D-Link Express EtherNetwork DI-804HV Router (DI804HVB) Logo
Posted on Feb 06, 2008

Site to Site VPN between DI 804HV and Sonicwall TZ190.

We are not able to establish site to site vpn between Dlink vpn router and Sonicwall utm box.
Error logs on dlink.
WAN Type: Static IP Address (V1.44)
Display time: Tuesday January 29, 2008 14:10:12
Tuesday January 29, 2008 14:10:01 Send IKE (INFO) : delete [192.168.0.0|202.70.200.22]-->[202.70.195.14|10.22.1.0] phase 2
Tuesday January 29, 2008 14:10:01 IKE phase2 (IPSec SA) remove : 192.168.0.0 <-> 10.22.1.0
Tuesday January 29, 2008 14:10:01 inbound SPI = 0xc000010, outbound SPI = 0x0
Tuesday January 29, 2008 14:10:01 Send IKE Q1(QINIT) : 192.168.0.0 --> 10.22.1.0
Tuesday January 29, 2008 14:10:01 Receive IKE Q2(QRESP) : [10.22.1.0|202.70.195.14]-->[202.70.200.22|192.168.0.0]
Tuesday January 29, 2008 14:10:05 Blocked access attempt from 202.70.86.58:49025 to TCP port 135
Tuesday January 29, 2008 14:10:05 Receive IKE Q2(QRESP) : [10.22.1.0|202.70.195.14]-->[202.70.200.22|192.168.0.0]
Tuesday January 29, 2008 14:10:06 IKED re-TX : QINIT to 202.70.195.14
Tuesday January 29, 2008 14:10:11 IKED re-TX : QINIT to 202.70.195.14

Error logs on Sonicwall

01/29/2008 01:50:27.336 - Warning - VPN IKE - Received packet retransmission. Drop duplicate packet - 202.70.200.22, 500 - 202.70.195.14, 500 - VPN Policy: IOLHDQ
01/29/2008 01:50:34.096 - Notice - Network Access - TCP connection dropped - 202.70.251.198, 1326, WAN - 202.70.195.15, 445, WAN - TCP SMB
01/29/2008 01:50:37.304 - Warning - VPN IKE - Received packet retransmission. Drop duplicate packet - 202.70.200.22, 500 - 202.70.195.14, 500 - VPN Policy: IOLHDQ
01/29/2008 01:50:57.256 - Warning - VPN IKE - Received packet retransmission. Drop duplicate packet - 202.70.200.22, 500 - 202.70.195.14, 500 - VPN Policy: IOLHDQ
01/29/2008 01:50:58.256 - Info - VPN IKE - IKE Responder: Received Quick Mode Request (Phase 2) - 202.70.200.22, 500 - 202.70.195.14, 500 - VPN Policy: IOLHDQ
01/29/2008 01:51:03.144 - Notice - Network Access - ICMP packet dropped - 202.70.202.126, 15898, WAN - 202.70.195.14, 8, WAN - ICMP Echo, Code: 0
01/29/2008 01:51:03.256 - Warning - VPN IKE - Received packet retransmission. Drop duplicate packet - 202.70.200.22, 500 - 202.70.195.14, 500 - VPN Policy: IOLHDQ
01/29/2008 01:51:07.656 - Notice - Network Access - UDP packet dropped - 172.25.2.75, 49371, WAN - 224.0.0.252, 5355 - UDP Port: 5355
01/29/2008 01:51:08.240 - Warning - VPN IKE - Received packet retransmission. Drop duplicate packet - 202.70.200.22, 500 - 202.70.195.14, 500 - VPN Policy: IOLHDQ
01/29/2008 01:51:18.208 - Warning - VPN IKE - Received packet retransmission. Drop duplicate packet - 202.70.200.22, 500 - 202.70.195.14, 500 - VPN Policy: IOLHDQ
01/29/2008 01:51:28.192 - Warning - VPN IKE - Received packet retransmission. Drop duplicate packet - 202.70.200.22, 500 - 202.70.195.14, 500 - VPN Policy: IOLHDQ
01/29/2008 01:51:35.576 - Notice - Network Access - TCP connection dropped - 68.205.153.225, 38696, WAN - 202.70.195.14, 22117, WAN - TCP Port: 22117

  • 2 more comments 
  • eborisov Apr 09, 2008

    Hello,



    I am having identical problem with identical configuration: D-Link to SonicWall with the same errors. Openning port 500 is not the solution unfortunately.



    Thank you



    Eugene

  • Anonymous Nov 19, 2008

    hello, i have a similar problem but with a CISCO, i can conect one tunnel, but the others donĀ“t make conection, i have 7 tunnels in the DI 804, and is the same configuration of the tunnel up.

  • Anonymous Jan 01, 2009

    yes the same

  • Anonymous Mar 29, 2014

    changed email password at request of gmail. i was requested to supply a telephone number to receive a number to complete the secure number. i received a 4 digit number. when i placed the 4 digit number in the box i noticed it requested a 6 digit number. i could not complete this entry. i can no longer use this gmail account.

×

1 Answer

A

Anonymous

Add Your Answer

×

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

0helpful
1answer

How to Site to Site VPN between DI 804HV and DI 804HV.

you can try to do port forwarding by logging in to router GUI setup page and manage this port

Service Name Start Port End Port Server IP address
VPN1 47 47 192.168.1.x
VPN2 50 51 192.168.1.x
VPN3 500 500 192.168.1.x
VPN4 1723 1723 192.168.1.x
0helpful
1answer

Vpn site to site

you need to create an IPSec tunnel between the router and windows server 2003 (run secpol.msc). From the dlink router, you need to set the IP address of the VoIP gateway as part of the LAN that is included on the VPN tunnel. Since it is the server 2003 that has a static IP, you need to initiate the connection from the Dlink router.
0helpful
1answer

How to routing router static ip address and local

Use the Sonicwall configuration wizard..

Please find below is to configure what ever you want.

Setup Wizard - This wizard will help you quickly configure the SonicWALL to secure your Internet connection. Once completed, you can use the SonicWALL Web Management Interface for additional configuration.

Registration & License Wizard - This wizard will help you register you and your firewall with mysonicwall.com and obtain licenses for additional Security Services features.

PortShield Interface Wizard - Segment and configure the integrated managed LAN switch of the SonicWALL.

Public Server Wizard - Quickly configure your SonicWALL to provide public access to an internal server.

VPN Wizard - Create a new site-to-site VPN Policy or configure the WAN GroupVPN to accept connections from the SonicWALL Global VPN Client
Thanks
..
0helpful
1answer

Sonicwall site2site vpn issues

please select nebios option in hq site tz190 firewall.
0helpful
2answers

Hi. i cant connecct my VPn

- Make sure you have an updated firmware on your router and after wards kindly visit this site for further instructions:
http://support.dlink.com/faq/view.asp?prod_id=1384&question=DI-804HV%20/%20DI-804V%20/%20DI-808HV
0helpful
1answer

Using DI-804hv, I can connected to vpn but not to LAN

First set up an static IP address on your computer with a range 192.168.3.x, once you connect to the DI go to >> LAN Settings and change there the DI IP to be in your range of 192.168.2.x.

If you use win XP here is a link how to set up a static IP with your computer:
http://www.hotcomm.com/FAQ/FAQ_staticIPXP.asp

Regards,
Adnan
0helpful
1answer

Vpn client

This router has built is VPN software that allows VPN from anywhere in the world. There would be no need for a software based VPN
0helpful
1answer

D Link DI 804HV is Server OS Windows 2k 2003 necessary? Or ca

The D Link DI 804HV is a standalone router/vpn it can work with any OS (Windows xp, vista, me, linux, mac...)

Regards,
Adnan
0helpful
2answers

I want to create site to site vpn with sonicwall tz170+ 2003serv

Complete documentation is available on the below link

http://www.sonicwall.com/us/support/3134.html#heading_3139
0helpful
1answer

Configuring the DI-804HV/DI-808HV

Step 1: Log into the web based configuration of the router by typing in the IP address of the router (default: 192.168.0.1) in your web browser. By default the username is admin and there is no password. Step 2: Click the VPN button on the left column, select the checkbox to Enable the VPN, and then in the box next to Max. number of tunnels, enter the maximum numbers of VPN tunnels that you would like to have connected. Step 3: In the space provided, enter the Tunnel Name for ID number 1, select IKE, and then click More. Step 4: In the Local Subnet and Local Netmask fields enter the network identifier for DI-804HVĀ“s LAN and the corresponding subnet mask. Step 5: In the Remote Subnet and Remote Netmask fields enter the network identifier for the DI-804VĀ“s LAN and the corresponding subnet mask. Step 6: In the Remote Gateway field enter the WAN IP address of the remote DI-804V and in the Preshared Key field, enter a key which must be exactly the same as the Preshared Key that is configured on the DI-804V. Step 7: Click Apply and then click on Select IKE Proposal... Step 8: Enter a name for proposal ID number 1 and select Group 2 from the DH Group drop-down menu. Step 9: Select 3DES as the Encryption Algorithm and SHA-1 as the Authentication Algorithm. Step 10: Enter a Lifetime value of 28800 and then select Sec. as the unit for the lifetime value. Step 11: Select 1 out of the Proposal ID drop-down menu and click Add To, which will add the proposal that was just configured to the IKE Proposal Index. Click Apply and then click Back. Step 12: Click on Select IPSec Proposal... Step 13: Enter a name for proposal ID number 1 and select None from the DH Group drop-down menu. Step 14: Select ESP as the Encapsulation Protocol. Step 15: Select 3DES as the Encryption Algorithm and MD5 as the Authentication Algorithm. Step 16: Enter a Lifetime value of 3600 and then select Sec. as the unit for the lifetime value. Step 17: Select 1 out of the Proposal ID dropdown menu and click Add To, which will add the proposal that was just configured to the IPSec Proposal Index. Click Apply and then click Restart. Configuring the DI-804V: Step 1: Access the router?s web configuration by entering the router?s IP address in your web browser. The default IP address is 192.168.0.1. Login using your password. The default username is admin and the password is blank. Help Accessing Web Management Step 2: Click on Basic Setup and then select Device IP Settings on the left. Step 3: Change the LAN IP address so that it is on a different subnet than the LAN of the DI-804HV (ie 192.168.1.1). Step 4: Click Next until you reach the Save & Restart screen. Click Save & Restart and then click Basic Setup once the unit has rebooted. Step 3: Click on VPN Settings. Step 4: Name your VPN connection and click ADD. Step 5: In Remote IP Network and Remote IP Netmask fields enter the network identifier and corresponding subnet mask of the DI-804HVĀ“s LAN. Step 6: In the Remote Gateway IP field enter the WAN IP address of the DI-804HV and make sure that the Network Interface is set to WAN Ethernet. Step 7: Verify that Secure Association is set to IKE and that Perfect Forward Secure is Disabled. Step 8: Verify the Encryption Protocol is set to 3DES and enter in your Preshared Key. The Preshared Key needs to be identical to the one configured on the DI-804HV Step 9: Leave the Key Life and IKE Life Time values at their default levels and click SAVE. Step 10: Click Next and then click on Save & Restart Establishing a connection: Step 1: Open a command prompt (Start > Run and type CMD) and from a computer on the internal LAN of the DI-804HV, ping the IP address of a computer that is on the internal LAN of the DI-804V, or vice versa. Step 2: Once you begin to receive replies, the VPN connection has been established. Step 3: To view the Status of the VPN on the DI-804V, click on Device Status. Step 4: From the Device Status screen click on VPN Status. Step 5: When the VPN has been established, the Status will be Active.
Not finding what you are looking for?

5,558 views

Ask a Question

Usually answered in minutes!

Top D-Link Computers & Internet Experts

ExpressFiX
ExpressFiX

Level 2 Expert

691 Answers

k24674

Level 3 Expert

8093 Answers

Grand Canyon Tech
Grand Canyon Tech

Level 3 Expert

3867 Answers

Are you a D-Link Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...