Page 1
OvisLink 8000VPN VPN Guide WL/IP-8000VPN Version 0.6...
Page 2
OvisLink 8000VPN VPN Guide Document Revision Version Date Note 11/10/2005 First version with four VPN examples 1. Added example 5: dynamic VPN using TheGreenBow 11/15/2005 VPN client 2. Corrected the illustration using 8000VPN icons 3. Added How To Use This Guide section 11/15/2005 Updated the cover page 11/17/2005...
OvisLink 8000VPN VPN Guide Document Revision....................i ....................- 1 - UIDE .................. - 1 - OCUMENT VPN E ......................- 2 - XAMPLES 1: U 2 LAN T ....... - 4 - XAMPLE SING EC TO ONNECT OGETHER USA Router Setup ................- 5 - Germany Router Setup ..............
Page 4
OvisLink 8000VPN VPN Guide VPN E XAMPLES In this Guide, we will provide setup guide for 5 VPN application examples: Using IPSec protocol to connect 2 remote LAN together using 2 WL/IP-8000 VPN Routers. Using PPTP protocol to connect 1 remote PC with WL/IP-8000 VPN Setting up IPSec protocol to connect a remote mobile PC with WL/IP-8000 VPN...
OvisLink 8000VPN VPN Guide UIDE The traditional VPN needs trained personnel with professional knowledge to set up. This WL/IP-8000 VPN example guide provides a step-by-step easy setup for the VPN configuration. OCUMENT There are many options to set up secure VPN environment. Various combinations may serve for different purposes.
OvisLink 8000VPN VPN Guide 1: U 2 LAN T XAMPLE SING EC TO ONNECT OGETHER Router WAN IP: Router LAN IP: Router LAN IP: Router WAN IP: 192.168.254.1 192.168.2.254 192.168.1.254 192.168.254.2 PC1 IP: PC2 IP: USA Office German Office 192.168.1.138 192.168.2.174 In this example, we will connect the USA office and German office together using IPSec VPN server (WL/IP-8000VPN on both sides).
OvisLink 8000VPN VPN Guide USA Router Setup 1. After login to WL/IP-8000VPN, click on VPN button on top of the page. 2. Check VPN Enable 3. Check NetBIOS Broadcast Enable 4. Enter Max. number of tunnels as 1. 5. In tunnel ID 1, enter the Tunnel Name as German. 6.
Page 9
OvisLink 8000VPN VPN Guide 192.168.254.2. 13.Enter local and remote SPI. The local SPI we set is 12345 and remote SPI 67890. 14.Encryption Protocol is ESP. 15.Encryption Algorithm is 3DES. 16.Encryption Keys are “1234567890123456”, “2222222222222222”, and “3333333333333333” (16 Arabic numerals per key). 17.Set the key Life Time to 3000 and the Life Time Unit to Second.
OvisLink 8000VPN VPN Guide Germany Router Setup 1. After login to WL/IP-8000VPN, click on VPN button on top of the page. 2. Check VPN Enable 3. Check NetBIOS Broadcast Enable 4. Enter Max. number of tunnels as 1. 5. In tunnel ID 1, enter the Tunnel Name as USA. 6.
Page 11
OvisLink 8000VPN VPN Guide 192.168.254.1. 13.Enter local and remote SPI. The local SPI we set is 67890 and remote SPI 12345. 14.Encryption Protocol is ESP. 15.Encryption Algorithm is 3DES. 16.Encryption Keys are “1234567890123456”, “2222222222222222”, and “3333333333333333” (16 Arabic numerals per key). 17.Set the key Life Time to 3000 and the Life Time Unit to Second.
Page 12
OvisLink 8000VPN VPN Guide to connect the 2 sides together. - 9 -...
OvisLink 8000VPN VPN Guide 2: U PPTP XAMPLE SING ONNECT EMOTE OCAL Router WAN IP: 192.168.0.3 Router LAN IP: PC WAN IP: 192.168.1.254 PC WAN IP: 192.168.1.2 192.168.0.1 In this example, we will demonstrate how to setup a VPN connection between a remote PC and the WL/IP-8000VPN using the PPTP server function.
OvisLink 8000VPN VPN Guide Router Setup 2, 3, 4 1. Click on VPN button on top of this page 2. Check VPN Enable checkbox. 3. Check NetBIOS broadcast Enable checkbox. 4. Enter the Max number of tunnels as 1 5. Enter the Tunnel Name as Tunnel 6.
Page 15
OvisLink 8000VPN VPN Guide 8, 9, 10 8. Check PPTP Server Enable checkbox. 9. Change the Virtual IP of PPTP Server address, if needed 10.Change the Authentication Protocol to CHAP 11.Enter the Tunnel Name, User Name, and Password. 12.Click on Save button 13.Click on Reboot button.
OvisLink 8000VPN VPN Guide Remote PC Setup (Using Windows XP VPN Client) In case of Windows XP, the following steps shows PPTP client setting. 1. Go to Network Connection on Control Panel 2. Click on Create a new connection. 3. Click on Next button - 13 -...
Page 17
OvisLink 8000VPN VPN Guide 4. Click on Connect to the network at my workplace. 5. Click on Next button 6. Click on Virtual Private Network connection 7. Click on Next button - 14 -...
Page 18
OvisLink 8000VPN VPN Guide 8. Enter the name of this VPN connection. In this case, the name is To VPN router. 9. Click on Next 10. Enter the WAN IP address or DDNS domain name of your VPN router. 11. Click on Next 192.168.0.3 - 15 -...
Page 19
OvisLink 8000VPN VPN Guide 12. If you would like this connection to appear on your desktop. Please do so by ticking the check box of Add a shortcut to the connection to my desktop. 13. Click on Finish button. 14. Click on Properties button - 16 -...
Page 20
OvisLink 8000VPN VPN Guide 15. Un-tick or cancel the check box of Require data encryption (disconnect if none) 16. Click on OK 17. Enter your User name and Password 18. Click on Connect button. - 17 -...
Page 21
OvisLink 8000VPN VPN Guide Once the successful connection is made, your Windows XP connection logo will appear on the bottom of your Window to confirm the successful connection. You can also access to your web-based management page from your router and go to PPTP server setting page.
OvisLink 8000VPN VPN Guide 3: IPS XAMPLE ONFIGURATION XAMPLE IPSec provides tunneling, authentication, and encryption technique so it ensure your data is safely transmitted on Internet without been attack by hackers. In order to create a secure VPN tunnel or channel between two endpoints by IPSEC, please take the following steps.
OvisLink 8000VPN VPN Guide Router’s IPSec Setup 2, 3, 4 1. Click on VPN button on top of this page 2. Check VPN Enable checkbox. 3. Check NetBIOS broadcast Enable checkbox. 4. Enter the Max number of tunnels as 1 5.
Page 24
OvisLink 8000VPN VPN Guide 8, 9 8. Enter the local subnet 192.168.1.0 and subnet mask 255.255.255.0. 9. Enter the remote subnet 192.168.2.1 and subnet mask 255.255.255.255. 10.Enter the IP address of the router’s WAN port. In this case, it is 192.168.2.1.
Page 25
OvisLink 8000VPN VPN Guide 14.Enter Proposal Name, key Life Time, and change any other settings, if needed, for proposal ID 1. (Note that you must use Group 2 with 3DES, or Group 1 with DES for default Windows XP IPSec) 15.Select Proposal ID 1 and click button Add to Proposal index.
Page 26
OvisLink 8000VPN VPN Guide 19.Enter IPSec Proposal Name, key Life Time, select DH Group, Auth algorithm, and change any other settings, if needed, for IPSec proposal ID 1. (Note that you must use Group 2 with 3DES, or Group 1 with DES for default Windows XP IPSec) 20.Select Proposal ID 1 and click button Add to Proposal index.
OvisLink 8000VPN VPN Guide PC’s IPSec Setup (Windows XP) The following section will explain the configuration steps on how to connection VPN tunnels between your PC (Windows XP) with your VPN router. Before you start to configure Windows XP IPSec environment, make sure you don’t have other 3 party IPSec clients installed in your system.
Page 28
OvisLink 8000VPN VPN Guide 5. Click on Add button 6. Click on IP Security policy management 7. Click on Add button - 25 -...
Page 29
OvisLink 8000VPN VPN Guide 8. Select Local Computer 9. Click on Finish button 10. Click on Close button - 26 -...
Page 30
OvisLink 8000VPN VPN Guide 11. Click on OK button 12. Click on IP Security Policies on Local Computer on the left screen 13. On the right screen, move your mouse cursor to the blank area and hit a single click on the right hand button of your mouse.
Page 31
OvisLink 8000VPN VPN Guide 15. Click on Next button 16. From the Name field, enter the name of VPN tunnel. (in this case, the name is called VPN) 17. Un-check or cancel the square box next to Activate the default response rule.
Page 32
OvisLink 8000VPN VPN Guide 19. Tick on the square box next to Edit properties 20. Click on Finish button 21. Un-tick or cancel Use Add Wizard 22. Click on Add button - 29 -...
Page 33
OvisLink 8000VPN VPN Guide 23. Click on Add button 24. Enter the name of the IP Filter List. (In this case, the name is WinXP to VPN router) 25. Uncheck Use Add Wizard. 26. Click OK. - 30 -...
Page 34
OvisLink 8000VPN VPN Guide 27. From Source address pull-down window, select My IP Address 28. From Destination address pull-down window, select A specific IP Subnet. Enter destination IP address and its subnet mask. (in this case, the destination IP is 192.168.1.0/255.255.
Page 35
OvisLink 8000VPN VPN Guide 32. Click on IP Filter name of your previous setting. (in this case, it’s WinXP to VPNrouter) 33. Click on Require Security 34. Click on Edit button - 32 -...
Page 36
OvisLink 8000VPN VPN Guide 35. Click on Negotiate security 36. Cancel the check box of Accept unsecured communication, but always respond using IPSec 37. Tick the box of session key perfect forward secrecy (PFS). 38. Click on OK button 39. Click on Edit button - 33 -...
Page 37
OvisLink 8000VPN VPN Guide 40. Click on Use this string (preshared key) 41. From the bottom blank area, enter the name of preshared key defined in web-based management from previous setting. 42. Click on OK buton 43. Click on The tunnel endpoint is specified by this IP address 44.
Page 38
OvisLink 8000VPN VPN Guide 46. Click on pre-defined IP Security rules. (in this case it’s WinXP to VPNtunnel) 47. Click on Add button 48. Click on Add button - 35 -...
Page 39
OvisLink 8000VPN VPN Guide 49. Enter the name of IP filter list in opposite direction. In this case, it’s VPNrouter to WinXP. 50. Click on Add button 51. From Source address pull-down window, select A specific IP Subnet 52. Enter destination IP address and its subnet mask.
Page 40
OvisLink 8000VPN VPN Guide 56. Click on OK button 57. Select Filter Action tab on top 58. Click on Require Security 59. Click on Edit button - 37 -...
Page 41
OvisLink 8000VPN VPN Guide 60. Click on Negotiate security 61. Cancel the check box of Accept unsecured communication, but always respond using IPSec 62. Tick the box of session key perfect forward secrecy (PFS). 63. Click on OK button 64. Click on Edit button - 38 -...
Page 42
OvisLink 8000VPN VPN Guide 65. Click on Use this string (preshared key) 66. From the bottom blank area, enter the name of preshared key defined in web-based management from previous setting. 67. Click on OK buton 68. Click on The tunnel endpoint is specified by this IP address 69.
Page 43
OvisLink 8000VPN VPN Guide 71. Click on OK button 72. Make sure you have checked the box of both IP Security rules you configured in previous section. In this case, they are WinXP to VPNrouter and VPNrouter to WinXP. 73. Click on Close button - 40 -...
Page 44
OvisLink 8000VPN VPN Guide 74. From IP Security Policy, click on the name of your VPN tunnel setting and click on the right hand button of your mouse. 75. Click on Assign from pull-down window. After successfully configure the Windows XP, you should be able to ping the network device at remote side.
OvisLink 8000VPN VPN Guide 4: U L2TP XAMPLE SING ONNECT EMOTE OCAL Router WAN IP: 192.168.0.3 Router LAN IP: PC WAN IP: PC WAN IP: 192.168.1.254 192.168.1.2 192.168.0.1 In this example, we will demonstrate how to setup a VPN connection between a remote PC and the WL/IP-8000VPN using the L2TP server function.
OvisLink 8000VPN VPN Guide Router Setup 2, 3, 4 1. Click on VPN button on top of this page 2. Check VPN Enable checkbox. 3. Check NetBIOS broadcast Enable checkbox. 4. Enter the Max number of tunnels as 1 5. Enter the Tunnel Name as Tunnel 6.
Page 47
OvisLink 8000VPN VPN Guide 8, 9, 10 8. Check L2TP Server Enable checkbox. 9. Change the Virtual IP of L2TP Server address, if needed 10.Change the Authentication Protocol to CHAP 11.Enter the Tunnel Name, User Name, and Password. 12.Click on Save button 13.Click on Reboot button.
OvisLink 8000VPN VPN Guide Remote PC Setup (Using Windows XP VPN Client) In case of Windows XP, the following steps shows L2TP client setting. Due to the limitation of L2TP protocol definition, we will need to disable IPSec in Windows remote access client. Please download file disableipsec.zip from Internet.
Page 49
OvisLink 8000VPN VPN Guide 3. Click on Next button 4. Click on Connect to the network at my workplace. 5. Click on Next button - 46 -...
Page 50
OvisLink 8000VPN VPN Guide 6. Click on Virtual Private Network connection 7. Click on Next button 8. Enter the name of this VPN connection. In this case, the name is To VPN router. 9. Click on Next - 47 -...
Page 51
OvisLink 8000VPN VPN Guide 10. Enter the WAN IP address or DDNS domain name of your VPN router. 11. Click on Next 192.168.0.3 12. If you would like this connection to appear on your desktop. Please do so by ticking the check box of Add a shortcut to the connection to my desktop.
Page 52
OvisLink 8000VPN VPN Guide 14. Click on Properties button 15. Un-tick or cancel the check box of Require data encryption (disconnect if none) 16. Click on OK - 49 -...
Page 53
OvisLink 8000VPN VPN Guide 17. Enter your User name and Password 18. Click on Connect button. Once the successful connection is made, your WINXP connection logo will appear on the bottom of your Window to confirm the successful connection. You can also access to your web-based management page from your router and go to L2TP server setting page.
OvisLink 8000VPN VPN Guide 5: D VPN A XAMPLE YNAMIC PPLICATION XAMPLE This example demonstrates the configuration for Dynamic VPN. The previous four VPN configurations are based on an assumption that we will configure both ends of the VPN. In the real world, it is almost impossible asking MIS people to set up VPN connections for every individual in the central site.
OvisLink 8000VPN VPN Guide Router’s Dynamic VPN with IPSec Setup 2, 3, 4 Click on VPN button on top of this page Check VPN Enable checkbox. Check NetBIOS broadcast Enable checkbox. Enter the Max number of tunnels as 1 Click on Save button at the bottom of the page (no need to reboot now) Click on Dynamic VPN Settings button - 52 -...
Page 56
OvisLink 8000VPN VPN Guide 7, 8 9, 10 7. Enter Tunnel Name 8. Enable Dynamic VPN by clicking on the check box 9. Enter Local subnet 10. Enter Local Netmask 11. Enter Pre-share Key (Note: the same key will be used in the VPN client) 12.
Page 57
OvisLink 8000VPN VPN Guide Enter Proposal Name, key Life Time, and change any other settings, if needed, for proposal ID 1. (Note that you must use Group 2 with 3DES, or Group 1 with DES if you use default Windows XP IPSec client) Select Proposal ID 1 and click button Add to Proposal index.
Page 58
OvisLink 8000VPN VPN Guide Enter IPSec Proposal Name, key Life Time, select DH Group, Auth algorithm, and change any other settings, if needed, for IPSec proposal ID 1. (Note that you must use Group 2 with 3DES, or Group 1 with DES if you use default Windows XP IPSec client) Select Proposal ID 1 and click button Add to Proposal index.
OvisLink 8000VPN VPN Guide Set up TheGreenBow VPN client Before start to set up the VPN client, it is assumed that (1) your computer is able to connect to Internet, (2) the Internet connection allows IPSec pass through, and (3) you have TheGreenBow VPN client installed in your PC. You can get TheGreenBow VPN client from the following link.
Page 60
OvisLink 8000VPN VPN Guide Please use the following steps to set up your TheGreenBow VPN client. 1. Install TheGreenBow VPN client in your PC. 2. Launch TheGreenBow VPN client. 3. Use mouse right button to click on Configuration, and add a New Phase 1 VPN connection.
Page 61
OvisLink 8000VPN VPN Guide Right (use mouse right button) click on CnxVpn1 and click (mouse left button) on Add Phase 2. 4. Click on CnxVpn1. Add the following information for phase 1. Remote Gateway Preshared Key twice (the second one in Confirm field) IKE information: select Key Group DH768 (If you use DH 1024 in WL/IP-8000 VPN, then you will need to use the right one).
Page 62
OvisLink 8000VPN VPN Guide Tunnel is successfully opened Tunnel is successfully opened 7. Click on the second CnxVpn1. Add the following phase 2 information. Select Address type as Subnet address, Remote LAN address, and Subnet Mask The ESP information: 3DES, SHA, and Tunnel mode Check mark PFS and select Group DH768.
Page 63
OvisLink 8000VPN VPN Guide VPN any more. The following link provides more information for TheGreenBow VPN client. http://www.thegreenbow.com/vpn_doc.html - 60 -...
Need help?
Do you have a question about the WL-8000VPN and is the answer not in the manual?
Questions and answers