Setting up Shrewsoft client VPN with DNA

Scope

This article discusses how to work with Windows VPN with Datto's DNA using the Shrewsoft client.

Prerequisites:

  • The DNA must be the edge router and not behind another router. Using Windows VPN may not work if the DNA is behind another router.
  • You must have the Shrewsoft client installed to use Windows VPN with the DNA. Access the downloads here: https://www.shrew.net/download/vpn
    Note: for Windows 10, use version 2.2.2-release
    For all installs, use the Standard version.

ShrewSoft1Capture.PNG

Getting Started

To configure Windows VPN:

  1. Launch the ShrewSoft application. It may appear as "VPN Access Manager."

  2. Click the Add button.

    shrewsoft.jpg

  3. Choose the General Tab and enter the following information
    1. Under "Host Name or IP Address" input the "ASSIGNED PUBLIC ADDRESS". This is found under the Router Details in the DNA Web UI under Network Overview.
    2. Make sure Port is set to "500"
    3. Make sure Auto Configuration is set to "ike config pull"
    4. From the Adapter Mode drop-down menu, select "Use virtual adapter and assigned address."

      VPN1.png

  4. Click "Add" on the Access Manager’s page. Then click Authentication Tab and then choose the Credentials subtab.
    1. For "Authentication Method" Choose "Mutual PSK + XAuth"
    2. Now Click Credentials and under "Pre Shared Key" Enter the Authentication "Shared Secret key" from the Client VPN card in the DNA UI under the Security section.

      VPN2.png

  5. Click the Phase 1 tab
    1. Set the Exchange type to "Main."
    2. Set DH Exchange to "group 2."

      VPN3.png

  6. Lastly, choose the Policy tab.
    1. Set the Policy Generation Level to “Unique.”
    2. Deselect the Obtain Topology Automatically or Tunnel All checkbox.
    3. Click the Add button and then type the Subnet and Netmask of the Network(s) you would like to connect to. This will be found under the LAN settings in the DNA.
    4. Once this is done click Ok and Save.

VPN4.png