ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    USG to EdgeRouter VPN

    IT Discussion
    ubnt ubiquiti usg unifi edgerouter vpn
    5
    10
    1.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller
      last edited by

      Has anyone set up a site to site VPN between an EdgeRouter and a USG? I'm assuming that this is no problem, but I'm not 100% sure that we've tested it before and I wanted to make sure that someone had done it first hand.

      JaredBuschJ 1 Reply Last reply Reply Quote 0
      • JaredBuschJ
        JaredBusch @scottalanmiller
        last edited by

        @scottalanmiller said in USG to EdgeRouter VPN:

        Has anyone set up a site to site VPN between an EdgeRouter and a USG? I'm assuming that this is no problem, but I'm not 100% sure that we've tested it before and I wanted to make sure that someone had done it first hand.

        I helped @Dashrender do this a long time ago before there was a vpn option built into the GUI.

        It works fine, just a simple IPSEC preshared key based tunnel.

        DashrenderD 1 Reply Last reply Reply Quote 2
        • DashrenderD
          Dashrender @JaredBusch
          last edited by

          @JaredBusch said in USG to EdgeRouter VPN:

          @scottalanmiller said in USG to EdgeRouter VPN:

          Has anyone set up a site to site VPN between an EdgeRouter and a USG? I'm assuming that this is no problem, but I'm not 100% sure that we've tested it before and I wanted to make sure that someone had done it first hand.

          I helped @Dashrender do this a long time ago before there was a vpn option built into the GUI.

          It works fine, just a simple IPSEC preshared key based tunnel.

          If I recall, I had to setup a JSON file on the controller for the USG to set the settings - it was a hassle to say the least... and if you weren't using a RADIUS server, it loves to bitch at you (or was that just the documentation).

          JaredBuschJ 1 Reply Last reply Reply Quote 1
          • JaredBuschJ
            JaredBusch @Dashrender
            last edited by

            @Dashrender you recall correctly. But basic IPSEC is in the controller now. I do believe.

            FATeknollogeeF DashrenderD 2 Replies Last reply Reply Quote 3
            • FATeknollogeeF
              FATeknollogee @JaredBusch
              last edited by

              @JaredBusch said in USG to EdgeRouter VPN:

              @Dashrender you recall correctly. But basic IPSEC is in the controller now. I do believe.

              JB is correct, just use the IPSEC in both controllers (aka routers).

              1 Reply Last reply Reply Quote 1
              • DashrenderD
                Dashrender @JaredBusch
                last edited by

                @JaredBusch said in USG to EdgeRouter VPN:

                @Dashrender you recall correctly. But basic IPSEC is in the controller now. I do believe.

                Yup.

                1 Reply Last reply Reply Quote 0
                • M
                  manxam
                  last edited by

                  In my experience, the two devices use different defaults for S2S connections (DH group, encryption).
                  Thankfully, this is now somewhat selectable on the USG but not on the Edgemax.
                  I'd setup the Edgemax site using the gui first (for simplicity), check the DH group and IKE settings then duplicate these on the USG.

                  JaredBuschJ 1 Reply Last reply Reply Quote 1
                  • JaredBuschJ
                    JaredBusch @manxam
                    last edited by

                    @manxam said in USG to EdgeRouter VPN:

                    In my experience, the two devices use different defaults for S2S connections (DH group, encryption).
                    Thankfully, this is now somewhat selectable on the USG but not on the Edgemax.
                    I'd setup the Edgemax site using the gui first (for simplicity), check the DH group and IKE settings then duplicate these on the USG.

                    Those settings are most certainly selectable on the EdgeMax line. Always have been.

                    02300793-91fe-49c1-a4ec-f65e23290612-image.png

                    1 Reply Last reply Reply Quote 3
                    • M
                      manxam
                      last edited by

                      Interesting. The last time that I looked at the GUI (as we typically use CLI for VPN), it didn't give the option of DH group like so :

                      alt text

                      Wonder in what version this changed?

                      JaredBuschJ 1 Reply Last reply Reply Quote 0
                      • JaredBuschJ
                        JaredBusch @manxam
                        last edited by

                        @manxam said in USG to EdgeRouter VPN:

                        Interesting. The last time that I looked at the GUI (as we typically use CLI for VPN), it didn't give the option of DH group like so :

                        alt text

                        Wonder in what version this changed?

                        It has had it for as long as I recall. At least 1.5.

                        The CLI has had it 100% of the time since release at version 1.2.0

                        1 Reply Last reply Reply Quote 0
                        • 1 / 1
                        • First post
                          Last post