VPN connection between two routers ER8411 and ER7206 via omada

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

VPN connection between two routers ER8411 and ER7206 via omada

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
36 Reply
Re:VPN connection between two routers ER8411 and ER7206 via omada
2023-04-24 17:12:34

  @test01 

 

Ok, I believe the issue is that IPSEC site-site only works when both endpoints have a public static IP, and yours don't:

 

 

 

Those 192.68.73.0/24 addresses are not publicly routable.

 

Not the end of the world, you just need to move a Client-Server setup instead, and make the client end the one with the (private or NAT'd) WAN IP of 192.168.73.2

 

I recently posted my config for this kind of setup here:

https://community.tp-link.com/en/business/forum/topic/606882?replyId=1201196

 

Alternatively, change the modem to remove the NAT function and just pass the public static IP through to the TPlink router.

<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#24
Options
Re:VPN connection between two routers ER8411 and ER7206 via omada
2023-04-24 17:19:10

  @d0ugmac1 the 2 public addresses are static.  There is a NAT but we don't want it disabled.  The VPN configuration between two ER7206 routers works perfectly.  it is only between the 8411 and 7206 that it does not work.

  0  
  0  
#25
Options
Re:VPN connection between two routers ER8411 and ER7206 via omada
2023-04-24 17:23:15
So are you port forwarding or DMZ'ing? I think the VPN definitions at either end should be done with both public IPs.
<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#26
Options
Re:VPN connection between two routers ER8411 and ER7206 via omada-Solution
2023-04-24 17:31:46 - last edited 2023-04-25 12:38:21

  @test01 

 

just a small comment, have you configured OpenVPN or SSL VPN on the ER8411? if you have it, IPsec traffic will not pass through, there is one or more bugs on the ER8411 that cause problems with the VPN

 

Recommended Solution
  1  
  1  
#27
Options
Re:VPN connection between two routers ER8411 and ER7206 via omada
2023-04-24 17:36:47

  @shberge Yes, I have an SSL VPN.  I will no longer be able to connect to the router externally if I disable it.

  0  
  0  
#28
Options
Re:VPN connection between two routers ER8411 and ER7206 via omada
2023-04-24 17:38:09

  @test01 

 

Then you have to choose, SSL or IPsec, you can't get both to work.

  0  
  0  
#29
Options
Re:VPN connection between two routers ER8411 and ER7206 via omada
2023-04-24 17:38:15

  @shberge 

Can't we have a client vpn and a site-to-site vpn on the ER8411 ?

  0  
  0  
#30
Options
Re:VPN connection between two routers ER8411 and ER7206 via omada
2023-04-24 17:41:37

  @test01 

No, you can do it with OpenVPN but you have to use TCP not UDP, I have reported this several times to TP-Link but they don't seem to care

 

  0  
  0  
#31
Options
Re:VPN connection between two routers ER8411 and ER7206 via omada
2023-04-24 17:47:43

  @test01 

 

It is also not enough to delete SSL VPN, the router must also be restarted after you have deleted SSL VPN

 

  0  
  0  
#32
Options
Re:VPN connection between two routers ER8411 and ER7206 via omada
2023-04-24 17:49:47

  @shberge 

okay

I create a new OPEN VPN in TCP and another site-to-site IPSEC.  I will let you know if it works.

  0  
  0  
#33
Options