Note: If your device/service supports SHA256 and DH group 14, it is recommended to use these settings instead.
Configuring the tunnel on the DrayTek Management Interface
-
Open the DrayTek management interface
-
In the left panel, select VPN and Remote Access, then select VPN Profiles. Select the add to create a new profile
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A50%3A12Z&se=2026-09-08T16%3A02%3A12Z&sr=c&sp=r&sig=o%2BgPyJWtGW2naq3yW7oWz3eBtj%2BYt8QA0vmp76JHczk%3D)
- Under the Basic tab, fill in the following information:
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A50%3A12Z&se=2026-09-08T16%3A02%3A12Z&sr=c&sp=r&sig=o%2BgPyJWtGW2naq3yW7oWz3eBtj%2BYt8QA0vmp76JHczk%3D)
- Auto Dial-Out: Enable; Always Dial-Out
- Dial-Out through: Your WAN interface; Default WAN IP
- Failover: Should remain with the null value.
- Local IP/Subnet Mask: Insert your FW external address and specify the correlating subnets.
- Remote Host: The IP of your NordLayer server with a dedicated IP
- Remote ID/Subnet Mask: The default values are 10.6.0.0 and 255.255.240.0/20
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A50%3A12Z&se=2026-09-08T16%3A02%3A12Z&sr=c&sp=r&sig=o%2BgPyJWtGW2naq3yW7oWz3eBtj%2BYt8QA0vmp76JHczk%3D)
- IKE Protocol: IKEv1 (IKEv2 recommended if your device supports it)
- IKE Phase 1: Main Mode
- Auth Type: PSK
- Pre-shared Key: Generate a pre-shared key (we will need this on our end as well)
- Security Protocol: ESP
- Fill in the following information in the Advanced section:
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A50%3A12Z&se=2026-09-08T16%3A02%3A12Z&sr=c&sp=r&sig=o%2BgPyJWtGW2naq3yW7oWz3eBtj%2BYt8QA0vmp76JHczk%3D)
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A50%3A12Z&se=2026-09-08T16%3A02%3A12Z&sr=c&sp=r&sig=o%2BgPyJWtGW2naq3yW7oWz3eBtj%2BYt8QA0vmp76JHczk%3D)
- Phase 1 Key Lifetime: 28800 seconds
- Phase 2 Key Lifetime: 3600 seconds
- Perfect Forward Secrecy Status: Enable
- DPD Status: Enable
- DPD Delay: 30 seconds
- DPD Timeout: 120 seconds
- Ping to Keep Alive: Disable
- Route/NAT Mode: Route
- Source IP: Auto-detect
- Apply NAT Policy: Disable
- Set VPN Default Gateway: Disable
- Netbios Naming Packet: Disable
- Multicast via VPN: Disable
- Rip via VPN: Disable
- Packet Triggered: Enable
- Force UDP Encapsulation: Disable
- Fill in the following information in the GRE section:
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A50%3A12Z&se=2026-09-08T16%3A02%3A12Z&sr=c&sp=r&sig=o%2BgPyJWtGW2naq3yW7oWz3eBtj%2BYt8QA0vmp76JHczk%3D)
- Enable GRE Function: Disable
- Auto Generate GRE Key: Enable
- Fill in with the following information in the Proposal section:
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A50%3A12Z&se=2026-09-08T16%3A02%3A12Z&sr=c&sp=r&sig=o%2BgPyJWtGW2naq3yW7oWz3eBtj%2BYt8QA0vmp76JHczk%3D)
- IKE Phase 1 Proposal: AES 256
- IKE Phase 1 Authentication: SHA1
- IKE Phase 2 Proposal: AWS 256 with auth
- IKE Phase 2 Authentication: SHA1
- Accepted Proposal: Acceptabove
- Leave the checkbox unmarked in the Multiple SAs section. Make sure to enable the profile and click Apply
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A50%3A12Z&se=2026-09-08T16%3A02%3A12Z&sr=c&sp=r&sig=o%2BgPyJWtGW2naq3yW7oWz3eBtj%2BYt8QA0vmp76JHczk%3D)
- If the tunnel is up, the profile will be green in the Connection Management tab:
.webp?sv=2026-02-06&spr=https&st=2026-09-08T15%3A50%3A12Z&se=2026-09-08T16%3A02%3A12Z&sr=c&sp=r&sig=o%2BgPyJWtGW2naq3yW7oWz3eBtj%2BYt8QA0vmp76JHczk%3D)
Ending note:
In order to finalize the site-to-site tunnel, please create a setup in Sites tab of the NordLayer Control Panel.
- Pre-shared key - you can generate it or we can provide it
- Encryption details (AES, SHA and DH group) - AES256, SHA256 and DH group 14 are recommended (also must support IKEv2)
- Remote gateway/router public IP (must be reachable while connected to the server with a dedicted IP)
- Remote subnet and mask (the subnet is used in your local network)
Note: In case you have any questions or issues, press 'Chat with support' at the bottom of the page.