Настроил канал по
http://www.d-link.ru/ru/faq/92/520.html.
В итоге на DI-804HV вижу статус "конект", но из одной сети не идут пинги в другую.
на DFL-210
dmz_ip 172.17.100.254 IPAddress of interface dmz
dmznet 172.17.100.0/24 The network on interface dmz
lan_ip 192.168.0.151 IPAddress of interface lan
lannet 192.168.0.0/24 The network on interface lan
wan_dns1 0.0.0.0 Primary DNS server for interface wan
wan_dns2 0.0.0.0 Secondary DNS server for interface wan
wan_gw 192.168.110.100 Default gateway for interface wan
wan_ip 192.168.110.10 IPAddress of interface wan
wannet 255.255.255.0/24 The network on interface wan
Заводские настройки:(
1 drop_smb-all Drop lan lannet wan all-nets smb-all
2 allow_ping-outbound NAT lan lannet wan all-nets ping-outbound
3 allow_ftp-passthrough_av NAT lan lannet wan all-nets ftp-passthrough-av
4 allow_standard NAT lan lannet wan all-nets all_tcpudp )
Настройки из описания по ссылке:(
1 IPSec_to_lan Allow tunnel1 IPSec_remote_net lan lannet all_services
2 lan_to_IPSec Allow lan lannet tunnel1 IPSec_remote_net all_services )
IPSec_remote_endpoint 192.168.110.100
IPSec_remote_net 192.168.1.0/24
На DI-804HV
WAN 192,168,110,100
MASK 255.255.255.0
Gateway 192.168.110.10
VPN
Tunnel Name : tunnel1
local Subnet: 192.168.1.0
local mask: 255.255.255.0
remote subnet:192.168.0.0
remote mask: 255.255.255.0
remote gateway:192.168.110.10