To add a new IPSEC VPN, click on the VPN->IPSEC menu on the Interface screen.
Here;
Local Network is assumed to be 192.168.1.0/24 and 192.168.10.0/24.
Remote center/branch external IP address is assumed to be 219.41.59.66 and Remote Local Network 192.168.2.0/24.
Let's start configuring the settings of our new vpn by clicking Add.
NOTE: IPSEC creates a secure connection between branches. Here it is assumed that the center and branch have static IPs. If you do not have a static IP, you cannot use this feature.
1- On the screen that opens, fill in the VPN Definition, Remote Server, Interface, Dead Pear Detective fields in the Network tab.
2- Switch to the Authentication tab, here Configuration type default IKEv1 is selected. Protocol, Mode, Exchange Mode is selected as shown in the image. We select Peer ID type IP and write the Public IP address of the Modem side as Peer ID. The key field is mandatory, for example, we write "ponatest". (Your configuration here must be the same as the other center/branch).
3- Switch to the Phase-1 tab, here we select Encryption, Hash, Group, Key Validity Period as shown in the image. We select Local ID type IP and write Poniva Public IP address as Local ID. (Your configuration here should be the same as the other center / branch).
4- Switch to Phase-2 tab, where Local Networks is your own local network. Remote Tunnel Networks is the local network on the opposite center/branch side. If you want which of your local networks to access the counter local network, you need to add them below as shown in the image. We select Encryption, Hash, Group, Key Validity Period as in the image. (Your configuration here should be the same as the other center/branch).
5- Switch to the Advanced tab, here you can type an IP address in the local network against the Ping Control field or leave it blank. The Auto Add Firewall Rules option must be active.
6- Switch to the Validity tab, where you can select the hours during which the IPSEC VPN will be active. The default ALWAYS option is active.
After saying Save, let's start configuring the same settings you configured here for our opposite TP-Link modem.
1- We log in to the modem Web interface.
2- Go to the General Network->IPSEC VPN menu. We say Add New Connection.
3- We check the Active box on the screen that opens.
We give a name for our vpn in the IPSec Connection Name field.
In the Remote IPSec Gateway Address (URL) field, we type the Poniva Public IP address. For example 77.55.66.99
Select the Tunnel Access Network Mask from the LAN IP address.
The IP address for the VPN is written in the IP block behind TP-Link. For example 192.168.2.0
IP subnet Mask 255.255.255.255.0 is selected.
Tunnel Access Network Mask is selected from the WAN IP address.
The IP address for VPN is written in the IP block behind Poniva. For example 192.168.1.0
IP subnet Mask 255.255.255.255.0 is selected.
Key Exchange Method Auto (IKE) is selected.
Authentication Method PSK Key is selected.
PSK Key is ponatest (this is how we set the key on the Poniva side).
We continue to configure the settings by clicking the Show Advanced Settings button.
The Phase 1 and Phase 2 settings here should be the same as on the Poniva side.
After you click Save, you can test your VPN connection.
