Your location: Your IP: Your status:ProtectedUnprotected · To the tests »

How to set up IPsec (IKEv2) VPN on a DrayTek v2960/v3900 router

On our page with information regarding IPsec choose the VPN server, to which you want to establish the VPN connection (e.g. "").

The router should have an active WAN connection.

The time and date settings should be valid and match the current time and date.

Go to the Certificate ManagementTrusted CA Certificate page and click on Upload.

Then select the CA certificate file perfect-privacy_ipsec_ca.crt from the downloaded and unpacked archive and upload it to the router.

After a successful upload the certificate appears in the overview.

The creation of the profile is done under VPN and Remote AccessVPN ProfilesIPsec. By clicking on Add the window to create a new VPN profile opens.

In the tab Basics make the following settings:

  • Enable makes sure the VPN profile is used
  • Dial-Out Through defines the WAN interface to use
  • By LocalIP / Subnet Mask the LAN network which gets to use the VPN is set
  • At Remote Host the server which should be used for the VPN has to be entered
  • As Remote IP / Subnet Mask set and
  • The IKE Protocol has to be set to IKEv2_EAP
  • At Username and Password enter your Perfect Privacy credentials

One more adjustment has to be made in the Advanced tab. The option Set VPN as Default Gateway has to be set to Enable.

Some more settings have to be made in the Proposal tab:

  • IKE Phase1 Proposal [Dial-Out]: AES256 G14
  • IKE Phase2 Proposal [Dial-Out]: AES256 with auth

After all settings have been confirmed the new profile is shown in the overview.

When the tunnel is successfully established it is shown in the Connection Management.

This website uses cookies to analyze the traffic and to control our advertising. By using this site, you agree to the use of cookies. More information can be found in our privacy policy.