I suggest you provide more details, honestly I can't clearly understand what you are trying to do. However, I can provide some highlights. For client to LAN (you connect from outside your network to your vpn Gateway behind your ISP modem), you should forward ports 1701, 500, 4500 UDP to the IP of your VPN gateway (WAN PORT IP). Then you configure your vpn gateway device as per the link below. Also, on your VPN gateway (R600), choose the menu Transmission > NAT > Virtual Servers and add those ports 1701, 500 and 4500 UDP with the local ip of the VPN server you configured in menu VPN > Users > Users. Please try first to test the client to LAN as its simple and easy to troubleshoot, then follow the rest of the document on how to configure LAN-to-LAN. https://www.tp-link.com/us/configuration-guides/configuration_guide_for_vpn/?configurationId=2981#_idTextAnchor007