VPN Tracker for Mac OS X



Similar documents
VPN Tracker for Mac OS X

VPN Tracker for Mac OS X

VPN Tracker for Mac OS X

VPN Tracker for Mac OS X

VPN Configuration Guide Netgear FVS338 / FVX538 / FVS124G

VPN Configuration Guide Linksys RV042/RV082

VPN Configuration Guide D-Link DFL-200

VPN Configuration Guide DrayTek Vigor / VigorPro

VPN Tracker for Mac OS X

VPN Configuration Guide D-Link DFL-800

VPN Configuration Guide LANCOM

VPN Configuration Guide. Cisco Small Business (Linksys) RV016 / RV042 / RV082

VPN Configuration Guide SonicWALL with SonicWALL Simple Client Provisioning

VPN Configuration Guide. Cisco Small Business (Linksys) WRVS4400N / RVS4000

How To Configure L2TP VPN Connection for MAC OS X client

VPN Configuration Guide SonicWALL with SonicWALL Simple Client Provisioning

VPN Configuration Guide. Cisco Small Business (Linksys) WRV210

IPsec VPN Application Guide REV:

VPN Quick Configuration Guide. Astaro Security Gateway V8

Configuration Guide. How to establish IPsec VPN Tunnel between D-Link DSR Router and iphone ios. Overview

VPN Configuration Guide. ZyWALL USG Series / ZyWALL 1050

VPN Configuration Guide WatchGuard Fireware XTM

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Fortinet Firewall. Overview

VPN Configuration Guide. AVM FRITZ!Box

VPN Configuration Guide. Parallels Remote Desktop for Mac

VPN Configuration Guide. Linksys (Belkin) LRT214 / LRT224 Gigabit VPN Router

VPN Configuration Guide. Juniper Networks NetScreen / SSG / ISG Series

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Sonicwall Firewall.

VPN. VPN For BIPAC 741/743GE

VPN Configuration Guide. Dell SonicWALL

Creating a Gateway to Client VPN between Sidewinder G2 and a Mac OS X Client

Configuring a Check Point FireWall-1 to SOHO IPSec Tunnel

VPN Configuration Guide. Cisco ASA 5500 Series

RF550VPN and RF560VPN

Virtual Private Network and Remote Access

Network/VPN Overlap How-To with SonicOS 2.0 Enhanced Updated 9/26/03 SonicWALL,Inc.

Virtual Private Network and Remote Access Setup

RouteFinder. IPSec VPN Client. Setup Examples. Reference Guide. Internet Security Appliance

VPN L2TP Application. Installation Guide

Internet Access Setup

Internet Access Setup

How to access peers with different VPN through IPSec. Tunnel

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Cisco Firewall. Overview

DFL-210/260, DFL-800/860, DFL-1600/2500 How to setup IPSec VPN connection

Deploying the Barracuda Link Balancer with Cisco ASA VPN Tunnels

How To Establish IPSec VPN connection between Cyberoam and Mikrotik router

How To Establish Site-to-Site VPN Connection. using Preshared Key. Applicable Version: onwards. Overview. Scenario. Site A Configuration

VPN PPTP Application. Installation Guide

VPN Configuration of ProSafe Client and Netgear ProSafe Router:

Application Notes. How to Configure UTM with Apple OSX and ios Devices for IPsec VPN

Setting up VPN connection: DI-824VUP+ with Windows PPTP client

Windows XP VPN Client Example

Configuring a VPN for Dynamic IP Address Connections

ZyWALL USG-Series. How to setup a Site-to-site VPN connection between two ZyWALL USG series.

I. What is VPN? II. Types of VPN connection. There are two types of VPN connection:

Remote Access via VPN Configuration (May 2011)

How To Configure Apple ipad for Cyberoam L2TP

Using IPsec VPN to provide communication between offices

ASUS WL-5XX Series Wireless Router Internet Configuration. User s Guide

How to setup PPTP VPN connection with DI-804HV or DI-808HV using Windows PPTP client

SonicWALL Global Management System Configuration Guide Standard Edition

Establishing a VPN tunnel to CNet CWR-854 VPN router using WinXP IPSec client

How to configure VPN function on TP-LINK Routers

Client applications are available for PC and Mac computers and ios and Android mobile devices. Internet

Broadband Router ALL1294B

VPNC Interoperability Profile

Fireware How To VPN. Introduction. Is there anything I need to know before I start? Configuring a BOVPN Gateway

LevelOne. User Manual. FBR-1430 VPN Broadband Router, 1W 4L V1.0

Version : 2.0 Date : 2006/6/12

Configuring Check Point VPN-1/FireWall-1 and SecuRemote Client with Avaya IP Softphone via NAT - Issue 1.0

Best Practices: Pass-Through w/bypass (Bridge Mode)

Astaro User Portal: Getting Software and Certificates Astaro IPsec Client: Configuring the Client...14

Wireless G Broadband quick install

Based on the VoIP Example 1(Basic Configuration and Registration), we will introduce how to dial the VoIP call through an encrypted VPN tunnel.

Connecting Remote Offices by Setting Up VPN Tunnels

Configuration Guide. How to Configure SSL VPN Features in DSR Series. Overview

Configuring the OfficeConnect Secure Gateway for a remote L2TP over IPSec connection

Global VPN Client Getting Started Guide

7. Configuring IPSec VPNs

Configuring SSL VPN on the Cisco ISA500 Security Appliance

Configuring an IPsec VPN to provide ios devices with secure, remote access to the network

Configuring SonicOS for Microsoft Azure

Katana Client to Linksys VPN Gateway

How To Set Up A Vpn Tunnel Between Winxp And Zwall On A Pc 2 And Winxp On A Windows Xp 2 On A Microsoft Gbk2 (Windows) On A Macbook 2 (Windows 2) On An Ip

Setting up D-Link VPN Client to VPN Routers

How To Configure An Ipsec Tunnel On A Network With A Network Gateways (Dfl-800) On A Pnet 2.5V2.5 (Dlf-600) On An Ipse Vpn

CREATING AN IKE IPSEC TUNNEL BETWEEN AN INTERNET SECURITY ROUTER AND A WINDOWS 2000/XP PC

How to Create a Basic VPN Connection in Panda GateDefender eseries

How To Industrial Networking

OUTDOOR IR NETWORK CAMERA Series

TW100-BRV204 VPN Firewall Router

Chapter 9 Monitoring System Performance

Setting up VPN Access for Remote Diagnostics Support

Internet. SonicWALL IP SEV IP IP IP Network Mask

How to set up Inbound Load Balance under Drop-in Mode

Broadband Bandwidth Controller

Workflow Guide. Establish Site-to-Site VPN Connection using RSA Keys. For Customers with Sophos Firewall Document Date: November 2015

How to configure VPN function on TP-LINK Routers

OvisLink 8000VPN VPN Guide WL/IP-8000VPN. Version 0.6

VPN Solution Guide Peplink Balance Series. Peplink Balance. VPN Solution Guide Copyright 2015 Peplink

Transcription:

VPN Tracker for Mac OS X How-to: Interoperability with DrayTek Vigor Rev. 1.0 Copyright 2003 equinux USA Inc. All rights reserved.

1. Introduction 1. Introduction This document describes how VPN Tracker can be used to establish a connection between a Macintosh running Mac OS X and a DrayTek Vigor VPN router. The entrie DrayTek product range should be compatible with VPN Tracker. equinux has tested the DrayTek Vigor 2200. Please note: The Vigor 2000 has no built-in VPN Server. The DrayTek Vigor is configured as a router, connecting a company LAN to the Internet. The example demonstrates a connection scenario, with a dial-in Mac connecting to a DrayTek Vigor. This paper is only a supplement to, not a replacement for, the instructions that have been included with your DrayTek Vigor. Please be sure to read and understand those instructions before beginning. All trademarks, product names, company names, logos, screenshots displayed, cited or otherwise indicated on the How-to are the property of their respective owners. EQUINUX SHALL HAVE ABSOLUTELY NO LIABILITY FOR ANY DIRECT OR INDIRECT, SPECIAL OR OTHER CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE USE OF THE HOW-TO OR ANY CHANGE TO THE ROUTER GENERALLY, INCLUDING WITHOUT LIMITATION, ANY LOST PROFITS, BUSINESS, OR DATA, EVEN IF EQUINUX HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. 2

2. Prerequisites 2. Prerequisites Firstly, you have to make sure that your DrayTek Vigor has VPN support built in. Please refer to your DrayTek Vigor manual for details. Furthermore, you should use a recent DrayTek firmware version. The latest firmware release for your DrayTek Vigor can be obtained from: http://www.draytek.com.tw For this document, firmware version 2.3.1 has been used. The type of the VPN Tracker license needed (personal or professional edition) depends on the connection scenario you are using. With a this router you can only connect whit a dial-in Mac without it s own subnet to the DrayTek Vigor so you need the personal edition in all cases. VPN Tracker is compatible with Mac OS X 10.2 or higher. Be sure to use VPN Tracker 1.6.1 or higher. 1 1 All VPN Tracker versions prior to the 1.6.1 did not include a connection type for DrayTek products. 3

3. Connecting a VPN Tracker Host to a DrayTek Vigor In this example, the Mac running VPN Tracker is directly connected to the internet via a dialup or PPP connection. 2 The DrayTek Vigor is configured in NAT mode and has the static WAN IP address 169.1.2.3 and the private LAN IP address 192.168.1.1. The stations in the LAN behind the DrayTek Vigor use 192.168.1.1 as their default gateway and should have a working Internet connection. VPN Tracker Mac (dynamic IP) local host 10.1.2.3 DrayTek Vigor WAN 169.1.2.3 LAN 192.168.1.1 192.168.1.10 192.168.1.20 192.168.1.30 LAN 192.168.1.0/24 Figure 1: VPN Tracker - DrayTek Vigor connection diagram (host to network) 2 Please note that the connection via a router, which uses Network Address Translation (NAT), only works if the NAT router supports IPSEC passthrough. Please contact your router s manufacturer for details. 4

3.1 D rayt ek V igor configuration The pre-defined VPN Tracker connection type has been created using the default settings on DrayTek Vigor. If you change any of the settings on the DrayTek Vigor VPN router, you will subsequently have to adjust the connection type in VPN Tracker. Step 1 Enable IPSec VPN Service: Go to [Advanced Setup -> Remote Access Control Setup] and enable IPSec VPN Service Figure 2: Enable IPSec VPN Service 5

Step 2 VPN IKE / IPSec Setup: Go to [Advanced Setup -> VPN IKE / IPSec Setup]. Enter your Pre-Shared key twice in the Dial-in Setup. Disable Medium (AH) and select High (ESP) and choose Both as IPSec Security method. You can leave the Pre-Shared Key for the Dial-Out Setup blank. Please Note: Every user uses the same shared key. Figure 3: VPN IKE / IPSec Setup 6

Step 3 Add a LAN-to-LAN dialer profile: To add a dialer profile, go to [Advanced Setup -> LAN-to-LAN Dialer Profile Setup]. By clicking on Index 1. you can create a new dialer profile. Figure 4: LAN-to-LAN Dialer Profile Setup Step 4 Edit a LAN-to-LAN dialer Profile Setup: Enter a name for this profile (e.g. vpntracker) and select Enable this profile. Choose Dial-In as Call Direction. Please leave the Dial-Out Settings blank. Enter a username for the Dial-In Setting and leave the password field blank. Make sure that the only allowed dial-in type is IPSec tunnel. Enter the same Remote Network IP (e.g. 10.1.2.3) that you will use for local host in VPN Tracker (figure 8) and change the Remote Network Mask to 255.255.255.255. This setting refers to the Local Host field in VPN Tracker. Please note: The remote host IP is not the same as the dynamic IP from the ISP. Finally please change the RIP direction to Disable. 7

Figure 5: LAN-to-LAN Dialer Profile Setup 8

> Multiple VPN Tracker Hosts Repeat step 4, using different names e.g. vpn2 and a different Remote Network IP. The Vigor 2200/2600 can handle up to 8 simultaneous connections. The Vigor 2300 up to 16. 3.2 VPN T racker configuration Step 1 Add a new connection with the following options: Choose DrayTek Vigor as the Connection Type, Host to Network as mode, then type in the remote endpoint (169.1.2.3) and the remote network (192.168.1.0/24). Enter the same local host that you typed in in Figure 5, which will be the virtual IP address of your Mac (10.1.2.3). Figure 6: VPN Tracker connection dialog Step 2 Click Edit pre-shared key and type in the shared secret key that you typed-in in the DrayTek Vigor (Figure 2). 9

Figure 7: Shared key dialog Step 3 Save the connection and Click Start IPsec in the VPN Tracker main window. You re done. After 10-20 seconds the red status indicator for the connection should change to green, which means you re securely connected to the DrayTek Vigor. After IPsec has been started, you may quit VPN Tracker. The IPsec service will keep running. Now to test your connection simply ping a host in the DrayTek Vigor network from the dialed-in Mac in the Terminal utility: ping 192.168.1.10 And from the DrayTek Vigor network (192.168.1.0/24) you can: ping 10.1.2.3 > Debugging If the status indicator does not change to green please have a look at the log file on both sides. You can define the amount of information available in the log file in the VPN Tracker preferences. 10

4. Connecting a VPN Tracker host to a DrayTek Vigor with dynamic DNS 4. Connecting a VPN Tracker host to a DrayTek Vigor with dynamic DNS The majority of users don t receive a fixed IP-Address from a provider without a leased line. In most cases of PPoE you will be disconnected from the network after 24 hours at the latest, and a new IP- Address will be assigned. Firstly, make sure that the configuration with static IP addresses (Chapter 3) works properly, then begin testing with dynamic DNS. A known IP address is the requirement for a VPN server. There are special DynDNS services available online to avoid entering the address each time. The DynDNS service providers translate a domain name like vpntracker.dyndns.org to the appropriate IP- Address. The Vigor-Router automatically informs the DynDNS-service after every change made. However, you have to restart your VPN connection on the Mac side to access the server again. To use this feature, set up a DynDNS account on your router as described in the DrayTek Vigor users guide. In VPN Tracker just replace the IP-Address in the field Remote Endpoint in the VPN Tracker connection dialog (e.g. 169.1.2.3) with the hostname of your DynDNS host (e.g. vpntracker.dyndns.org). Figure 8: VPN Tracker connection dialog 11