How to Configure Site-to-site IPSec VPN Where the Peer has a Dynamic IP Address

Options
Zyxel_Kevin
Zyxel_Kevin Posts: 795  Zyxel Employee
First Anniversary 10 Comments Friend Collector First Answer
edited November 2023 in VPN

This example shows how to use the VPN Setup Wizard to create a site-to-site VPN with the Peer has a Dynamic IP Address. The example instructs how to configure the VPN tunnel between each site. When the VPN tunnel is configured, each site can be accessed securely.

Set up IPSec VPN Tunnel for HQ

VPN > Site to Site VPN > Scenario

Type the VPN name used to identify this VPN connection. Select the type to the Custom. Click Next.

VPN > Site to Site VPN

Type My Address and select Peer Gateway Address as Dynamic Address.

Type a secure Pre-shared key.

Scroll down to find the Phase2 setting, type Local and Remote Subnet and select Responder Only. Then click save change.

Set up IPSec VPN Tunnel for Branch

VPN > Site to Site VPN > Scenario

Type the VPN name used to identify this VPN connection. Select the type to the Custom. Click Next.

VPN > Site to Site VPN

Type My Address as 0.0.0.0 and type Peer Gateway Address.

Type a secure Pre-shared key.

Scroll down to find the Phase2 setting, type Local and Remote Subnet. Then click save change.

Test IPSec VPN Tunnel

Go to VPN Status > IPSec VPN

Verify the IPSec VPN status

PC to Brance Office > Win 11 > cmd > ping 192.168.160.1