How to Troubleshoot Site-to-Site IPSec VPN w/ ER605s

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

How to Troubleshoot Site-to-Site IPSec VPN w/ ER605s

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
How to Troubleshoot Site-to-Site IPSec VPN w/ ER605s
How to Troubleshoot Site-to-Site IPSec VPN w/ ER605s
2022-12-07 22:44:37
Tags: #VPN
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.0.1 Build 20220223 Rel.68551

Goal: setup 4 branch offices to home office with site-to-site VPN.

 

Initially, I was able to get Auto IPSec VPN setup between home office and 1st branch router. Then tried to setup 2nd branch router and got an error claiming overlapping subnets although each branch router's local subnet is unique. Read here on the form to setup manual IPSec VPNs to overcome "overlap" subnet error. Followed step-by-step instructions for manual site-to-site IPSec w/ IKEv2 but no VPN tunnels were formed (checking Settings > Insight > VPN Status shows "No VPN seesions found." 

 

Deleted and tried IKEv1 steps and still no VPN. Rebooted controller and all routers, then tried Auto VPN again and still no VPN. No messages in logs either. 

 

How are we supposed to troubleshoot these cases if nothing is reported in the logs?

  0      
  0      
#1
Options
2 Reply
Re:How to Troubleshoot Site-to-Site IPSec VPN w/ ER605s
2022-12-07 22:50:35

  @GoPokes1 slight correction: logs DID show overlap subnet error on initial auto IPSec attempt to add 2nd router.

But after deleteing auto VPN there were no other logs pertaining to 'VPN' or 'IPSec' 

  0  
  0  
#2
Options
Re:How to Troubleshoot Site-to-Site IPSec VPN w/ ER605s
2022-12-09 05:24:32

  @GoPokes1 

Do you have public IP on both router's WAN?

 

If you have NAT in front of tp-link router, you will need to do port forwarding 500/4500 for the tp-link router WAN IP.

  0  
  0  
#3
Options