D-Link And TheGreenBow Solution DI-824VUP Wireless VPN Router Application Note Version 1.
Revision History Date Rev. Description Editor 1.0 Interoperability Compliance Testing Negotiate mode for Phase1 and Phase2 using TheGreenBow VPN Client and DLink product’s Wireless VPN router DI-824VUP. John Yoong 2009-4-24 1. Introduction The objective of this document is to provide a guide describing how to configure the devices to achieve the same environment as show at the network topology.
5. Network Diagram Note: DI-824VUP+ Router is set to allow IPSec pass through. It is important to note that this application note is also applicable to the following VPN routers: • DI-804HV • DI-808HV • DI-824VUP • DI-824VUP+ 6. Configurations In this document, we will only describe the main configurations for this Scenario. The configurations setting for all the D-Link products will not be described here and for more detail about the product you can download their user guide. 6.
• • Setup Phase 1 Setup Phase 2 6.1.1) Setup DI-824VUP+ for VPN tunneling 6.1.1.1) 1) Setup Dynamic VPN Click on the “VPN” and select the “Dynamic VPN”, please ensure all other VPN setting is clear or disable.
2) Fill in the details as show below and for the “Preshare key” must be the same as the preshare key set in Thegreenbow VPN Client software. Next click on “IKE Proposal” 3) Fill in the setting and select the “Encrypt” and “Auth” algorithm and lastly, add the profile to the setting to active it.
4) Lastly is to set the “IPSec Proposal”, add the profile to active it.
6.1.2) Setup TheGreenBow VPN Client software 6.1.2.1) 1) Setup Phase 1 Right click on the “Root” to add a new “Phase1”, next fill in the IP address for this VPN Client and Remote gateway IP follow by Preshared Key and IKE setting.
Note: the Preshared Key and IKE must be the same setting set in the Wireless VPN router DI-824VUP+. 6.1.2.2) 1) Setup Phase 2 Right click on the “Phase1” to add a new “Phase2”, next fill in the VPN Client address for this VPN Client and Remote gateway IP follow by ESP setting.
Note: the ESP Encryption and Authentication setting must be the same in the Wireless VPN router DI-824VUP+ IKE and IPSec setting. 7. Interoperability Compliance Testing 7.
a.
Series Negotiate Mode 7.2) Phase 1 Phase 2 3DES-SHA DES-MD5 DES-MD5 DES-MD5 DES-SHA DES-MD5 Test Result a. The VPN tunnel will be open at any negotiate mode set in Phase 1 and Phase 2.
b. The Wireless VPN Router DI-824VUP+ will show the tunnel is up at their VPN status. DI-824VUP+ VPN status c. VPN Client is able to Ping to the remote network.
8. Conclusion The Application Notes demonstrate how D-Link VPN products and TheGreenBow software combined perfectly address the requirements of the small and medium businesses worldwide. The joint VPN solution offer advantages around multiple access control and authorization mechanisms for users and tunneling capabilities to access the entire corporate network; it can also provide different access rights to different users.
D-Link Inc. All Rights Reserved D-Link is the worldwide leader and an award-winning designer, developer, and manufacturer of Wi-Fi and Ethernet networking, broadband, multimedia, voice and data communications and digital electronics solutions.