To add a new IPSEC VPN, click on the VPN->IPSEC menu on the Interface screen.
Here;
Local Network is assumed to be 192.168.1.0/24 and 192.168.10.0/24.
Remote center/branch external IP address is assumed to be 219.41.59.66 and Remote Local Network 192.168.2.0/24.
Let's start configuring the settings of our new vpn by clicking Add.
NOTE: IPSEC creates a secure connection between branches. Here it is assumed that the center and branch have static IPs. If you do not have a static IP, you cannot use this feature.
1- On the screen that opens, fill in the VPN Definition, Remote Server, Interface, Dead Pear Detective fields in the Network tab.
2- Switch to the Authentication tab, here Configuration type default IKEv1 is selected. Protocol, Mode, Exchange Mode is selected as shown in the image. We select Peer ID type IP and write the Public IP address of the Modem side as Peer ID. The key field is mandatory. (Your configuration here must be the same as the other center/branch).
3- Switch to the Phase-1 tab, here we select Encryption, Hash, Group, Key Validity Period as shown in the image. We select Local ID type IP and write Poniva Public IP address as Local ID. (Your configuration here should be the same as the other center / branch).
4- Switch to Phase-2 tab, where Local Networks is your own local network. Remote Tunnel Networks is the local network on the opposite center/branch side. If you want which of your local networks to access the counter local network, you need to add them below as shown in the image. We select Encryption, Hash, Group, Key Validity Period as in the image. (Your configuration here should be the same as the other center/branch).
5- Switch to the Advanced tab, here you can type an IP address in the local network against the Ping Control field or leave it blank. The Auto Add Firewall Rules option must be active. If you activate the Failover option, when your current line goes down, the other line you select here will continue to keep the connection active.
6- Switch to the Validity tab, where you can select the hours during which the IPSEC VPN will be active. By default the ALWAYS option is active.
After saying Save, let's start configuring the same settings you configured here for our opposite Zyxel modem.
1- We log in to the modem Web interface.
2- Go to the Security->IPSEC VPN menu. We say Add New Connection.
3- On the screen that opens, check the Active box.
We give a name for our vpn in the IPSec Connection Name field.
In the Remote IPSec Gateway Address (IP or Domain Name) field, we write the Poniva Public IP address. For example 77.55.66.99
The IP block behind the IP Address for VPN Zyxel is written. For example 192.168.2.0
The ip block behind IP Address for VPN Poniva is written. For example 192.168.1.0
Protocol and Key Exchange Method remain the same.
Pre-Shared Key We enter the Key we entered in the Poniva Authentication settings.
Local ID Content We type Zyxel modem public ip.
Remote ID Content Poniva public ip.
We continue to configure the settings by clicking the more button.
The Phase 1 and Phase 2 settings here should be the same as the settings on the Poniva side.
After you click Save, click Monitor and here we trigger our vpn by clicking the Trigger button.
