Route all traffic over IPSEC tunnel

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Route all traffic over IPSEC tunnel

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Route all traffic over IPSEC tunnel
Route all traffic over IPSEC tunnel
2019-10-09 00:35:05 - last edited 2021-04-19 11:51:38
Model: TL-R600VPN  
Hardware Version: V4
Firmware Version: 4.0.3 Build 20190227 Rel.48206

I have two TL-R600vpn devices connected together between two sites. 

I can bring up an ipsec tunnel and communicate lan-to-lan. 

I am trying to figure out how to route all traffic through site A from site b and then out to the internet. 

So lan_site_B-->IPSEC--->site_A--->Site_A_ISP.  

 

Static routing does not allow for a route_all, 0.0.0.0/0, default route and policy routing does not allow for specifying ipsec tunnel or additional next hop.  Am i missing something on how to set a default route across IPSEC tunnel?

  0      
  0      
#1
Options
3 Reply
Re:Route all traffic over IPSEC tunnel
2019-10-09 10:05:25 - last edited 2021-04-19 11:51:38

@Jcckmc 

 

Unfortunately IPsec VPN cannot meet your requirements. Because it's based on local subnet and remote subnet. Only the data whose destination is remote subnet will be forwarded to VPN tunnel.

 

You need to use L2TP VPN, and set up dialup way as L2TP to connect L2TP VPN. Then the router will become L2TP VPN client. But unfortunately this way doesn't support encryption on TP-Link router. Cannot make sure the security.

  0  
  0  
#2
Options
Re:Route all traffic over IPSEC tunnel
2019-10-09 15:19:47 - last edited 2021-04-19 11:51:38

@Andone thank you for the reply!  I was suspecting this was the case.

  0  
  0  
#3
Options
Re:Route all traffic over IPSEC tunnel
2021-12-01 05:00:24

@Andone Wow! I wish the TP-Link support guys were this smart enough to answer my question. Wasted almost a week time trying to see how I can route all the traffic from site-b to site-a over

Andone wrote

@Jcckmc 

 

Unfortunately IPsec VPN cannot meet your requirements. Because it's based on local subnet and remote subnet. Only the data whose destination is remote subnet will be forwarded to VPN tunnel.

 

You need to use L2TP VPN, and set up dialup way as L2TP to connect L2TP VPN. Then the router will become L2TP VPN client. But unfortunately this way doesn't support encryption on TP-Link router. Cannot make sure the security.

IPSec VPN to access internet from the site-a ISP. I wish I knew this before that this is not possible in IPSec. Thanks for your help

  0  
  0  
#5
Options