This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| app-notes:ipsec-fritzbox [2021/11/24 10:09] – [Table] klueppel | app-notes:ipsec-fritzbox [2021/11/25 09:00] (current) – klueppel | ||
|---|---|---|---|
| Line 2: | Line 2: | ||
| This has been tested with Netmodule SW 4.5.0.106 and Fritz!OS: 07.28. | This has been tested with Netmodule SW 4.5.0.106 and Fritz!OS: 07.28. | ||
| - | At first, we configure the Fritzbox to accept VPN LAN2LAN connection. | + | At first, we configure the Fritzbox to accept VPN LAN2LAN connection. |
| + | Instructions can be found at AVM https:// | ||
| - | Internet -> Freigaben | + | Internet -> Permit Access |
| - | "Ihr Heimnetz mit einem anderen | + | "Connect your home network with another |
| - | - Please choose a VPN Preshared | + | {{tablelayout? |
| - | | + | ^ VPN Connection |
| - | - Internet-Addresse der Gegenstelle: | + | | VPN password (pre-shared |
| - | - Internet-Addresse dieser Fritz!Box: Please insert your DynamicDNS name of you fritzbox. For example | + | | Name of the VPN connection |
| - | - Entferntes Netzwerk: This is the Subnet shared by Netmodule Router. In our case we use: 192.168.1.0/ 255.255.255.0 | + | | Web address of the remote site* | 1.2.3.4 |
| - | | + | | Web address of this FRITZ!Box*2 | netmodule.ddns.net |
| + | | Remote network | ||
| + | | Subnet mask | 255.255.255.0 | ||
| + | | Hold VPN connection permanently | ||
| + | *This value needs to be set on Netmodule Router as LocalID, Local ID Type IP-Address | ||
| Click OK to save the changes. | Click OK to save the changes. | ||
| + | |||
| + | *2 Please use your configured hostname. | ||
| Now we can configure the netmodule router: | Now we can configure the netmodule router: | ||
| Line 25: | Line 32: | ||
| | Config mode | | | Config mode | | ||
| | Local address | 0.0.0.0 | | | Local address | 0.0.0.0 | | ||
| - | | Remote peer address | netmodule.ddns.net | + | | Remote peer address | |
| Line 57: | Line 64: | ||
| {{tablelayout? | {{tablelayout? | ||
| ^ IPsec Proposal (IKE Phase 2) | ^ IPsec Proposal (IKE Phase 2) | ||
| - | | Encapsulation mode | + | | Encapsulation mode |
| | IPsec protocol | | IPsec protocol | ||
| | Encryption algorithm | | Encryption algorithm | ||
| | Authentication algorithm | | Authentication algorithm | ||
| - | | SA life time | + | | SA life time |
| | Perfect forward secrecy (PFS) | Check, use DH-Group "use from phase 1" | | | Perfect forward secrecy (PFS) | Check, use DH-Group "use from phase 1" | | ||
| - | | Force encapsulation | + | | Force encapsulation |
| **Networks** | **Networks** | ||
| Line 85: | Line 92: | ||
| Apply new settings. Now the netmodule router should connect to Fritzbox and both should share there networks. | Apply new settings. Now the netmodule router should connect to Fritzbox and both should share there networks. | ||
| + | |||
| + | You also can use a config and update your values: | ||
| + | < | ||
| + | ipsec.status=1 | ||
| + | ipsec.0.remote.serverIp=netmodule.ddns.net | ||
| + | ipsec.0.ike.psk=[enc]sTs/ | ||
| + | ipsec.0.ike.mode=aggressive | ||
| + | ipsec.0.ike.hash=sha1 | ||
| + | ipsec.0.ike.dh=modp1024 | ||
| + | ipsec.0.ike.localId=1.2.3.4 | ||
| + | ipsec.0.ike.remoteId=netmdoule.ddns.net | ||
| + | ipsec.0.ike.remoteIdType=FQDN | ||
| + | ipsec.0.esp.hash=sha1 | ||
| + | ipsec.0.esp.pfs=1 | ||
| + | ipsec.0.dpd.status=0 | ||
| + | ipsec.0.local.0.lanAddress=192.168.1.0 | ||
| + | ipsec.0.local.0.lanMask=255.255.255.0 | ||
| + | ipsec.0.local.0.natAddress=- | ||
| + | ipsec.0.remote.0.lanAddress=192.168.178.0 | ||
| + | ipsec.0.remote.0.lanMask=255.255.255.0 | ||
| + | </ | ||
| + | |||