VPN L2TP with NAT and DDNS
Comments
-
Hi Alan, yes you can use IPSEC VPN site to site with a WAN port on each of the USG's with a dynamic-dns (e.g. no-ip.com ) broadcasting the IPV4 (dynamic IP address) or IPV6 9/64 and host name) .
I use a VTI tunnel between the USG's.... so much easier for routing etc.
The DDNS service used in our implementations with dynamic IPV4 WANs AND with block /64 IPV6s is no-ip.com
USE what ever you like as you see fit.......
Here's the basics...
use something unique to identify the gateways on each end .. refer to parameters 2-5 below.
parameter #1 is of course the remote dynamics-dns host you use.... make sure the ISG's have it active.... works great!
Site 1 - ddns host name= "site1.dyndns.org'- VPN Gateway / Peer Gateway Address / Status Address --> "site2.dyndns.org"
- VPN Gateway / Authentication Local ID Type: "E-Mail"
- VPN Gateway / Content: "any_email@site1.dyndns.org" (any concocted string will do)
- VPN Gateway / Peer ID Type : E-mail
- VPN Gateway / Content: "any_email@site2.dyndns.org" (any concocted string will do)
Site 2 - ddns host name= "site2.dyndns.org'- VPN Gateway / Peer Gateway Address / Status Address --> " site1.dyndns.org"
- VPN Gateway / Authentication Local ID Type: "E-Mail"
- VPN Gateway / Content: "any_email@site2.dyndns.org" (any concocted string will do)
- VPN Gateway / Peer ID Type : E-mail
- VPN Gateway / Content: "any_email@site1.dyndns.org" (any concocted string will do)
HTH
warwick
Hong Kong1
Categories
- All Categories
- 414 Beta Program
- 2.3K Nebula
- 132 Nebula Ideas
- 92 Nebula Status and Incidents
- 5.4K Security
- 181 USG FLEX H Series
- 258 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 37 Wireless Ideas
- 6.2K Consumer Product
- 236 Service & License
- 372 News and Release
- 79 Security Advisories
- 24 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.9K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 80 About Community
- 69 Security Highlight