How to configure an EasyLink VPN Tunnel for Site-to-Site VPN

This article will provide you with instructions on how to set up a site-to-site VPN tunnel between two (2) Linksys LRT224 and/or LRT214 routers.
 
NOTE:  In this example, the Linksys LRT224 routers are used.
 
In a typical network environment, the Gigabit VPN router (Linksys LRT214 and/or LRT224) will have a public IP Address from the Internet Service Provider (ISP).  In this example, we will connect two (2) Gigabit VPN routers with an Ethernet cable and configure a static IP Address on both routers to emulate the Internet connection in a lab environment.  
 
QUICK TIP:  Specifically, Router 1 will have a WAN IP of 10.0.0.1 and Router 2 will have a WAN IP of 10.0.0.2.  Since the routers have their WAN ports connected to each other directly, the default gateway of Router 1 is configured to be the WAN IP of Router 2, and vice versa.
 
Configuring WAN settings
Configuring DHCP
Configuring the server
Configuring the client
Summary
 
Configuring WAN settings

 
Step 1:
Access the web-based setup page of Router 1 and Router 2.  For instructions, click here.
 
Step 2:
Under the Configuration tab, click Setup > Network.
 
Step 3:
In the WAN SETTING section, click the WAN1’s Edit button.
 
 
Step 4:
Select Static IP for the WAN Connection Type
 
 
Step 5:
For Router 1, enter “10.0.0.1” in the Specify WAN IP Address field and “10.0.0.2” for the Default Gateway Address.  Click Save.
 
 
Step 6:
For Router 2, enter “10.0.0.2” in the Specify WAN IP Address field and “10.0.0.1” for the Default Gateway Address. Click Save.
 
 
Configuring DHCP
 
As a pre-requisite to setting up a site-to-site VPN tunnel, the LAN IP subnets of both routers must be different.  In this section, we will change the LAN IP of Router 2 to 192.168.2.1, and leave the LAN IP of Router 1 unchanged (ex. 192.168.1.1).

Step 1:
Under the Configuration tab, click DHCP > DHCP Setup.
 
Step 2:
Enter “192.168.2.1” in the Device IP field.
 
 
Step 3:
Click Save.
 
Configuring the server
 
Both routers are now connected on the WAN side, with different LAN IP subnets.  We can now proceed with configuring a site-to-site VPN tunnel using EasyLink VPN.  In this scenario, it is assumed that Router 1 is the EasyLink VPN server and Router 2 is one of the five (5) EasyLink VPN clients that will initiate a connection to the server.

Step 1:
Under the Configuration tab of Router 1 (Server), click EasyLink VPN > Summary.
 
Step 2:
In the EASYLINK VPN SERVER STATUS section, click the Edit button.
 
 
Step 3:
Click Enable then OK.
 
 
Step 4:
Click the Inbound EasyLink VPN sub-tab to create an account.
 
Step 5:
Enter your preferred Account Name and Password.
 
NOTE:  In this example, the account name is easyLink1.
 
 
Step 6:
Click Save.
 
Configuring the client
 
On the client side, the account credentials and the Primary Server IP Address or the WAN IP of Router 1 (Server) are required in the Outbound EasyLink VPN tab. 

Step 1:
Under the Configuration tab of Router 2 (Client), click EasyLink VPN > Outbound EasyLink VPN.
 
Step 2:
Check Enable.
 
Step 3:
Enter the values for Account Name, Password and Primary Server.
 
 
NOTE:  The Primary Server IP Address is the WAN IP of Router 1.  In this example, 10.0.0.1 is used.
 
QUICK TIP:  The Secondary Server IP Address can be used to specify an alternative EasyLink VPN server when the primary server is not reachable.  In practice, this could be the IP Address of the second WAN port of Router 1 if Router 1 has both WAN ports configured.
 
Step 4:
Check Keep Alive.
 
 
NOTE:  This option should be checked if you want the tunnel to be up all the time.

Step 5:
Click Save.
 
Summary
 
Both ends of the EasyLink VPN tunnel are now configured.  The status of the EasyLink VPN tunnels can be viewed in the EasyLink VPN > Summary page on both routers.  
 
NOTE:  Initially, the Tunnel Status will show Waiting for connection, indicating that the tunnel negotiation is in progress.  After about 30-60 seconds, the status will show Connected.
 
Router 2 EasyLink VPN Summary Page
 
The image below shows that Router 2 (Client) has a connected Outbound EasyLink VPN Tunnel from its LAN subnet (Local Group 192.168.2.0/255.255.255.0) to Router 1 (Server- with Remote Gateway 10.0.0.1 or Remote Group 192.168.1.0/255.255.255.0).

 
 
Router 1 EasyLink VPN Summary Page
 
The below image shows that Router 1 (Server) has a connected Inbound EasyLink VPN Tunnel from its LAN subnet (Local Group 192.168.1.0/255.255.255.0) to Router 2 (Client- with Remote Gateway 10.0.0.2 or Remote Group 192.168.2.0/255.255.255.0).

 

Was this support article useful?

Additional Support Questions?
Search Again