Main Menu
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Events
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • SonicWall Promotions
    • Customer Loyalty Program
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
SonicWall
  • Products
      All Products A–Z
      Free Trials
    • Network Security
      • Next-Generation Firewall (NGFW)
      • Network Security Services
      • Network Security Management
      • Secure SD-WAN
    • Threat Protection
      • Advanced Threat Protection Cloud
      • Advanced Threat Protection Appliance
      • Capture Labs
    • Secure Access Service Edge (SASE)
      • Zero-Trust Network Access (ZTNA)
    • Cloud Security
      • Cloud Firewall
      • Cloud App Security
    • Endpoint Security
      • Endpoint Detection & Response (EDR)
    • Email Security
      • Cloud Email Security
      • Hosted Email Security
      • On-Prem Email Security
    • Secure Access
      • Wireless Access Points
      • Network Switch
      • Virtual Private Network (VPN)
    • Wi-Fi 6 Access Points

      SonicWall SonicWave 600 series access points provide always-on, always-secure connectivity for complex, multi-device environments.

      Read More
  • Solutions
    • Industries
      • Distributed Enterprises
      • Retail & Hospitality
      • K-12 Education
      • Higher Education
      • State & Local
      • Federal
      • Healthcare
      • Financial Services
      • Carriers
    • Use Cases
      • Secure SD-Branch
      • Network Segmentation
      • Zero Trust Security
      • Secure SD-WAN
      • Office 365 Security
      • SaaS Security
      • Secure Wi-Fi
    • Solutions Widgets
      • Solutions Content Widgets
        Federal

        Protect Federal Agencies and Networks with scalable, purpose-built cybersecurity solutions

      • Solutions Image Widgets
  • Partners
    • SonicWall Partners
      • Partners Overview
      • Find a Partner
      • Authorized Distributors
      • Technology Partners
    • Partner Resources
      • Become a Partner
      • SonicWall University
      • Training & Certification
    • Partner Widgets
      • Custom HTML : Partners Content WIdgets
        Partner Portal

        Access to deal registration, MDF, sales and marketing tools, training and more

      • Partners Image Widgets
  • Support
    • Support
      • Support Portal
      • Knowledge Base
      • Technical Documentation
      • Community
      • Video Tutorials
      • Product Life Cycle Tables
      • Partner Enabled Services
      • Contact Support
    • Resources
      • Resource Center
      • Events
      • Free Trials
      • Blog
      • SonicWall University
      • MySonicWall
    • Capture Labs
      • Capture Labs
      • Security Center
      • Security News
      • PSIRT
      • Application Catalog
    • Support Widget
      • Custom HTML : Support Content WIdgets
        Support Portal

        Find answers to your questions by searching across our knowledge base, community, technical documentation and video tutorials

      • Support Image Widgets
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Events
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • SonicWall Promotions
    • Customer Loyalty Program
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
  • Contact Sales
  • English English English en
  • BLOG
  • CONTACT SALES
  • FREE TRIALS
  • English English English en
SonicWall
  • Products
      All Products A–Z
      Free Trials
    • Network Security
      • Next-Generation Firewall (NGFW)
      • Network Security Services
      • Network Security Management
      • Secure SD-WAN
    • Threat Protection
      • Advanced Threat Protection Cloud
      • Advanced Threat Protection Appliance
      • Capture Labs
    • Secure Access Service Edge (SASE)
      • Zero-Trust Network Access (ZTNA)
    • Cloud Security
      • Cloud Firewall
      • Cloud App Security
    • Endpoint Security
      • Endpoint Detection & Response (EDR)
    • Email Security
      • Cloud Email Security
      • Hosted Email Security
      • On-Prem Email Security
    • Secure Access
      • Wireless Access Points
      • Network Switch
      • Virtual Private Network (VPN)
    • Wi-Fi 6 Access Points

      SonicWall SonicWave 600 series access points provide always-on, always-secure connectivity for complex, multi-device environments.

      Read More
  • Solutions
    • Industries
      • Distributed Enterprises
      • Retail & Hospitality
      • K-12 Education
      • Higher Education
      • State & Local
      • Federal
      • Healthcare
      • Financial Services
      • Carriers
    • Use Cases
      • Secure SD-Branch
      • Network Segmentation
      • Zero Trust Security
      • Secure SD-WAN
      • Office 365 Security
      • SaaS Security
      • Secure Wi-Fi
    • Solutions Widgets
      • Solutions Content Widgets
        Federal

        Protect Federal Agencies and Networks with scalable, purpose-built cybersecurity solutions

      • Solutions Image Widgets
  • Partners
    • SonicWall Partners
      • Partners Overview
      • Find a Partner
      • Authorized Distributors
      • Technology Partners
    • Partner Resources
      • Become a Partner
      • SonicWall University
      • Training & Certification
    • Partner Widgets
      • Custom HTML : Partners Content WIdgets
        Partner Portal

        Access to deal registration, MDF, sales and marketing tools, training and more

      • Partners Image Widgets
  • Support
    • Support
      • Support Portal
      • Knowledge Base
      • Technical Documentation
      • Community
      • Video Tutorials
      • Product Life Cycle Tables
      • Partner Enabled Services
      • Contact Support
    • Resources
      • Resource Center
      • Events
      • Free Trials
      • Blog
      • SonicWall University
      • MySonicWall
    • Capture Labs
      • Capture Labs
      • Security Center
      • Security News
      • PSIRT
      • Application Catalog
    • Support Widget
      • Custom HTML : Support Content WIdgets
        Support Portal

        Find answers to your questions by searching across our knowledge base, community, technical documentation and video tutorials

      • Support Image Widgets
  • COMPANY
    • Boundless Cybersecurity
    • Press Releases
    • News
    • Events
    • Awards
    • Leadership
    • Press Kit
    • Careers
  • PROMOTIONS
    • SonicWall Promotions
    • Customer Loyalty Program
  • MANAGED SERVICES
    • Managed Security Services
    • Security as a Service
    • Professional Services
  • Contact Sales
  • Menu

How can I configure a Site to Site VPN tunnel between a SonicWall and Linksys VPN Router?

03/26/2020 795 People found this article helpful 226,033 Views

    Download
    Print
    Share
    • LinkedIn
    • Twitter
    • Facebook
    • Email
    • Copy URL The link has been copied to clipboard

    Description

    This article covers how to configure a site to site VPN tunnel between a SonicWall and Linksys VPN router in aggressive mode.

    Resolution

    SonicWall Configuration

    • Address Object For Remote Network
    1. Log into the SonicWall.
    2. Navigate to Manage | Policies | Objects | Address Objects.
    3. Create a new Address Object for the network on the LinkSys VPN router end you wish to reach (LinkSys LAN).Image
    • SA Configuration
    1. Browse to VPN, then Settings (default view for VPN).
    2. Ensure that Enable VPN is selected.
    3. Click Add.
    4. Change the Authentication Method to IKE using pre-shared secret.
    5. Name the SA,  EXAMPLE:Tunnel to LinkSys VPN Router.
    6. Enter the WAN IP of the LinkSys VPN router for IPSec Primary Gateway Name or Address.
    7. Enter your shared secret, EXAMPLE:P@ss20140603.
    8. Define Local IKE ID & Peer IKE ID. In this example the Local IKE ID is Yahoo.com and the Peer IKE ID is Google.com.Image

    9. Select the Network tab.
    10. Select Lan Subnets for Local Networks from the drop down box.
    11. Select the address object previously created for the destination network.Image

    12. Select the Proposals tab.
    13. Configure DH group under IKE Phase 1 to Group 1.
    14. Configure Phase 1 Encryption 3DES & authentication SHA1.
    15. Configure Phase 2 Encryption 3DES & authentication SHA1.
    16. Enable Perfect Forward Secrecy. And Select the DH Group as Group1.
    17. Configure Phase 1 & Phase 2 Life Time 28800.
      Image

    18. Select Advanced tab.
    19. Ensure that keep alive is enabled on only one end of the tunnel, it would be mostly on the device which is running on the DHCP WAN IP. In this example it is the LinkSys VPN Router.
    20. Select Enable Windows Networking (NetBIOS) Broadcast if you would like to pass NetBIOS across the VPN.Image

    LinkSys VPN Router Configuration

    • VPN CONFIG
    1. Navigate to VPN | Gateway to Gateway.
    2. Edit the tunnel.
    3. Define the Tunnel/Gateway.
    4. Select interface WAN1.
    5. Check the Enable option.
      Image

     

    •  Local Group Setup
    1. Select the Local Security Gateway Type as  IP + Domain name (FQDN) Authentication.
    2. Choose a domain name. EXAMPLE: Google.com. 
    3. Choose Local Security Group Type as Subnet.
    4. Mention the IP address and subnet mask of the local network which are behind the Linksys VPN Router.

    • Remote Group Setup
    1. Select the Remote Security Gateway Type as  IP + Domain name (FQDN) Authentication.
    2. Mention the IP address of the remote firewall. In this case it is the IP of the SonicWall firewall.
    3. Choose a domain name. EXAMPLE: Yahoo.com.
    4. Choose Remote Security Group Type as Subnet.
    5. Mention the IP address of the network which are behind the SonicWall or the network which you want to access behind the SonicWall.

      Image

     

    • IPSec Setup
    1. Select Keying mode as IKE with Preshared key.
    2. Select Phase 1 DH Group as Group1.
    3. Select Phase 1 encryption as 3DES.
    4. Select Phase 1 Authentication as SHA1.
    5. Mention the Phase 1 SA lifetime as 28800.
    6. Enable Perfect Forward Secrecy.
    7. Select Phase 2 DH Group as Group1.
    8. Select Phase 2 encryption as 3DES.
    9. Select Phase 2 Authentication as SHA1.
    10. Mention the Phase 2 SA lifetime as 28800.
    11. Mentioned the Pre-shared key. This key should be same on both the devices, SonicWall as well as LinkSys VPN router.
      Image

     

    •  Advanced Tab
    1. Enable the Aggressive Mode.
    2. Enable Keep Alive.
    3. Enable NetBIOS (If needed).
    4. Enable Dead Peer Detection (If needed).
      Image

    Related Articles

    • How to change the HTTP and HTTPS management ports on UTM Appliances using CLI
    • Bandwidth usage and tracking in SonicWall
    • How to force an update of the Security Services Signatures from the Firewall GUI

    Categories

    • Firewalls > NSa Series > VPN
    • Firewalls > NSv Series > VPN
    • Firewalls > TZ Series > VPN

    Not Finding Your Answers?

    ASK THE COMMUNITY

    Was This Article Helpful?

    YESNO

    Article Helpful Form

    Article Not Helpful Form

    Company
    • Careers
    • News
    • Leadership
    • Awards
    • Press Kit
    • Contact Us
    Popular resources
    • Communities
    • Blog
    • SonicWall Capture Labs

    Stay In Touch

    • By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement. You can unsubscribe at any time from the Preference Center.
    • This field is for validation purposes and should be left unchanged.
    • Facebook
    • Twitter
    • Linkedin
    • Youtube
    • Instagram

    © 2023 SonicWall. All Rights Reserved.

    • Legal
    • Privacy
    • English
    Scroll to top