Jump to content

IPsec RUTOS configuration example: Difference between revisions

No edit summary
No edit summary
Line 27: Line 27:
----First of all, let's configure the VPN IPsec instance from RUTX11's side:
----First of all, let's configure the VPN IPsec instance from RUTX11's side:
*Login to the router's WebUI and go to '''Services → VPN → IPsec'''. Enter a custom name (for this example we use ''test'') for the IPsec instance click the "Add" button:
*Login to the router's WebUI and go to '''Services → VPN → IPsec'''. Enter a custom name (for this example we use ''test'') for the IPsec instance click the "Add" button:
[[File:IPsec RUT955 instance2.png|alt=|border|992x992px|border|class=tlt-border]]
[[File:Rutos ipsec rut955 instance 1.png|alt=|border|992x992px|border|class=tlt-border]]
----
----
*Click the "Edit" button located next to the newly created instance and set up the configuration according to the network:
*Click the "Edit" button located next to the newly created instance and set up the configuration according to the network:
[[File:IPsec RUT955 config 2.png|alt=|border|center|930x930px|class=tlt-border]]
[[File:IPsec RUT955 config 2.png|alt=|border|center|930x930px|class=tlt-border]]
[[File:RUTOS ipsec RUT955 optionconfig xauth 1.png|alt=|border|center|930x930px|class=tlt-border]]
*Below are explanations of the parameters highlighted in the figure above. Other parameters (not highlighted) are defaults. You can find descriptions for these parameters in the '''[[VPN#IPsec|VPN manual page, IPsec section]]'''
*Below are explanations of the parameters highlighted in the figure above. Other parameters (not highlighted) are defaults. You can find descriptions for these parameters in the '''[[VPN#IPsec|VPN manual page, IPsec section]]'''
**'''Enable''' - enables the IPsec instance
**'''Enable''' - enables the IPsec instance
Line 41: Line 42:
***'''Ping period (sec)''' - the period (in seconds) at which ICMP packets will be sent to the specified host
***'''Ping period (sec)''' - the period (in seconds) at which ICMP packets will be sent to the specified host
**'''Allow WebUI access''' - when checked, allows WebUI access for hosts from the opposite instance
**'''Allow WebUI access''' - when checked, allows WebUI access for hosts from the opposite instance
**'''XAUTH''' - when checked, allows is used to edit and display the authorization information used in connecting to the X server
'''NOTE''': remember to replace certain parameter values (like IP addresses) with your own relevant data.
'''NOTE''': remember to replace certain parameter values (like IP addresses) with your own relevant data.


*IKE lifetime must be added and can be any desired value.
*IKE lifetime must be added and can be any desired value.
[[File:IPsec RUT955 phase 12.png|alt=|center|714x714px|border|class=tlt-border]]
[[File:RUTOS IPsec RUT955 phase 12.png|alt=|center|930x930px|border|class=tlt-border]]
* Phase 1 & Phase 2 details should be the same with that of the RUT955 P1 & P2 details or else the tunnel will not be properly established.
* Phase 1 & Phase 2 details should be the same with that of the RUT955 P1 & P2 details or else the tunnel will not be properly established.
[[File:IPsec RUTX11 Phase 22.png|alt=|border|center|719x719px|class=tlt-border]]
[[File:RUTOS IPsec RUT955 phase 2 2.png|alt=|center|930x930px|border|class=tlt-border]]


===RUT955===
===RUT955===
----Similarly, the configuration for the VPN IPsec instance from RUT955's side is as follows:
----Similarly, the configuration for the VPN IPsec instance from RUT955's side is as follows:


[[File:IPsec RUT955 instance2.png|alt=|border|992x992px|border|class=tlt-border]]
[[File:RUTOS IPsec RUTX11 instance 2.png|alt=|border|992x992px|border|class=tlt-border]]


*In this case, Remote endpoint should be RUTX11's Public IP:
*In this case, Remote endpoint should be RUTX11's Public IP:
[[File:IPsec RUTX11 Config2.png|alt=|center|762x762px|border|class=tlt-border]]
[[File:IPsec RUTX11 Config2.png|alt=|center|930x930px|border|class=tlt-border]]
[[File:RUTOS ipsec RUT955 optionconfig xauth 1.png|alt=|border|center|930x930px|class=tlt-border]]
----
----
*The last step in configuring the IPsec instances is '''Phase settings'''. Make sure they match with the Phase settings (both Phase 1 and Phase 2) of the RUTX11's connection:
*The last step in configuring the IPsec instances is '''Phase settings'''. Make sure they match with the Phase settings (both Phase 1 and Phase 2) of the RUTX11's connection:
[[File:IPsec RUT955 phase 12.png|alt=|border|center|789x789px|class=tlt-border]]
[[File:RUTOS IPsec RUT955 phase 12.png|alt=|center|930x930px|border|class=tlt-border]]
[[File:IPsec RUTX11 Phase 22.png|alt=|border|center|734x734px|class=tlt-border]]
[[File:RUTOS IPsec RUT955 phase 2 2.png|alt=|center|930x930px|border|class=tlt-border]]