ER605 V2 as client, does not work with OpenVPN client-to-site

ER605 V2 as client, does not work with OpenVPN client-to-site

ER605 V2 as client, does not work with OpenVPN client-to-site
ER605 V2 as client, does not work with OpenVPN client-to-site
2024-12-22 18:05:01 - last edited Tuesday
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2.6 Build 20240718 Rel.82712

I have configured a couple of VLAN to go through a client-to-site OpenVPN setup and it is working great.

 

But as soon as I tried doing the same for a second OpenVPN for a different VLAN/Interfaces, it does not work.

 

If I disable all the OpenVPN clien-to-site, and then reenable them in different order, it is always the first one that was enabled that works correctly, the other vlan does not have any internet.

 

I have the same issue as this thread: https://community.tp-link.com/en/home/forum/topic/609790

  0      
  0      
#1
Options
2 Accepted Solutions
Re:ER605 V2 as client, does not work with OpenVPN client-to-site -Solution
a week ago - last edited Tuesday

  @malexe 

 

You have to remember that it is the server that pushes the route to the OpenVPN client, if there is a conflict route you will have problems. You will probably have to wait until we get policy routing to Omada to make this work.
If it is Omada servers then you determine the route on the server. If you have a full tunnel on all servers then there will be a crash.

 

 

Recommended Solution
  1  
  1  
#4
Options
Re:ER605 V2 as client, does not work with OpenVPN client-to-site -Solution
Monday - last edited Tuesday

  @MR.S You are right! I don't know why, but I was under the impression I could set source vlan (from my network), to each use and redirect all traffic. My goal was to "connect" different VLAN with different cloud Server/IPs, so that each VLAN would have different public IPs, but it seems I was wrong.

 

Removing the default route push through every VPN server I had fixed it.

 

I still have to rethink/redesign what I want to accomplish though smiley

 

Thanks.

Recommended Solution
  0  
  0  
#5
Options
4 Reply
Re:ER605 V2 as client, does not work with OpenVPN client-to-site
2024-12-23 01:31:09

Hi @malexe 

Thanks for posting in our business forum.

Second VPN server or you created a second VPN user profile?

Please give details about your network diagram and config.

 

The user you posted, has misconfigured his network which caused such an issue. Instead of duplicating the VPN server on the router, you should create the user profile.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#2
Options
Re:ER605 V2 as client, does not work with OpenVPN client-to-site
a week ago

  @Clive_A I am back from the Holidays, sorry for the delay.

 

I am trying to use multiple Client-to-Site VPN OpenVPN(Client)

 

The only Client-To-Site VPN that is redirecting the traffic correctly is the first one(order) I enable. I Can disable all of them, and then renable the third one in the list first, and then enable the others, only the first that was enabled is working.

 

  0  
  0  
#3
Options
Re:ER605 V2 as client, does not work with OpenVPN client-to-site -Solution
a week ago - last edited Tuesday

  @malexe 

 

You have to remember that it is the server that pushes the route to the OpenVPN client, if there is a conflict route you will have problems. You will probably have to wait until we get policy routing to Omada to make this work.
If it is Omada servers then you determine the route on the server. If you have a full tunnel on all servers then there will be a crash.

 

 

Recommended Solution
  1  
  1  
#4
Options
Re:ER605 V2 as client, does not work with OpenVPN client-to-site -Solution
Monday - last edited Tuesday

  @MR.S You are right! I don't know why, but I was under the impression I could set source vlan (from my network), to each use and redirect all traffic. My goal was to "connect" different VLAN with different cloud Server/IPs, so that each VLAN would have different public IPs, but it seems I was wrong.

 

Removing the default route push through every VPN server I had fixed it.

 

I still have to rethink/redesign what I want to accomplish though smiley

 

Thanks.

Recommended Solution
  0  
  0  
#5
Options