What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

BE-98G - need help setting up a site-to-site VPN

nsayer

New Around Here
This is a little complicated. I've got two houses and they've been linked with Synology routers using their site-to-site IPsec VPN. And that's been fine up to now except for two things:

1. Synology seems to be exiting the router business. They have no roadmap for multiple multi-gig port routers or WiFi7, so I think they're fired.
2. One of the houses is about to get 2G symmetrical fiber. Well, it'd be kind of dumb to plug a 2G capable ONT into a 2.5GE port on the Synology only to have 1GB on the LAN side or vice versa.

So I bought a BE-98Pro specifically because the Internet made me think it could do a site-to-site IPsec VPN and it has 10GE ports for both LAN and WAN. I absolutely don't need any of the gaming stuff. But I saw no other way to get s2s VPN and 10GE WAN and LAN (and mesh WiFi7 as well).

Well, it turns out they want to you to use Wireguard and Synology doesn't support that. Oops.

Ok, so my choices are

1. Return the BE98 and get something else (what?).
2. Figure out if there's a way - perhaps at the command line - to get an IPsec site-to-site VPN set up with the synology at the other end (at least for now. When I get back to the other place - 2000 miles away - I can swap that one out for a BE98 and switch to wireguard maybe - I am not absolutely wedded to IPsec. I just want it to work).
3. Figure out if there's a way to connect the BE98 via wireguard to a Raspberry Pi inside the firewall at the other end. Forwarding the wireguard traffic doesn't sound hard, but what sounds like it may be complex is that suddenly that premises will have to have a routing table of some sort, and that sounds rather grotesque.

The desired goal is that any device on either LAN can transparently see any other device on the other LAN (don't want to pass broadcast traffic - that gives HomeKit fits).

Thanks in advance for any ideas.
 
I may have gotten past this... I have successfully moved the s2s VPN functionality to a pair of Raspberry PIs at each premises, so I should be able to just magically upgrade the router without having to care too much about this. The only negative thing I see at the moment is that when I try to ping the other premises I get ICMP redirect messages from the router trying to smack the host(s) around, so it's sort of routing-by-error-message, I guess.

I assume that the WG implementation built in to the BE98 is interoperable with the Pi one, so I may be able to move the local endpoint into the router, which would be useful since neither of the pis has multi-gig Ethernet (though that doesn't matter much for the remote house today).
 
I have Site-to-Site VPN between two UniFi Cloud Gateways physically located 6200km from each other. It's a Site Manager feature called Site Magic SD-WAN. In my case the units are UCG-Ultra for $129 with Gigabit ports. The model with 2.5GbE ports is UCG-Max for $199. I can't test the maximum speed between the sites due to ISP restrictions, but someone online reported ~600Mbps.
 
Last edited:

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top