Ask
Reply
Solution
31-10-2009 06:55 PM
01-11-2009 08:11 PM
02-11-2009 04:44 PM
03-11-2009 05:41 PM
I need to set up a VPN from a Draytek 2820 router using only a Vodafone L3565 USB (on monthly contract) to another Draytek 2820 Router using ADSL.
My problem is the way NAT is implemented over the Vodafone network prevents me from connecting the two - using a dynamic dns does not help.
Does anybody know of a way this can be achieved at router level?
What I am trying to achive is the connection of remote cameras at temporary sites to a central point.
...
04-11-2009 01:27 PM
04-11-2009 04:13 PM
The ADSL part of the router-to-router VPN link isn't the problem
it is the Vodafone network (and the NAT devices on it) which must be preventing the traffic flowing over the VPN. There is no publicly accessible IP address given to the device which is connecting to the Vodafone APN which means that the traffic can't get back to the spoke from the hub.
I found a topic regarding public IP's on 3G data card providers below. Luckily I have a Three data connection which I am going to test in the coming weeks. I'll hopefully find out if my connection receives a public IP address this week, if so, I can't see any reason why the VPN won't work.
http://forum.vodafone.co.uk/index.php?showtopic=1800
I thought that a NAT-T device like the Vigor 2820 would get around the problem of the non-public IP which Vodafone give to the 3G connection, but from the original post it appears this is not so. I am waiting for my Vigor 2820 to arrive to test.
Lastly, SSL vpn is not possible for a router-to-router vpn. It's ok if you have a PC with a VPN client installed, but I haven't come across any routers which can use SSL VPN's to each other.
04-11-2009 04:21 PM
04-11-2009 06:40 PM
So what is your exact setup that allows this to work on the Vodafone network, if you don't mind me asking?
05-11-2009 08:54 AM
05-11-2009 06:03 PM
Right ok, so you are not using the router-to-router vpn setup like the topic of this thread addresses.
The original post describes a scenario where the remote site only has a CCTV camera attached to a router so no PC/Linux involved.
With regards to your link to the other post, doesn't using IPSEC in aggresive mode get around the changing IP address issue?
For the record, I checked my Three connection yesterday and using the APN '3internet' I get a publicly accessing IP address, so this will work for connecting a VPN. Shame Vodafone don't offer a similar service, ie one APN for private address and one for public address but until I get a NAT-T router to test with, it is possible to establish a VPN router-to-router but traffic won't flow.