Description:

This document describes how to set up an IKEv2 connection (site-to-site) between a LANCOM router and a LANCOM R&S®Unified Firewall.



Requirements:



Scenario:

1) The Unified Firewall is connected directly to the Internet and has a public IPv4 address:

2) The Unified Firewall is connected to the Internet via an upstream router:



Procedure:

The setup for scenarios 1 and 2 are basically the same. Scenario 2 additionally requires port and protocol forwarding to be set up on the upstream router (see section 3).

1) Configuration steps on the Unified Firewall:

1.1) Connect to the configuration interface of the Unified Firewall and navigate to VPN → IPSec → IPSec Settings.

1.2) Activate IPSec.

1.3) Switch to VPN → IPSec → Connections and click on the “+” icon to create a new IPSec connection.

1.4) Save the following parameters:

If you have created your own template or security profile, you can use these here.

1.5) Change to the Tunnels tab and enter the following parameters:

The activation of the option IKEv2 Compatbility Mode is mandatory when more than one network is to be used on one or both sides for VPN communication. Otherwise the VPN connection won't work!

Therefore LANCOM Systems recommends to generally activate the IKEv2 Compatibilty Mode for VPN connections between a LANCOM Router and a Unified Firewall.

1.6) Change to the Authentication tab and enter the following parameters:


The local and remote identifiers must not match!


1.7) Click the icon to create a new VPN host.

1.8) Save the following parameters:

1.9) In the VPN host click on the "connection" icon and, to open the firewall objects, click on the network object that the object (the site-to-site connection) should access. Repeat this step for every network that the branch should be able to access.

1.10) Use the “+” sign to assign the required protocols to the VPN host.

A Unified Firewall uses a deny-all strategy. You therefore have to explicitly allow communication.

Firewall objects can also be accessed via Desktop -> Desktop Connections and clicking on the “edit” icon.

1.11) Finally, implement the configuration changes by clicking Activate in the firewall.

1.12) This concludes the configuration steps on the Unified Firewall.



2) Configuration steps on the LANCOM router:

2.1) Start the Setup Wizard and select the option Connect two local area networks (VPN).

2.2) Select the option IKEv2.

2.3) IPSec over HTTPS must be disabled.

2.4) Enter a name for the new VPN remote.

2.5) Set the local identity to the same value as you configured for the remote identifier in step 1.6.

The local password must be set as the preshared key entered in step 1.6.

2.6) Set the remote identity to the same value as you configured for the local identifier set in step 1.6.

The remote password must be set as the preshared key entered in step 1.6.

2.7) In this example, the branch office establishes the VPN connection to the headquarters.

2.8) Enter the public IP address of the Unified Firewall (or the upstream router) into the Gateway field.

In the fields Address and Netmask, enter the LAN address range at the headquarters (192.168.66.0) along with the associated netmask.

2.9) Click on Finish to write the configuration back to the LANCOM router.



3) Setting up port and protocol forwarding on a LANCOM router (scenario 2 only):

IPSec requires the use of the UDP ports 500 and 4500 as well as the protocol ESP. These must be forwarded to the Unified Firewall.

Forwarding the UDP ports 500 and 4500 automatically causes the ESP protocol to be forwarded.

If you are using a router from another manufacturer, ask them about appropriate procedure.


If the UDP ports 500 and 4500 and the ESP protocol are forwarded to the Unified Firewall, an IPSec connection to the LANCOM router can only be used if it is encapsulated in HTTPS (IPSec-over-HTTPS). Otherwise, no IPSec connection will be established.

3.1) Open the configuration for the router in LANconfig and switch to the menu item IP-Router → Masq. → Port forwarding table.

3.2) Save the following parameters:

3.3) Create a further entry and specify the UDP port 4500.

3.4) Write the configuration back to the router.