- Router
Teleworker VPN - IPsec with XAuth - Vigor 3900
V. VPN (Virtual Private Networking)
The DrayTek routers that support Dial-In VPN connections can use any compatible VPN client to connect a remote dial-in user VPN to achieve secured access to the network connected to the router and its internet connection.
The DrayTek Vigor 2960 and Vigor 3900 routers with 1.3.0 firmware provide IPsec with XAuth authentication, which allows many standard IPsec VPN clients to authenticate with a username and password, creating a securely encrypted IPsec tunnel to the Vigor router with access to network resources and its Internet connection.
This article is broken down into three sections, with the tasks that are required for IPsec VPN dial-in user clients to connect using XAuth authentication:
| IPsec XAuth VPN Server Setup | Configure the router's IPsec VPN server for XAuth authentication |
| VPN Profile Setup | Configuration of VPN user profiles on the router |
| iOS VPN Client Configuration | Setup of a VPN profile on an Apple iOS device (iPad, iPhone) with the built-in VPN client |
IPsec XAuth VPN Server Setup
The DrayTek Vigor 2960 and Vigor 3900 routers are able to support IPsec using XAuth authentication from firmware version 1.3.0 onwards. It is necessary to update to this firmware version (or any later current firmware version) before proceeding.
To configure the Vigor router's IPsec server for dial-in users to connect with XAuth authentication, go to [VPN and Remote Access] > [Remote Access Control]:
- Ensure that Enable IPsec Service is ticked
- Set IPsec Remote Dial-In Service to DHCP over IPsec

Click Apply to apply the change to the router's VPN services.
Go to [VPN and Remote Access] > [IPsec General Setup] to configure the router's IPsec VPN server for dial-in users:
Set the IPsec User Preshared Key with a secure password, this Preshared key is shared between all users that will connect via XAuth authentication.
Click Apply to save and apply the change.

VPN / User Profile Setup
VPN profiles for the Vigor 2960 and 3900 routers are configured in the User Management section; each user profile can be configured to connect to a specified LAN / VLAN and allow dial-in VPN services on a per-user basis.

To set up the VPN profile on the router, go to [User Management] > [User Profile], click Add in the User Profile tab to create a new user profile.

- Enable the profile
- Enter a suitable Username, please note that this cannot be changed after creating the user account
- Set a secure Password
- Click on the IPsec User Setting bar to expand the VPN options for the profile
- Enable XAuth
Click Apply to save the changes to that profile. The router is now ready to accept client IPsec VPN connections with those credentials.
iOS Device VPN Client Configuration
Apple's iOS (used by iPad, iPhone and iPod Touch devices) has a built-in VPN client with support for IPsec encrypted VPN tunnels, this uses XAuth as the authentication method to allow dial-in users to connect with individual usernames and passwords.
On the Apple iPad / iPhone, open the Settings menu.

Go to the General menu and select VPN
Select Add VPN Configuration to create a new VPN profile
In the VPN profile, configure the following settings:

| Type |
IPSec |
| Description | Enter a name for the VPN profile |
| Server | Hostname or IP address of the VPN server router. In this example, the hostname is "london.company.vpn" |
| Account | Username of account configured in [User Management] > [User Profile] |
| Password | Password of account configured in [User Management] > [User Profile] |
| Use Certificate |
Leave this option disabled |
| Group Name |
Leave this field blank |
| Secret | Enter the IPsec User Pre-shared Key that is configured on the router under [VPN and Remote Access] > [IPsec General Setup] |
Press Done to save the VPN profile.
To establish the VPN tunnel, select the profile from the list in the VPN menu and toggle the Status option to establish the VPN tunnel.
Note that the iOS device must be connected to a different network so that the router is accessed over the Internet, the router's VPN server does not accept VPN connections on the LAN side.

When the VPN tunnel is established, press the "i" button to view the connection status:

The status of the VPN tunnel can be viewed from the router's web interface under [VPN and Remote Access] > [Connection Management].
How do you rate this article?
Add a comment to this article
NOTE : All comments are reviewed before publication and may not be posted or may be redacted if the editors do not consider them helpful. The use of offensive or obscene language, copyrighted material, or advertising or promotion or linking to any other product or service is prohibited. By submitting your comment, you confirm that you are the original author and assign copyright of the content to DrayTek indefinitely and irrevocably.
