Since firmware version 3.9.6.1, Vigor Router supports dialing out an IKEv2 EAP VPN tunnel to NordVPN server. This article introduces how to create IKEv2 EAP VPN tunnel from Vigor Router to NordVPN server in this document.
Note: Vigor2960/3900 support it since v1.5.0
1. You will need a NordVPN account and download the NordVPN root CA certificate from https://downloads.nordvpn.com/certificates/root.der
And copy Service Credentials in NordVPN.
2. Get the NordVPN server domain from https://nordvpn.com/servers/
You may get a recommended server by selecting the country you located. In the following picture, de241.nordvpn.com
is the hostname of the VPN server.
3. Log into the router's management page. Go to Certificate Management >> Trusted CA Certificate page, and click IMPORT. Click Choose File to select the root.der file we downloaded in step 1. Then, click Import.
4. Wait for few seconds until the router responds “Import Success” and the Certificate Status shows OK
5. Go to VPN and Remote Access >> IPsec Peer Identity, edit a profile to for NordVPN server.
6. Go to VPN and Remote Access >> LAN to LAN, click on an available index number, and edit the profile as follows. In Common Settings,
7. In Dial-Out Settings,
8. Click Advanced button, In the IKE advanced settings pop-up windows, confgure:
9. Click OK o close the window. At TCP/IP Network Settings:
10. After finishing above settings, we can check the VPN status via VPN and Remote Access >> Connection Management page.
11. Go to Routing >> Load-Balance/Route Policy and set up a route policy to send all traffic to NordVPN.
12. We can use the command “tracert” to check if the traffic is going through the VPN tunnel correctly.
Note: In order to accept large packets from NordVPN, Allow pass inbound fragmented large packets (required for certain games and streaming) should be enabled.
1. You will need a NordVPN account and download the NordVPN root CA certificate from https://downloads.nordvpn.com/certificates/root.der
And copy Service Credentials in NordVPN.
2. Get the NordVPN server domain from https://nordvpn.com/servers/
You may get a recommended server by selecting the country you are located in. The following picture, tw51.nordvpn.com is the hostname of the VPN server.
3. Now, On the Router. Go to Certificate Management>>Trusted CA Certificate page, click upload, and select Local Certificate. Click Choose file to select the root.der file which we download from Step1. After uploading the file, you can see the status shows ok.
4. VPN and Remote Access >> VPN profile>>IPsec, and click Add, configure the settings at basic page.
5. Switch to Advanced page, set phase1 key lifetime to 14400, phase2 key lifetime to 3600, and enable Set VPN as Default Gateway
6. Switch to Proposal Page.
7. Go to VPN and Remote Access>>Connection Management.
You can check the status of the VPN porfile.
Published On: 2020-06-04
Was this helpful?