Articles Articles Most Popular Articles Most Popular Articles Most Helpful Articles Most Helpful Articles
DrillDown Icon Table of Contents Back
 . . . . . . . . . . . . .
DrillDown Icon Product Literature
DrillDown Icon Best Practices & Policies
DrillDown Icon Protect Your Cyberoam Appliances from Power Fluctuations
DrillDown Icon Version 10.x
DrillDown Icon Version 9.x
DrillDown Icon How To
DrillDown Icon Anti Spam
DrillDown Icon Anti Virus
DrillDown Icon Authentication
DrillDown Icon Blocking
DrillDown Icon Clients
DrillDown Icon Content filtering
DrillDown Icon Firewall
DrillDown Icon IPS
DrillDown Icon Logs & Reports
DrillDown Icon SNMP
DrillDown Icon System
DrillDown Icon Registration
DrillDown Icon User
DrillDown Icon VPN
DrillDown Icon Configure SSL VPN in Cyberoam
DrillDown Icon Configure MS Windows Vista Client for PPTP connection
DrillDown Icon VPN Interoperability
DrillDown Icon Establish IPSec VPN using Vigor Draytek ADSL
DrillDown Icon Establish Net-to-Net IPSec VPN Connection between Cyberoam and Cisco Router using Preshared key
DrillDown Icon Establish VPN Tunnel between Cyberoam and Fortinet using Preshared key
DrillDown Icon Establish VPN Tunnel between Cyberoam and Checkpoint using Preshared key
DrillDown Icon Cyberoam to D Link (DI 808HV) IPSec VPN using preshared key
DrillDown Icon Cyberoam to Firebox (WatchGuard) IPSec VPN using Preshared key
DrillDown Icon Cyberoam to Sonicwall IPSec VPN using Preshared key
DrillDown Icon Cyberoam to Cisco PIX IPSec VPN using Preshared key
DrillDown Icon Cyberoam to Sonicwall IPSec VPN using Certificate
DrillDown Icon VPN Failover
DrillDown Icon Check VPN connection routes
DrillDown Icon Configure L2TP
DrillDown Icon Cyberoam to Cyberoam (Net-to-Net) IPSec VPN using Preshared key
DrillDown Icon Cyberoam to Cyberoam (Net-to-Net) IPSec VPN using Certificate
DrillDown Icon Cyberoam to Cyberoam (Net-to-Net) IPSec VPN when peers have Dynamic IP address
DrillDown Icon Cyberoam VPN Client to Cyberoam IPSec VPN for the remote access using preshared key
DrillDown Icon Cyberoam VPN Client to Cyberoam IPSec VPN for remote access using Digital Certificates
DrillDown Icon Configure MS Windows XP VPN Client for L2TP connection
DrillDown Icon Configure Cyberoam as a PPTP server
DrillDown Icon Configure Cyberoam to establish PPTP connection using MS Windows XP VPN Client
DrillDown Icon Configure MS Windows 2000 Client for PPTP connection
DrillDown Icon Create Hub and Spoke IPSec VPN Network
DrillDown Icon Intimation Regarding US New Daylight Saving Time Support
DrillDown Icon Verify the integrity check of Cyberoam Upgrade file using MD5 checksum
DrillDown Icon Troubleshooting
DrillDown Icon FAQ
DrillDown Icon Tech Notes
DrillDown Icon Visio Stencils
DrillDown Icon Glossary
DrillDown Icon Product Technical Support
DrillDown Icon Compatibility
  Email This ArticlePrintPrint Current Article and All Sub-Articles
Rate Icon Rate Icon Rate Icon Rate Icon Rate Icon
 
Establish VPN tunnel between Cyberoam and D Link (DI 808HV) using preshared key


Applicable to Version: 9.4.0 build 2 onwards

 

This article describes a detailed configuration example that demonstrates how to configure net-to-net IPSec VPN tunnel between a Cyberoam and D-Link (DI-808HV) Broadband VPN Router.

 

It is assumed that the reader has a working knowledge of Cyberoam and D-Link configuration.

 

Throughout the article we will use the following network parameters:

Configuration Parameters

Cyberoam

D-Link

Preshared Key

Cyberoam_Dlink_key

Cyberoam_Dlink_key

IPSec Connection

(Net-to-Net)

Local Network details

Local Network details

Cyberoam WAN IP address – 202.134.168.202

DLink WAN IP address – 202.134.168.208

Local Internal Network – 192.168.21.0/24

Local Internal Network – 192.168.22.0/24

Local ID – john@elitecore.com

Local ID – dean@elitecore.com

 

 

 

 

Remote Network details

Remote Network details

Remote VPN server – IP address – 202.134.168.208

Remote VPN server – IP address – 202.134.168.202

Remote Internal Network – 192.168.22.0/24

Remote Internal Network – 192.168.21.0/24

Remote ID – dean@elitecore.com

Remote ID – john@elitecore.com

 

Cyberoam Configuration

Step 1: Create VPN Policy

Go to VPN ® Policy ® Create Policy and create policy with the following values:

 

Policy Name: dlink_policy

Using Template: None

Keying Method: Automatic

Allow Re-keying: Yes

Pass Data In Compressed Format: Yes

Perfect Forward Secrecy (PFS): Yes

Action When Peer Is Not Active: Hold

 

Phase 1

Encryption Algorithm – 3DES

Authentication algorithm – SHA1

 

Other parameters as per your requirement

 

Phase 2

Encryption Algorithm – 3DES

Authentication algorithm – MD5

 

Other parameters as per your requirement

 

Step 2: Create IPSec connection

Go to VPN ® IPSec Connection ® Create Connection and create connection with the following values:

 

Connection name: CR_DL

Policy: dlink_policy

Action on restart: As required

Mode: Tunnel

Connection Type: Net to Net

 

Authentication Type – Preshared key

Preshared key – Specify Preshared key. Forward this key to the remote peer (D-Link) as same preshared key should be used by both the peers.

 

Local server IP address (WAN IP address) – 202.134.168.202

Local Internal Network – 192.168.21.0/24

 

Remote server IP address (WAN IP address) – 202.134.168.208

Remote Internal Network – 192.168.22.0/24

 

User Authentication Mode: As required

Protocol: As required

 

Step 3. Activate Connection and establish Tunnel

Go to VPN ® IPSec Connection ® Manage Connection

To activate the connection, click  under Connection Status against the CR_DL connection

 

  under Connection Status indicates that the connection is successfully activated

 

 

Note

At a time only one connection can be active if both the types of connection - Digital Certificate and Preshared Key - are created with the same source and destination. In such situation, at the time of activation, you will receive error ‘unable to activate connection’ hence you need to deactivate all other connections.


D-Link Configuration

Step 4. Add VPN settings

Go to VPN ® Home and configure with the following values:

VPN: Enable

Max. number of tunnels: 1

 

Tunnel Name: DL_CR

Method: IKE

Click More button to define Connection settings.

 
 

Step 5. Define Local and Remote Network

 

Tunnel Name: DL_CR (as defined in the previous step)

Local Subnet: 192.168.22.0

Local Netmask: 255.255.255.0

Remote Subnet: 192.168.21.0

Remote Netmask: 255.255.255.0

Remote Gateway: 202.134.168.202

Preshared Key: Same as defined in Cyberoam configuration in step 1


Click
 
 
 
 

Step 6. Define Phase 1 parameters

Click Select IKE Proposal to defined Phase 1 parameters and input following values:

 

Proposal Name: 3des_sha1

DH Group: 1

Encryption algorithm: 3DES

Authentication algorithm: sha1

Life Time: 3600

Life Time Unit: Sec.

Click

 
 

Step 7. Define Phase 2 parameters

Click Select IPSec Proposal to defined Phase 2 parameters and input following values:

Proposal Name: 3des_md5_360

DH Group: Group 2

Encap protocol: ESP

Encryption algorithm: 3DES

Auth algorithm: MD5

Life Time: 3600

Life Time Unit: Sec

Click

 
 

Step 8. View VPN connection status

Go to VPN ® Status to check the connection status.

 

Reference Documents

·     VPN Troubleshooting Guide

 

 

 

Document Version: 9402-1.0-05/04/2007

Article ID: 402