a screenshot of Vigor3900 VPN
VPN Server (Dial-In) Setup

2. Similarly, on the VPN Peer, go to VPN and Remote Access >> VPN Profile >> IPsec to add a new profile:

  1. In the Basic tab, enter the Profile name
  2. Check Enable
  3. Leave Auto Dial-Out and For Remote Dial-In User as "Disable"
  4. Enter Local IP /Subnet Mask as the LAN network on this router
  5. Enter VPN Peer's WAN IP in Remote Host
  6. Enter Remote IP/ Subnet Mask as the LAN IP of VPN Peer
  7. Select Aggressive Mode
  8. Enter Local ID (It should be the Remote ID on the VPN Peer)
  9. Enter Remote ID (It should be the Local ID on the VPN Peer)
  10. Enter Pre-Shared Key as the same as the one in VPN Peer
  11. Click Apply to save the profile
a screenshot of Vigor3900 VPN
Establishing the VPN

If all the settings match, the VPN connection will create automatically. In connection status, we will see the IPsec tunnel is up.

a screenshot of Vigor3900 VPN

Published On: 2016-05-18 

Was this helpful?