Orbi WiFi 7 RBE973
Reply

fvs318 v1 vpn inactive

tony-g
Aspirant

fvs318 v1 vpn inactive

I have two netgear FVS318 vpns (both version 1) and I'm having a hard time getting them to connect together. Under vpn status I always get 'inactive'. I just want to be sure: does inactive mean they are not connected? or does it just mean they could be connected but there's no traffice between them (yet)? I don't have any devices pluigged into the vpns at either end. thanks for any help.

Model: FVS318|Cable/DSL ProSafe VPN Firewall with 8-port switch
Message 1 of 8
JohnC_V
NETGEAR Moderator

Re: fvs318 v1 vpn inactive

@tony-g,

 

Inactive means that the VPN service is disabled. Kindly check if the VPN policy on both routers is enabled and not disabled.

 

Regards,

 

John

NETGEAR Community Team

Message 2 of 8
tony-g
Aspirant

Re: fvs318 v1 vpn inactive

thankyou for yor response however this is v1 device and I don't recall seeing the setting you speak of.

where would I go in the web interface to see if VPN policy is enabled?

Model: FVS318|Cable/DSL ProSafe VPN Firewall with 8-port switch
Message 3 of 8
JohnC_V
NETGEAR Moderator

Re: fvs318 v1 vpn inactive

@tony-g,

 

I see. My apologies for that. May I know if both routers are in the same location? Please make sure that the LAN address on both routers is not on the same subnet. You can also try to set up a pc to the other router and do a ping test so that we may know if something is missing here.

 

Regards,

 

John

NETGEAR Community Team

Message 4 of 8
tony-g
Aspirant

Re: fvs318 v1 vpn inactive

thankyou john following what you say I am trying to connect a windows pc running shrewsoft vpn client to the netgear fvs318 but it fails.

the vpn log shows this:

Sun, 02/14/2021 18:51:58 - FVS318 IPsec:Receive Packet address:0x1397554 from <pc-public-ip-address>
Sun, 02/14/2021 18:51:58 - FVS318 IKE:Peer Initialized IKE Main Mode
Sun, 02/14/2021 18:51:58 - FVS318 IKE:[<FVS318-machine>] RX << MM_I1 : <pc-public-ip-address>
Sun, 02/14/2021 18:51:58 - FVS318 IPsec:New State index:3, sno:48
Sun, 02/14/2021 18:51:58 - FVS318 IPsec:responding to Main Mode
Sun, 02/14/2021 18:51:58 - FVS318 IPsec:loglog[3] invalid value 14 for attribute OAKLEY_GROUP_DESCRIPTION in Oakley Transform

 

I searched google but I don't know what that last line means  invalid value 14 for attribute OAKLEY_GROUP_DESCRIPTION in Oakley Transform

 

I've watched the shrewsoft pc in wireshark while trying to connect and there's never any response from the fvs318 machine, and yet the log shows it is receiving something from the shrewsoft pc.

thanks if you can shed light

Model: FVS318|Cable/DSL ProSafe VPN Firewall with 8-port switch
Message 5 of 8
JohnC_V
NETGEAR Moderator

Re: fvs318 v1 vpn inactive

@tony-g,

 

My apologies. I think we are not on the same page. I thought you are creating a VPN box-to-box connection because you said on your first thread that you do have 2 FVS318s that can't connect to each other. Now, you are using a shrewsoft VPN client which is for client-to-box connection. May I know what do you want to achieve here? If it is a client-to-box connection you may follow this article.

 

Regards,

 

John

NETGEAR Community Team

Message 6 of 8
tony-g
Aspirant

Re: fvs318 v1 vpn inactive

your are correct I am trying to achieve a gateway-to-gateway connection using two fvs318 boxes, both v1. thanks

Message 7 of 8
JohnC_V
NETGEAR Moderator

Re: fvs318 v1 vpn inactive

@tony-g,

 

Please try to re-create both VPN firewalls and make sure that the credentials on both sides should match and it should be running on the same/latest firmware version.

 

Regards,

 

John

NETGEAR Community Team

Message 8 of 8
Top Contributors
Discussion stats
  • 7 replies
  • 1341 views
  • 0 kudos
  • 2 in conversation
Announcements