How to Setup IPSec Tunnel (VPN) on TD-W8960N/TD-W8950ND/TD-W8968(V3 V4)

TD-W8968 , TD-W8950ND , TD-W8950N , TD-W8960N
Recent updates may have expanded access to feature(s) discussed in this FAQ. Visit your product's support page, select the correct hardware version for your device, and check either the Datasheet or the firmware section for the latest improvements added to your product. Please note that product availability varies by region, and certain models may not be available in your region.
This article illustrates a configuration instance for building an IPSec VPN tunnel between two units of TD-W8960N/TD-W8950ND/TD-W8968(V3).
IPSec tunnel is usually built to connect two or more remote LANs via Internet so that hosts in different remote LANs are able to communicate with each other as if they are all in the same LAN. For more details about VPN tunnel please refer to Wikipedia.
Figure 1 Configuration Instance
Here are step by step instructions for your reference (the following steps are based on Figure 1):
Configuration on Site A
1. Login to the management page of TD-W8960N/TD-W8950ND/TD-W8968(V3). If you are not sure how to enter the management page, please click here for details.
2. On the left menu of the management page, please click Advanced Setup and then click IPSec.
3. On the IPSec main page, please click Add New Connection.
4. On the IPSec configuration page, please do configuration as follows:
IPSec Connection Name: Define a name for this connection;
Remote IPSec Gateway Address: Input he WAN IP address of site B;
Site A
Tunnel access from local IP addresses: For a whole LAN please select Subnet; for a single host please select Single Address. In this instance we select Subnet;
IP Address for VPN: Input the LAN IP range of site A. In this instance, we should input 192.168.1.0;
IP Subnetmask: Input the LAN subnet mask of site A. In this instance, we should input 255.255.255.0;
Site B
Tunnel access from remote IP addresses: For a whole LAN please select Subnet; for a single host please select Single Address. In this instance we select Subnet;
IP Address for VPN: Input the LAN IP range of site B. In this instance, we should input 192.168.2.0;
IP Subnetmask: Input the LAN subnet mask of site B. In this instance, we should input 255.255.255.0;
5. Leave other settings as the default value and click Save/Apply.
Configuration on Site B
1. Log onto the management page of TD-W8960N/TD-W8950ND/TD-W8968(V3).
2. On the left menu of the management page, please click Advanced Setup and then click IPSec.
3. On the IPSec main page, please click Add New Connection.
4. On the IPSec configuration page, please do configuration as follows:
IPSec Connection Name: Define a name for this connection;
Remote IPSec Gateway Address: Input he WAN IP address of site B;
Site A
Tunnel access from local IP addresses: For a whole LAN please select Subnet; for a single host please select Single Address. In this instance we select Subnet;
IP Address for VPN: Input the LAN IP range of site B. In this instance, we should input 192.168.2.0;
IP Subnetmask: Input the LAN subnet mask of site B. In this instance, we should input 255.255.255.0;
Site B
Tunnel access from remote IP addresses: For a whole LAN please select Subnet; for a single host please select Single Address. In this instance we select Subnet;
IP Address for VPN: Input the LAN IP range of site A. In this instance, we should input 192.168.1.0;
IP Subnetmask: Input the LAN subnet mask of site A. In this instance, we should input 255.255.255.0;
5. Leave other settings as the default value and click Save/Apply.
Check the IPSec Connection
1. On the host in LAN1, press [Windows Logo] + [R] to open Run dialog. Input “cmd” and hit OK.
2. In the CLI window, type in “ping 192.168.2.x” (“192.168.2.x” can be IP address of any host in LAN2). Then press [Enter].
If Ping proceeds successfully (gets replies from host in LAN2), the IPSec connection must be working properly now.
Here until, all basic configuration required for an IPSec tunnel is completed. If one of the site has been off line for a while, for example, if Site A has been disconnected, on Site B you need to click Disable and then click Enable after Site A back on line in order to re-establish the IPSec tunnel.
If there are any further problems, please click here to contact TP-Link technical support.
Get to know more details of each function and configuration please go to Download Center to download the manual of your product.
Полезен ли беше този ЧЗВ?
Вашите отзиви помагат за подобряване на този сайт.
Какви проблеми открихте с тази статия?
- Недоволен от продукта
- Твърде сложно
- Объркващо заглавие
- Не се отнася за мен
- Твърде неясно
- Друга причина
Благодаря ти
Оценяваме вашето мнение.
This website uses cookies to improve website navigation, analyze online activities and have the best possible user experience on our website. You can object to the use of cookies at any time. You can find more information in our privacy policy .
This website uses cookies to improve website navigation, analyze online activities and have the best possible user experience on our website. You can object to the use of cookies at any time. You can find more information in our privacy policy .
Basic Cookies
These cookies are necessary for the website to function and cannot be deactivated in your systems.
TP-Link
accepted_local_switcher, tp_privacy_base, tp_privacy_marketing, tp_smb-select-product_scence, tp_smb-select-product_scenceSimple, tp_smb-select-product_userChoice, tp_smb-select-product_userChoiceSimple, tp_smb-select-product_userInfo, tp_smb-select-product_userInfoSimple, tp_top-banner, tp_popup-bottom, tp_popup-center, tp_popup-right-middle, tp_popup-right-bottom, tp_productCategoryType
Livechat
__livechat, __lc2_cid, __lc2_cst, __lc_cid, __lc_cst, CASID
Youtube
id, VISITOR_INFO1_LIVE, LOGIN_INFO, SIDCC, SAPISID, APISID, SSID, SID, YSC, __Secure-1PSID, __Secure-1PAPISID, __Secure-1PSIDCC, __Secure-3PSID, __Secure-3PAPISID, __Secure-3PSIDCC, 1P_JAR, AEC, NID, OTZ
Analysis and Marketing Cookies
Analysis cookies enable us to analyze your activities on our website in order to improve and adapt the functionality of our website.
The marketing cookies can be set through our website by our advertising partners in order to create a profile of your interests and to show you relevant advertisements on other websites.
Google Analytics & Google Tag Manager
_gid, _ga_<container-id>, _ga, _gat_gtag_<container-id>
Google Ads & DoubleClick
test_cookie, _gcl_au
Meta Pixel
_fbp
Crazy Egg
cebsp_, _ce.s, _ce.clock_data, _ce.clock_event, cebs
lidc, AnalyticsSyncHistory, UserMatchHistory, bcookie, li_sugr, ln_or