Draytek LAN to LAN issues

KPC

KPC

Associate
Joined
7 Apr 2021
Posts
12
I have/am looking after...

2830n on FW 3.8.8.2_sb_232201 (Company A)
2862n on FW 3.9.1.1_BT (Company B site 1)
2820 on FW 3.7.3_232201 (Company B site 2)
2860 on FW 3.8.9.8_BT (My home)
2865 on FW 4.2.3_BT (My next home)

From home I have dial-out LAN to LAN configured from my 2860 to the company routers, each has a dial-in profile for me. This works seamlessly. Company B site 2 also dials in to Company B site 1 (an always-on connection).

I am moving soon but the new house has FTTP. I have just bought a 2865 for there as my 2860 might *just* handle the 300/50 line but certainly doesn't have enough throughput for anything higher if we decide to upgrade. So I need to get the VPNs set up on this, to the work sites.

The 2865 dials out fine to the 2860, but not to the older 2820 & 2830 routers. It just does not establish a connection at all. It does dial out to the 2862n and accepts a dial-in from my 2860.

Just for an experiment (and because I'd overlooked it) I upgraded the 2860 from 3.8.9.8 to 3.9.0 only to find this also broke the connections to the two older routers. I downgraded and this fixed it.

Has anyone else run across this issue and is there a resolution (besides having to buy newer units)? The 2820 and 2830n are on the latest available firmware. The work sites are a pain to get to so I want to avoid driving out and defaulting them if that isn't even going to work.
 
The two older routers haven't seen a firmware update since 2018, heck the 2820 has been EoL for almost a decade. You could just move the VPN function off the router, or upgrade the router - you seemingly have a 2860 spare now.
 
The two older routers haven't seen a firmware update since 2018, heck the 2820 has been EoL for almost a decade. You could just move the VPN function off the router, or upgrade the router - you seemingly have a 2860 spare now.

You're right... but a spare is handy to have and I think I've worked it out. On the 2865 the IKE settings are a little different, in IKE phase 2 settings I changed the Proposal Authentication from All to SHA1 for the 2820 and that now works. I'm guessing it'll be the same for the 2830n.

The 2830n is behind a Cisco on a Gamma Assured line. Gamma told me the Cisco had been changed to bridge mode and was doing nothing other than acting as a DSL modem. Turns out it's still blocking traffic from everything except their SIP servers and my current IP. I'll get them to change that.
 
Back
Top Bottom