ER-605 how to give L2TP client access to network at remote end of IPsec Lan-to-Lan tunnel?

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

ER-605 how to give L2TP client access to network at remote end of IPsec Lan-to-Lan tunnel?

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
ER-605 how to give L2TP client access to network at remote end of IPsec Lan-to-Lan tunnel?
ER-605 how to give L2TP client access to network at remote end of IPsec Lan-to-Lan tunnel?
2021-12-14 17:00:08
Model: ER605 (TL-R605)  
Hardware Version: V1
Firmware Version: 1.1.1

Requirement:  To gain access over an L2TP client tunnel to an ER-605's LAN, and also to a remote n/w via the ER-605 over an IPsec tunnel.

Both tunnels are working well individually.

- The IPsec Lan to Lan SA went in very easily (with a DrayTek at the far end).
- I have (finally) configured the L2TP client VPN, having realised that it depended on the client using the VPN as default gateway to work.  (As there is no route on the client from the VPN client pool n/w to the remote LAN).  But that issue is by-the-by, except that the issue I now have might be related...
So now...
I would like to give the L2TP clients access to the remote network at the end of the IPsec tunnel, but cannot find a way to do this. I've tried putting in a route manually on the client, giving the router's LAN address as gateway for the remote network, but that doesn't work because there is no route on the client to the LAN n/w - it depends on the VPN tunnel being the default gateway to reach the ER-605's LAN.
No static route should be necessary on the router either, because it already knows about the IPsec tunnel and the n/w at the end of it, and routes local LAN traffic there just fine.

--

I'l give some example IPs to illustrate (all n/w are class C):

L2TP setup:

Client PC (192.168.1.100 /24) - router <-L2TP tunnel-> VPN pool n/w 192.168.10.100 /24 - ER-605 - LAN 192.168.17.0 /24

IPsec setup

LAN 192.168.17.0 /24 - ER-605  <-IPsec tunnel-> DrayTek - LAN 192.168.19.0 /24

So in short, I want the client above to access the DrayTek's LAN n/w.  

--

Any clues as to how?  TIA

  0      
  0      
#1
Options
1 Reply
Re:ER-605 how to give L2TP client access to network at remote end of IPsec Lan-to-Lan tunnel?
2021-12-15 09:01:26

@Simon1963 

 

Here is a similar thread maybe can help you: https://community.tp-link.com/en/business/forum/topic/275302

Just striving to develop myself while helping others.
  0  
  0  
#2
Options