VPN L2TP with NAT and DDNS
Comments
-
Hi Alan, yes you can use IPSEC VPN site to site with a WAN port on each of the USG's with a dynamic-dns (e.g. no-ip.com ) broadcasting the IPV4 (dynamic IP address) or IPV6 9/64 and host name) .
I use a VTI tunnel between the USG's.... so much easier for routing etc.
The DDNS service used in our implementations with dynamic IPV4 WANs AND with block /64 IPV6s is no-ip.com
USE what ever you like as you see fit.......
Here's the basics...
use something unique to identify the gateways on each end .. refer to parameters 2-5 below.
parameter #1 is of course the remote dynamics-dns host you use.... make sure the ISG's have it active.... works great!
Site 1 - ddns host name= "site1.dyndns.org'- VPN Gateway / Peer Gateway Address / Status Address --> "site2.dyndns.org"
- VPN Gateway / Authentication Local ID Type: "E-Mail"
- VPN Gateway / Content: "any_email@site1.dyndns.org" (any concocted string will do)
- VPN Gateway / Peer ID Type : E-mail
- VPN Gateway / Content: "any_email@site2.dyndns.org" (any concocted string will do)
Site 2 - ddns host name= "site2.dyndns.org'- VPN Gateway / Peer Gateway Address / Status Address --> " site1.dyndns.org"
- VPN Gateway / Authentication Local ID Type: "E-Mail"
- VPN Gateway / Content: "any_email@site2.dyndns.org" (any concocted string will do)
- VPN Gateway / Peer ID Type : E-mail
- VPN Gateway / Content: "any_email@site1.dyndns.org" (any concocted string will do)
HTH
warwick
Hong Kong1
Categories
- All Categories
- 429 Beta Program
- 2.6K Nebula
- 163 Nebula Ideas
- 112 Nebula Status and Incidents
- 6K Security
- 350 USG FLEX H Series
- 291 Security Ideas
- 1.5K Switch
- 78 Switch Ideas
- 1.2K Wireless
- 42 Wireless Ideas
- 6.6K Consumer Product
- 261 Service & License
- 406 News and Release
- 87 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.8K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 82 Security Highlight