Document
How to configure IPSec VPN on 3G/4G Wireless Router TL-MR3420 (new logo)

How to configure IPSec VPN on 3G/4G Wireless Router TL-MR3420 (new logo)

With IPSec VPN, you can access the network securely when out of home. To use the VPN Service, you need to configure Dynamic DNS Service or assign a st

Related articles

VMware Cloud Foundation Cloud Models for a Tailored IT Strategy Connecting from FortiClient VPN client 10 Cloud Storage Security Issues, Risks & Solutions 2024 VPN Not Connecting? 11 Possible Causes (With Fixes) in 2024 How to create Telegram unlimited cloud storage?

With IPSec VPN, you can access the network securely when out of home. To use the VPN Service, you need to configure Dynamic DNS Service or assign a static IP address for the router’s WAN port. And the System Time should be synchronized with the internet.

Note: TL-MR3420_V5 is used for demonstration in this article.

1 . visit http://tplinkwifi.net , and log in with the password you set for the router . For detail , please refer toHow to log in to the web – base interface of Wi – Fi Routers ( new logo ) ?

2. Go to Advanced > VPN > IPSec VPN.

3 . enable dead Peer detection .

4 . click Add and enter correspond parameter .

How to configure IPSec VPN on 3G/4G Wireless Router TL-MR3420 (new logo)

• IPSec Connection Name: Enter a name for the IPSec VPN connection.

• Remote IPSec Gateway (URL): Enter the destination gateway IP address which is the public WAN IP or domain name of the remote VPN server endpoint.

• Tunnel access from local ip address : Select Subnet Address if you want the whole LAN to join the VPN network , or select Single Address if you want a single IP to join the VPN network .

• IP Address for VPN: Enter the IP address of your LAN.

• Subnet Mask: Enter the subnet mask of your LAN.

• Tunnel access from remote IP addresses: Select Subnet Address if you want the whole remote LAN to join the VPN network, or select Single Address if you want a single IP to join the VPN network.

• IP Address for VPN: Enter the IP address of the remote LAN.

• IP Subnet Mask: Enter the subnet mask of the remote LAN.

• Key Exchange Method: Select Auto (IKE) or Manual to be used to authenticate IPSec peers.

• Authentication Method: Select Pre-Shared Key (recommended).

• Pre-Shared Key: Create a pre-shared key to be used for authentication.

• Perfect Forward Secrecy : Select Enable or disable as an additional security protocol for the pre – shared key .

You can configure the advanced settings as needed. It’s recommended to keep the default values. If you want to change these settings, make sure that both VPN server endpoints use the same Encryption Algorithm, Integrity Algorithm, Diffie-Hellman Group and Key Lifetime in both phase1 and phase2.

5. Click Save.

Get to know more detail of each function and configuration please go to Download Center to download the manual of your product .

Is this faq useful?

Your feedback helps improve this site.

What ’s your concern is ’s with this article ?

  • Dissatisfied with product
  • Too complicated
  • Confusing Title
  • Does not apply to me
  • Too Vague
  • Other

We ‘d love to get your feedback , please let us know how we can improve this content .

Thank you

We is appreciate appreciate your feedback .
click here to contact TP – Link technical support .