How can I configure a Site to Site VPN tunnel between a SonicWall and Linksys VPN Router?

Description

This article covers how to configure a site to site VPN tunnel between a SonicWall and Linksys VPN router in aggressive mode.

Resolution

SonicWall Configuration

  • Address Object For Remote Network
  1. Log into the SonicWall.
  2. Navigate to Manage | Policies | Objects | Address Objects.
  3. Create a new Address Object for the network on the LinkSys VPN router end you wish to reach (LinkSys LAN).Image
  • SA Configuration
  1. Browse to VPN, then Settings (default view for VPN).
  2. Ensure that Enable VPN is selected.
  3. Click Add.
  4. Change the Authentication Method to IKE using pre-shared secret.
  5. Name the SA,  EXAMPLE:Tunnel to LinkSys VPN Router.
  6. Enter the WAN IP of the LinkSys VPN router for IPSec Primary Gateway Name or Address.
  7. Enter your shared secret, EXAMPLE:P@ss20140603.
  8. Define Local IKE ID & Peer IKE ID. In this example the Local IKE ID is Yahoo.com and the Peer IKE ID is Google.com.Image

  9. Select the Network tab.
  10. Select Lan Subnets for Local Networks from the drop down box.
  11. Select the address object previously created for the destination network.Image

  12. Select the Proposals tab.
  13. Configure DH group under IKE Phase 1 to Group 1.
  14. Configure Phase 1 Encryption 3DES & authentication SHA1.
  15. Configure Phase 2 Encryption 3DES & authentication SHA1.
  16. Enable Perfect Forward Secrecy. And Select the DH Group as Group1.
  17. Configure Phase 1 & Phase 2 Life Time 28800.
    Image

  18. Select Advanced tab.
  19. Ensure that keep alive is enabled on only one end of the tunnel, it would be mostly on the device which is running on the DHCP WAN IP. In this example it is the LinkSys VPN Router.
  20. Select Enable Windows Networking (NetBIOS) Broadcast if you would like to pass NetBIOS across the VPN.Image

LinkSys VPN Router Configuration

  • VPN CONFIG
  1. Navigate to VPN | Gateway to Gateway.
  2. Edit the tunnel.
  3. Define the Tunnel/Gateway.
  4. Select interface WAN1.
  5. Check the Enable option.
    Image

 

  •  Local Group Setup
  1. Select the Local Security Gateway Type as  IP + Domain name (FQDN) Authentication.
  2. Choose a domain name. EXAMPLE: Google.com
  3. Choose Local Security Group Type as Subnet.
  4. Mention the IP address and subnet mask of the local network which are behind the Linksys VPN Router.

  • Remote Group Setup
  1. Select the Remote Security Gateway Type as  IP + Domain name (FQDN) Authentication.
  2. Mention the IP address of the remote firewall. In this case it is the IP of the SonicWall firewall.
  3. Choose a domain name. EXAMPLE: Yahoo.com.
  4. Choose Remote Security Group Type as Subnet.
  5. Mention the IP address of the network which are behind the SonicWall or the network which you want to access behind the SonicWall.

    Image

 

  • IPSec Setup
  1. Select Keying mode as IKE with Preshared key.
  2. Select Phase 1 DH Group as Group1.
  3. Select Phase 1 encryption as 3DES.
  4. Select Phase 1 Authentication as SHA1.
  5. Mention the Phase 1 SA lifetime as 28800.
  6. Enable Perfect Forward Secrecy.
  7. Select Phase 2 DH Group as Group1.
  8. Select Phase 2 encryption as 3DES.
  9. Select Phase 2 Authentication as SHA1.
  10. Mention the Phase 2 SA lifetime as 28800.
  11. Mentioned the Pre-shared key. This key should be same on both the devices, SonicWall as well as LinkSys VPN router.
    Image

 

  •  Advanced Tab
  1. Enable the Aggressive Mode.
  2. Enable Keep Alive.
  3. Enable NetBIOS (If needed).
  4. Enable Dead Peer Detection (If needed).
    Image

Related Articles

  • Using 31-Bit Prefixes on IPv4 Address Error: Index of the interface: Invalid IP Address
    Read More
  • How to block a website using CFS 4.0 CLI commands
    Read More
  • How to Configure Wire / Tap mode in SonicOS
    Read More
not finding your answers?
was this article helpful?