ER605 IPSec VPN Site to Site Client Communication

ER605 IPSec VPN Site to Site Client Communication

ER605 IPSec VPN Site to Site Client Communication
ER605 IPSec VPN Site to Site Client Communication
a week ago - last edited a week ago
Tags: #VPN
Hardware Version: V2
Firmware Version:

Hello All,

I am a beginner in networking and currently I have the below setup.

 

To give a overview of the setup, I have 2 sites (Site A and Site B 2 different locations).  Both sites have ER605 VPN router which is connected to WAN and an IPSec VPN tunnel has been established between them.  Each site has a Wi-Fi router (Archer AX73) whose WAN port is connected to LAN port of the VPN router.  I have few clients connected to the Wi-Fi router via Wireless and Wired.  This setup is similar on both the sites.

IPSec VPN tunnel has been created with LAN IP of the VPN router as the Remote Subnets.  

Connecting to LAN IP of the VPN router from clients in both sites works fine.  Now my requirement is to connect to a client in Site B which has a IP address of 192.168.6.3 from a client in Site A which has a IP address of 192.168.5.10.  How to access LAN IP of Wi-Fi router of Site B from a client in Site A and vice versa?  Hope my requirement is clearly understandable.  Kindly let me know whether it is achievable and if yes what needs to be done to get this working.  Thanking you.

  0      
  0      
#1
Options
5 Reply
Re:ER605 IPSec VPN Site to Site Client Communication
a week ago

  @Dintu88 

 

the short answer is you can't, the Archer AX73 has NAT and blocks the same way as if you had the Archer AX73 on the internet.

remove the Archer AX73 and it will work without problems, why do you have the Archer AX73 on the network?

 

  1  
  1  
#2
Options
Re:ER605 IPSec VPN Site to Site Client Communication
a week ago

  @MR.S Initially I had only Archer AX73 in both the locations to server wireless clients.  Then I had Multi WANs in both the locations and so purchased ER605 and configured load balancing for both the locations.  Now I am not in situation to replace Archer AX73 with APs and the reason to keep Archer AX73 in Router mode is to utilize the EasyMesh.

  0  
  0  
#3
Options
Re:ER605 IPSec VPN Site to Site Client Communication
a week ago

  @Dintu88 @MR.S 

 

I bet he's doing that to have the WiFi, cuz ER605 doesn't have built in WiFi module...

 

The easiest way would be to replace the Archer with TP-Link (or any other) Access Point.

 

But I guess it could be possible to configure, as I check, the Archer supports Static Routing:

 

Here's more info of how to set up routing on that router:

https://www.tp-link.com/pl/support/faq/3601/

  1  
  1  
#4
Options
Re:ER605 IPSec VPN Site to Site Client Communication
a week ago

  @Dintu88 

 

Ok then you will not be able to communicate via VPN, if you need to get a specific service you can try port forwarding on Archer AX73

 

  1  
  1  
#5
Options
Re:ER605 IPSec VPN Site to Site Client Communication
a week ago

  @Dintu88 

 

BTW, Maybe it woulr work better if you would set those into Access Point Mode?

 

Cheers

  1  
  1  
#6
Options