This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
app-notes:ipsec-fritzbox [2021/11/24 10:09] – [Table] klueppel | app-notes:ipsec-fritzbox [2021/11/25 09:00] (current) – klueppel | ||
---|---|---|---|
Line 2: | Line 2: | ||
This has been tested with Netmodule SW 4.5.0.106 and Fritz!OS: 07.28. | This has been tested with Netmodule SW 4.5.0.106 and Fritz!OS: 07.28. | ||
- | At first, we configure the Fritzbox to accept VPN LAN2LAN connection. | + | At first, we configure the Fritzbox to accept VPN LAN2LAN connection. |
+ | Instructions can be found at AVM https:// | ||
- | Internet -> Freigaben | + | Internet -> Permit Access |
- | "Ihr Heimnetz mit einem anderen | + | "Connect your home network with another |
- | - Please choose a VPN Preshared | + | {{tablelayout? |
- | | + | ^ VPN Connection |
- | - Internet-Addresse der Gegenstelle: | + | | VPN password (pre-shared |
- | - Internet-Addresse dieser Fritz!Box: Please insert your DynamicDNS name of you fritzbox. For example | + | | Name of the VPN connection |
- | - Entferntes Netzwerk: This is the Subnet shared by Netmodule Router. In our case we use: 192.168.1.0/ 255.255.255.0 | + | | Web address of the remote site* | 1.2.3.4 |
- | | + | | Web address of this FRITZ!Box*2 | netmodule.ddns.net |
+ | | Remote network | ||
+ | | Subnet mask | 255.255.255.0 | ||
+ | | Hold VPN connection permanently | ||
+ | *This value needs to be set on Netmodule Router as LocalID, Local ID Type IP-Address | ||
Click OK to save the changes. | Click OK to save the changes. | ||
+ | |||
+ | *2 Please use your configured hostname. | ||
Now we can configure the netmodule router: | Now we can configure the netmodule router: | ||
Line 25: | Line 32: | ||
| Config mode | | | Config mode | | ||
| Local address | 0.0.0.0 | | | Local address | 0.0.0.0 | | ||
- | | Remote peer address | netmodule.ddns.net | + | | Remote peer address | |
Line 57: | Line 64: | ||
{{tablelayout? | {{tablelayout? | ||
^ IPsec Proposal (IKE Phase 2) | ^ IPsec Proposal (IKE Phase 2) | ||
- | | Encapsulation mode | + | | Encapsulation mode |
| IPsec protocol | | IPsec protocol | ||
| Encryption algorithm | | Encryption algorithm | ||
| Authentication algorithm | | Authentication algorithm | ||
- | | SA life time | + | | SA life time |
| Perfect forward secrecy (PFS) | Check, use DH-Group "use from phase 1" | | | Perfect forward secrecy (PFS) | Check, use DH-Group "use from phase 1" | | ||
- | | Force encapsulation | + | | Force encapsulation |
**Networks** | **Networks** | ||
Line 85: | Line 92: | ||
Apply new settings. Now the netmodule router should connect to Fritzbox and both should share there networks. | Apply new settings. Now the netmodule router should connect to Fritzbox and both should share there networks. | ||
+ | |||
+ | You also can use a config and update your values: | ||
+ | < | ||
+ | ipsec.status=1 | ||
+ | ipsec.0.remote.serverIp=netmodule.ddns.net | ||
+ | ipsec.0.ike.psk=[enc]sTs/ | ||
+ | ipsec.0.ike.mode=aggressive | ||
+ | ipsec.0.ike.hash=sha1 | ||
+ | ipsec.0.ike.dh=modp1024 | ||
+ | ipsec.0.ike.localId=1.2.3.4 | ||
+ | ipsec.0.ike.remoteId=netmdoule.ddns.net | ||
+ | ipsec.0.ike.remoteIdType=FQDN | ||
+ | ipsec.0.esp.hash=sha1 | ||
+ | ipsec.0.esp.pfs=1 | ||
+ | ipsec.0.dpd.status=0 | ||
+ | ipsec.0.local.0.lanAddress=192.168.1.0 | ||
+ | ipsec.0.local.0.lanMask=255.255.255.0 | ||
+ | ipsec.0.local.0.natAddress=- | ||
+ | ipsec.0.remote.0.lanAddress=192.168.178.0 | ||
+ | ipsec.0.remote.0.lanMask=255.255.255.0 | ||
+ | </ | ||
+ | |||