ER707-M2 as openvpn server on WAN port

ER707-M2 as openvpn server on WAN port

ER707-M2 as openvpn server on WAN port
ER707-M2 as openvpn server on WAN port
2 weeks ago - last edited a week ago
Model: ER707-M2  
Hardware Version: V1
Firmware Version: 1.2.2 Build 20240324 Rel.42799

I have a firewall that does not provide openvpn server. I would like to use ER707-M2 to provide openvpn on the LAN by redirecting openvpn port from firewall to ER707-M2.

 

How do I configure ER707-M2 to permit connections to machines on my LAN which is the WAN on the ER707-M2

 

I do not want to setup a second LAN below the ER707-M2.

 

If possible I would like all ports on ER707-M2 to be on LAN by setting them to be "WAN"

 

ideas appreciated.

  0      
  0      
#1
Options
1 Accepted Solution
Re:ER707-M2 as openvpn server on WAN port-Solution
2 weeks ago - last edited a week ago

Hi @MarkAGregory 

Thanks for posting in our business forum.

DMZ might be something you are after but it may not work to put all LAN of the ER707-M2 to its WAN. That's barely possible to do on any router.

At the end of the day, you might wanna try to remove the first NAT to avoid double-NAT.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#2
Options
7 Reply
Re:ER707-M2 as openvpn server on WAN port-Solution
2 weeks ago - last edited a week ago

Hi @MarkAGregory 

Thanks for posting in our business forum.

DMZ might be something you are after but it may not work to put all LAN of the ER707-M2 to its WAN. That's barely possible to do on any router.

At the end of the day, you might wanna try to remove the first NAT to avoid double-NAT.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#2
Options
Re:ER707-M2 as openvpn server on WAN port
2 weeks ago

  @Clive_A thank you for the ideas, I've moved through the possible approaches that appear to be doable with this device. What I need to do might be possible, but it would require specific guidance from someone that has done it before. As we know we can setup openvpn servers on single nic devices, e.g., NAS boxes do it, and it can be done on desktop computers.

 

I'm hoping that someone from tp-link will respond with the guidance that I need to move forward.

  0  
  0  
#3
Options
Re:ER707-M2 as openvpn server on WAN port
2 weeks ago

Hi @MarkAGregory 

Thanks for posting in our business forum.

MarkAGregory wrote

  @Clive_A thank you for the ideas, I've moved through the possible approaches that appear to be doable with this device. What I need to do might be possible, but it would require specific guidance from someone that has done it before. As we know we can setup openvpn servers on single nic devices, e.g., NAS boxes do it, and it can be done on desktop computers.

 

I'm hoping that someone from tp-link will respond with the guidance that I need to move forward.

I am from the TP-Link but what you described is not clear enough. I don't know where you learned that is possible to do that. But to simplify what you asked, that's port forwarding. DMZ is a different way to work around port forwarding. Port forwarding twice if necessary in your setup. A generic port forward guide would answer your request for guidance.

 

The problem is if you have double NAT, you should remove and avoid the NAT. Anything that happened to the double-NAT may not be resolved by us because it is not the recommended way to use it.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#4
Options
Re:ER707-M2 as openvpn server on WAN port
2 weeks ago

  @Clive_A I'm not certain that what I've put is not clear. But to be clear let me state again.

 

Option 1. WAN port on ER707-M2 is connected to the local LAN. Upstream firewall port forwards to the ER707-M2 WAN port. OpenVPN is configured to listen on the WAN port and when a client connects the client is given access to the WAN port(s) -> meaning the LAN of my network.

 

Option 2. LAN port on ER707-M2 is connected to the local LAN. Upstream firewall port forwards to the ER707-M2 LAN port. OpenVPN is configured to listen on the LAN port and when a client connects the client is given access to the LAN port(s) -> meaning the LAN of my network.

 

As mentioned, many other devices are capable of this configuration. NAS boxes, single NIC computers, pFsense, etc.

 

My question is whether the ER707-M2 can be configured to do what I need.

 

Everything is possible, the question is whether the configuration / OS has the flexibility or has it been setup to only do WAN / LAN translations for all services.

  0  
  0  
#5
Options
Re:ER707-M2 as openvpn server on WAN port
2 weeks ago

Hi @MarkAGregory 

Thanks for posting in our business forum.

MarkAGregory wrote

  @Clive_A I'm not certain that what I've put is not clear. But to be clear let me state again.

 

Option 1. WAN port on ER707-M2 is connected to the local LAN. Upstream firewall port forwards to the ER707-M2 WAN port. OpenVPN is configured to listen on the WAN port and when a client connects the client is given access to the WAN port(s) -> meaning the LAN of my network.

 

Option 2. LAN port on ER707-M2 is connected to the local LAN. Upstream firewall port forwards to the ER707-M2 LAN port. OpenVPN is configured to listen on the LAN port and when a client connects the client is given access to the LAN port(s) -> meaning the LAN of my network.

 

As mentioned, many other devices are capable of this configuration. NAS boxes, single NIC computers, pFsense, etc.

 

My question is whether the ER707-M2 can be configured to do what I need.

 

Everything is possible, the question is whether the configuration / OS has the flexibility or has it been setup to only do WAN / LAN translations for all services.

Are you sure others can do this? Any docs on this? Keeps saying this is doable where I see no way to do it. If you ask me about this, I say no, not doable with any Omada. Nor do we have a guide on this.

 

Option 1 is just a generic port that forwards the local service to the first NAT. Every router supports NAT - port forward.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#6
Options
Re:ER707-M2 as openvpn server on WAN port
2 weeks ago

  @Clive_A thank you for the clarification that the device will not do what I need, which is to be an openVPN server on a LAN. I bought the device thinking it might do what I need, but that is ok, it can be used to provide a simple NAT.

 

I'm not going to spend time providing documents on how pFsense, QNAP NAS, LINKSYS NAS, and many many other devices can be configured to be an openVPN server on a single NIC device. Google is your friend.

  0  
  0  
#7
Options
Re:ER707-M2 as openvpn server on WAN port
2 weeks ago

Hi @MarkAGregory 

Thanks for posting in our business forum.

MarkAGregory wrote

  @Clive_A thank you for the clarification that the device will not do what I need, which is to be an openVPN server on a LAN. I bought the device thinking it might do what I need, but that is ok, it can be used to provide a simple NAT.

 

I'm not going to spend time providing documents on how pFsense, QNAP NAS, LINKSYS NAS, and many many other devices can be configured to be an openVPN server on a single NIC device. Google is your friend.

I am aware that they are LINXU based and installing the simple app to enable them with the OVPN or WG.

I am not interested in digging into their web or docs on this. From what I understand and your understanding, we don't share common ground/knowledge on this.

 

Connecting the WAN to the first NAT LAN, that makes sense by doing port forwarding. However, by connecting the second NAT LAN to the first NAT LAN, you would not get too much support or approval from the networking community. I don't deny that making some iptable/routing would enable that, but mostly it is not how it works. You don't have to listen to my suggestions if you have your view on this. But like I said, we don't have guides or similar cases which in this case it seems that the router does not meet your expectations. You can return it before the return window closes. Or wait for someone else from the community to share a solution if they have done something similar.

 

Reddit is also a good place where you have many more active and knowledgeable members to discuss this. If you want to listen to more suggestions or comments.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#8
Options