Friday, June 21, 2013

How to Configure IPSec Tunnel (VPN) on TP-LINK TD-W8960N/TD-W8950ND

This article illustrates a configuration instance for building an IPSec VPN tunnel between two units of TD-W8960N/TD-W8950ND.

If you have only one unit and you want to setup a client to site VPN connection. This FAQ is not available for you and the TD-W8950ND/TD-W8960N has no such function to meet your need. They can´t work as a VPN server.
IPSec tunnel is usually built to connect two or more remote LANs via Internet so that hosts in different remote LANs are able to communicate with each other as if they are all in the same LAN. For more details about VPN tunnel please refer to Wikipedia.

Figure 1 Configuration Instance

Here are step by step instructions for your reference (the following steps are based on Figure 1): 

Configuration on Site A

1.    Login to the management page of TD-W8960N/TD-W8950ND. If you are not sure how to enter the management page, please click here for details.

2.    On the left menu of the management page, please click Advanced Setup and then click IPSec.



3.    On the IPSec main page, please click Add New Connection.


4.    On the IPSec configuration page, please do configuration as follows:



IPSec Connection Name: Define a name for this connection;

Remote IPSec Gateway Address: Input he WAN IP address of site B;
Site A

Tunnel access from local IP addresses: For a whole LAN please select Subnet; for a single host please select Single Address. In this instance we select Subnet;

IP Address for VPN: Input the LAN IP range of site A. In this instance, we should input 192.168.1.0;

IP Subnetmask: Input the LAN subnet mask of site A. In this instance, we should input 255.255.255.0;

Site B

Tunnel access from remote IP addresses: For a whole LAN please select Subnet; for a single host please select Single Address. In this instance we select Subnet;

IP Address for VPN: Input the LAN IP range of site B. In this instance, we should input 192.168.2.0;

IP Subnetmask: Input the LAN subnet mask of site B. In this instance, we should input 255.255.255.0;

5.    Leave other settings as the default value and click Save/Apply.

Configuration on Site B

1.    Log onto the management page of TD-W8960N/TD-W8950ND.

2.    On the left menu of the management page, please click Advanced Setup and then click IPSec.

3.    On the IPSec main page, please click Add New Connection.

4.    On the IPSec configuration page, please do configuration as follows:


IPSec Connection Name: Define a name for this connection;
Remote IPSec Gateway Address: Input he WAN IP address of site B;

Site A

Tunnel access from local IP addresses: For a whole LAN please select Subnet; for a single host please select Single Address. In this instance we select Subnet;

IP Address for VPN: Input the LAN IP range of site B. In this instance, we should input 192.168.2.0;

IP Subnetmask: Input the LAN subnet mask of site B. In this instance, we should input 255.255.255.0;

Site B

Tunnel access from remote IP addresses: For a whole LAN please select Subnet; for a single host please select Single Address. In this instance we select Subnet;

IP Address for VPN:
Input the LAN IP range of site A. In this instance, we should input 192.168.1.0;

IP Subnetmask:
Input the LAN subnet mask of site A. In this instance, we should input 255.255.255.0;

5. Leave other settings as the default value and click Save/Apply.

Check the IPSec Connection

1. On the host in LAN1, press [Windows Logo] + [R] to open Run dialog. Input “cmd” and hit OK.


2. In the CLI window, type in “ping 192.168.2.x” (“192.168.2.x” can be IP address of any host in LAN2). Then press [Enter].


If Ping proceeds successfully (gets replies from host in LAN2), the IPSec connection must be working properly now.

Here until, all basic configuration required for an IPSec tunnel is completed. If one of the site has been off line for a while, for example, if Site A has been disconnected, on Site B you need to click Disable and then click Enable after Site A back on line in order to re-establish the IPSec tunnel.

If there are any further problems, please click here to contact TP-LINK technical support.

How To configure TL-WA5110G/TL-WA5210G to wireless AP Client Router mode

Step 1
Connect your computer to TL-WA5110G/TL-WA5210G with a LAN cable and log into the Web-based Utility by entering the IP address192.168.1.254 into Web Browser.
 
 
Step 2
Configure the operation mode to AP Client Router and connect to the wireless network.
  
1. Click on Operation mode on the left, select AP Client Router, then click on Save.
 
 
  
2. Click on Wireless -> Wireless Mode on the left side, select Client.(In that page, only Client mode is available)



3. Click on Survey/Search button to view the available wireless networks.





Connect to the root WIFI Network.




After click on Connect button, the SSID and the MAC address of the root router/AP will be shown in the Client mode box automatically.
Or if you know the SSID or the MAC address of the root router/AP, you can type them in the SSID or MAC of AP box manually, and then Click on Save to save the settings
 
3. Click on Save.
 
Step 3
 
Click Network->WAN. Then select the correct type for WAN Connection Type. If you are not sure about the WAN Connection type, please contact your service provider about this.
 
For Dynamic IP: You just need to select Dynamic IP from the drop-down menu and then click on Save.
 
For Static IP: Please select Static IP from the drop-down menu, and input the correct parameters in the boxes. The parameters are given by your internet service provider (ISP). Then click on Save
 

For PPPOE: Please select PPPOE from the drop-down menu, and input the correct parameters (Username and Password) in the boxes. The parameters are given by your service provider. Then click Save.
 
 
Step 4
Click Security settings. Select the same security settings as the network you want to connect. Click Save and reboot the device.
WEP.
 
  
Or WPA-PSK/WPA2-PSK
 
 

Step 5
After the configuration, please refer to the link in Step 1 again to change the IP address of your computer back to Obtain IP address automatically.

NOTE: Just in case, if the IP address of the root router/AP is 192.168.1.254 as well, you will need to change the IP address of TP-LINK device to avoid IP conflict. You can do it as follows:


1.     Click Network->LAN on the left side.
2.     Change the IP Address to 192.168.2.254.
 
 
 3.     Click on save, and reboot your device.