Your location: Your IP: Your status:ProtectedUnprotected · To the tests »

How to set up VPN on a DrayTek Vigor Router

On our page with information regarding IPsec choose the VPN server, to which you want to establish the VPN connection (e.g. "").

Go to the settings of the DrayTek Vigor router and then go to the Certificate ManagementTrusted CA Certificate page and click the Import button.

Click Choose File to select the CA certificate file perfect-privacy_ipsec_ca.crt from the downloaded and unpacked archive, then click Import.

Wait for a few seconds. The Vigor router will respond “Import Success” and you can see the Certificate Status is OK.

Go to VPN and Remote AccessIPsec Peer Identity page, edit a profile to add an "identity profile" for Perfect Privacy server. Click Enable this account and select Accept Any Peer ID.

Go to VPN and Remote AccessLAN to LAN, click on an available "index" number and edit the profile as follows:
a. In Common Settings:

  • Give the profile a name and activate Enable this profile
  • Set Call Direction to Dial-Out
  • Select the WAN interface that the VPN will Dial-Out through

b. In Dial-Out Settings:

  • Select IPsec EAP as the "VPN server type"
  • Enter the VPN server IP address/ Hostname of the previously selected VPN server
  • Enter the Username and Password (of your Perfect Privacy account)
  • Choose Digital Signature and select the previously created"IPsec Peer Identity Profile"
  • As "IPsec Security Method" select High (ESP) and AES with Authentication

Click the Advanced button for configuring advanced IKE/ IPsec Settings and configure:

  • IKE phase 1 proposal: AES256_SHA1_G14
  • IKE phase 2 proposal: AES256_SHA1
  • IKE phase 1 key lifetime: 3600
  • IKE phase 2 key lifetime: 1200

c. In TCP/IP Network Settings:

  • Remote Network IP /Mask:
  • Select NAT for this VPN connection
  • Enable the Change Default Route to this VPN tunnel option if you want all traffic to be routed to the Perfect Privacy VPN server

After finishing above settings, you can check the VPN status via the VPN-Status via VPN and Remote AccessConnection Management page.

You can optionally create a Policy Route via RoutingLoad-Balance/Route Policy to define only specific traffic to be routed through the Perfect Privacy-VPN tunnel.

You can verify that the VPN connection works correctly by visiting our Check IP website on any device connected via the router.

This website uses cookies to analyze the traffic and to control our advertising. By using this site, you agree to the use of cookies. More information can be found in our privacy policy.