This article describes a detailed configuration example that demonstrates how to set up a net-to-net IPSec VPN connection between Cyberoam and Vigor Draytek ADSL using preshared key to authenticate VPN peers.
Throughout the article we will use the network parameters as shown in the diagram below.
Configuration Parameters
Site1 (Gateway-A)
Site2 (Gateway-B)
IPSec Connection
Local Network details
Local Network details
Cyberoam WAN IP address – 14.15.16.17
Draytek WAN IP address – 22.23.24.25
Local Internal Network – 10.5.6.0/24
Local Internal Network – 172.23.0.24
Preshared Key - 0123456789
Preshared Key - 0123456789
Remote Network details
Remote Network details
Remote VPN server – IP address 22.23.24.25
Remote VPN server – IP address 14.15.16.17
Remote Internal Network – 172.23.9.0/24
Remote Internal Network – 10.5.6.0/24
Note: If same subnets are configured at Draytek and Cyberoam then connection will not be established
Step by Step Configuration Draytek ADSL
Step 1:
§Go to VPN and Remote Accessà Remote Access Control
§To allow the VPN traffic through routers, enable services as per following screen:
Step 2:
§Go to VPN and Remote AccessàLAN to LAN
§Choose an unused profile, e.g. 1. and click Next to continue.
§The status of unused profile will be “x”
Step 3:
Section 1: Common Settings
Enter a Profile Name and enable the profile
As Draytek router will always initiate the VPN connection, for Call Direction click “Dial-Out” and click “Always on” to enable always on VPN tunnel.
Section 2: Dial- Out Settings
§Under Type of Server I am calling, click “IPSec Tunnel” and enter WAN IP address of Cyberoam i.e. 14.15.16.17 as Server IP/Host Name
§Under IKE Authentication Method, click “Pre-Shared Key” and enter Pre-Shared Key
§Under IPSec Security Method, click “High (ESP)”
§Click “Advanced” button
In Advanced settings enter parameters as follows:
IKE phase 1 mode: Main mode
IKE phase 1 proposal: 3DES_MD5_G2
IKE phase 2 proposal: 3DES_MD5
IKE phase 1 key lifetime: 28800
IKE phase 2 key lifetime: 3600
Perfect Forward Secret: Disable
Section 3: Dial- in Settings:
No configuration is required in this section
Section 4: TCP/ IP Network Settings
Enter following parameters
Remote Network IP – 10.5.6.0 (Cyberoam’s internal network IP)
Remote Network Mask - 255.255.255.0
Do not change the default setting of any other parameters.
Click “OK” button
Step by Step Configuration Cyberoam
Step 4: Create VPN Policy
Go to VPNàPolicyà Create Policy and create VPN Policy with following values: