IPSec IKEv2 VPN with internet access

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

IPSec IKEv2 VPN with internet access

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
IPSec IKEv2 VPN with internet access
IPSec IKEv2 VPN with internet access
2024-02-22 14:11:41 - last edited 2024-02-29 01:38:25
Tags: #VPN
Model: ER605 (TL-R605)  
Hardware Version: V1
Firmware Version: 1.3.1 Build 20231207 Rel.61384

I own a ER605 v1 router and want to set it to work as a VPN server so that I can connect my mobile devices to my home network if I'm away from home.
I do not only want to access my home network but also want to route my internet traffic through my router at home so that it seems my device is at home. However I haven't got that to work.

 

What I currently have is the following IPSec Policy:

 

 

For obvious reasons some fields show errors ;). Btw the Primary DNS server seems to disappear after navigation to another page and getting back here. I've set it to 1.1.1.1.

 

The IP Address Pool for the policy is a different range than my home network..

It is set to use IKEv2 with the correct settings (not sure about Phase 2 on which the Encapsulation Mode is set to Tunnel mode).

 

So far so good. I now can connect with my Android phone and I can access network resources. What I cannot do is access the internet (through the VPN) on my phone.

 

I was figuring that there is no known route for the IP range of the VPN to go to the internet so I added the following IP Address:

and then the following IP Group:

 

Now under Routing -> Policy Routing I added a rule:

 

I was hoping this would work but unfortunately it doesn't.

I do not want to use PPTP, L2TP or OpenVPN (old or slower). Wireguard would be an option but that doens't seem to be available on V1 devices.

 

Any idea on how to get this working?

 

 

Additional info:
The ER605 sits behind my ISP router. I port-forwarded port 500 UDP and 4500 UDP to the ER605.

  0      
  0      
#1
Options
6 Reply
Re:IPSec IKEv2 VPN with internet access
2024-02-23 01:12:42 - last edited 2024-02-23 01:13:28

Hi @Tratsz 

Thanks for posting in our business forum.

1. Read what may happen if you place it behind NAT.

 

2. Policy Routing may not work because it does not apply to IPsec as far as I recall.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#2
Options
Re:IPSec IKEv2 VPN with internet access
2024-02-23 06:54:59

Thanks for your repsonse.

 

Before I try to chase something that just isn't possible: Is it possible at all to use an IPSec policy with IKEv2 with client-to-lan and use internet through the tunnel?

 

Does anyone know why the v1 router does not have Wireguard as option?

  0  
  0  
#3
Options
Re:IPSec IKEv2 VPN with internet access
2024-02-23 07:41:12

Hi @Tratsz 

Thanks for posting in our business forum.

Tratsz wrote

Thanks for your repsonse.

 

Before I try to chase something that just isn't possible: Is it possible at all to use an IPSec policy with IKEv2 with client-to-lan and use internet through the tunnel?

 

Does anyone know why the v1 router does not have Wireguard as option?

No.

Limited hardware resources.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#4
Options
Re:IPSec IKEv2 VPN with internet access
2024-02-23 13:08:18

Thanks. In that case I will leave the ER605 alone and will run Wireguard on some other device.

  0  
  0  
#5
Options
Re:IPSec IKEv2 VPN with internet access
2024-02-27 07:41:09

  @Tratsz 

Just modify in the router vpn settings the following:

And it should work.

For DNS, use 8.8.8.8

  1  
  1  
#6
Options
Re:IPSec IKEv2 VPN with internet access
2024-02-28 07:43:49

Hi @Marge78

Marge78 wrote

  @Tratsz 

Just modify in the router vpn settings the following:

And it should work.

For DNS, use 8.8.8.8

Big brain move. No offense. It indeed seems to be the way to use it as a proxy.

This will pose the whole local subnet to the clients as well.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#7
Options