What's new

Instant Guard or IPSEC VPN can't connect from outside

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

fearz

Senior Member
Hi,

AC5300 using latest Merlin firmware, Instant Guard or IPSEC VPN works perfectly from within the network internally, but never from external, always says VPN server can't breached or not responding...if i enable WIFI, it connects instantly...

What maybe wrong?

Remote access is enabled and working BUT only on port 80, if i use secured connection port 8443 on the official iOS Asus App....it won't connect..

I'm suspecting something wrong with Secured connectivity to my router...

i'm using DDNS also DOT using servers 1.1.1.1 and 1.0.0.1

Any help please?
 
hi i need help. i am not sure what i have did but ipsec server / instant Guard stopped working. the log shows the following. hope this helps:
added configuration 'Host-to-Netv2'
Sep 6 17:06:39 06[CFG] received stroke: delete connection 'Host-to-Net'
Sep 6 17:06:39 06[CFG] deleted connection 'Host-to-Net'
Sep 6 17:06:39 08[CFG] received stroke: delete connection 'Host-to-Netv2'
Sep 6 17:06:39 08[CFG] deleted connection 'Host-to-Netv2'
Sep 6 17:06:39 05[CFG] received stroke: add connection 'Host-to-Net'
Sep 6 17:06:39 05[CFG] reusing virtual IP address pool 10.10.10.0/24
Sep 6 17:06:39 05[CFG] added configuration 'Host-to-Net'
Sep 6 17:06:39 07[CFG] received stroke: add connection 'Host-to-Netv2'
Sep 6 17:06:39 07[CFG] reusing virtual IP address pool 10.10.10.0/24
Sep 6 17:06:39 07[CFG] loaded certificate "C=TW, O=ASUS, CN=ranshome.asuscomm.com" from 'svrCert.pem'
Sep 6 17:06:39 07[CFG] added configuration 'Host-to-Netv2
 
Have you followed the official Asus FAQ here? it uses IKEv1. Instant Guard is IPSec under the hood to simplify the process that mask some complexity for the end user:

If you are interested to consider to use IPsec with IKEv2, see my old post(s) here:

I have OpenVPN, IPsec (IKEv1 and IKEv2), Instant Guard Server(s) setup on my Asus RT-AX88U

PS:
  • If you setup Instant Guard first, it will generate a cryptic pre-shared-key, However, if you setup IPSec Server first, you can specify your own pre-shared-key, and when you subsequently setup Instant Guard, it will honour and use this pre-shared-key.
  • Once in a while (rarely) Instant Guard on iOS fail to connect when I am in remote network or cellular. My workaround is to start Instant Guard inside my home network (including, if I am outside, I establish OpenVPN connection, to get my iPhone into Home Network), it will somehow sort it out. After that when I reconnect on a remote network or cellular it usually works again.
Hope it is useful
 
I did follow the faqs and the instructions and can’t get it to work.
it used to be such an easy setup and worked on the first try.
do you know what’s the error I sent means? “Received stroke”
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top