Connect site to controller in another site

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Connect site to controller in another site

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Connect site to controller in another site
Connect site to controller in another site
2022-08-30 10:20:00
Model: ER605 (TL-R605)  
Hardware Version: V1
Firmware Version:

Good Morning,

 

I'm hoping someone might be able to assist here.

 

I am managing two sites remotely, both sites are connected via mobile data, so have CG-NAT.

 

There are two sites at the same location, one site contains the OC-200 controller.  I have established site to site VPNs from both remote sites to my own ER-605 and can access both from here.

 

What I'd like to achieve is to allow remote site 1 to access remote site 2 so that I can manage the devices in remote site 2 on the OC-200 in remote site 1

 

Given I have VPN connectivity to my own ER-605 for both of the remote sites, is there a way I can allow the two to talk via my ER-605?

 

I have tried static routes, configured one on each site to allow it to send data destined for the other via my ER-605.

 

Example

 

My network: 192.168.0.1/24

Remote Site 1: 192.168.3.0/24

Remote Site 2: 192.168.2.0/24

 

Both 1 and 2 can talk to my network and all devices are accessible from here, I configured a static route on site 1 to talk to site 2 via 192.168.0.1 and vice versa, but this doesn't work.

 

I'm guessing that my ER-605 is dropping the traffic, so my conclusion is I need to tell my devices when it receives data from 192.168.3.0/24 destined for 192.168.2.0/24, to send it via the VPN tunnel for site 2.  I don't even know if this is possible, but thought I would ask anyway!

 

Hoping for some creative ideas :)

 

Best

Chris

 

  0      
  0      
#1
Options
3 Reply
Re:Connect site to controller in another site
2022-08-31 07:16:24

  @Lasermatrix 

 

I can understand your requirement but the simple solution is just build another IPSec VPN between remote site 1 and remote site 2 directly.

 

If you want to use your own ER605 to let them communicate with each other, it will be more difficult and I will offer my suggestions, but I did not test these configurations:

 

1. On your own router and remote site 1, you need to build up two IPSec tunnels.

One is for 192.168.0.1/24<--> 192.168.3.0/24;

Another one is for 192.168.3.0/24<-->192.168.2.0/24

 

2. On your own router and remote site 2, you also need to build up two IPSec tunnels.

One is for 192.168.0.1/24<--> 192.168.2.0/24;

Another one is for 192.168.2.0/24<-->192.168.3.0/24

 

You cannot use Omada Controller to build these tunnels since on Controller, the local LAN can not be customized. It only allow you to choose the existing LAN network on this router. However like I mentioned before, on your own router you need to define 192.168.3.0/24 and 192.168.2.0/24 as local network also. (they are not your own router's LAN network, but when you set up IPSec in standalone you can just put in the subnet manually)

 

Again I did not test this, I just think it should work.

 

 

  0  
  0  
#2
Options
Re:Connect site to controller in another site
2022-08-31 07:37:28

  @Somnus Thanks for your input :)

 

I would normally do a site to site between them, but because they are both connected to the mobile network, they have CG-NAT in front of them.

 

I will give your other idea a go, thank you :)

 

 

 

  0  
  0  
#3
Options
Re:Connect site to controller in another site
2022-08-31 21:53:45

  @Somnus Thanks a lot, u've helped me too!

  0  
  0  
#4
Options