2 VPN tunnels with same subnets through different WAN ports

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

2 VPN tunnels with same subnets through different WAN ports

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
2 VPN tunnels with same subnets through different WAN ports
2 VPN tunnels with same subnets through different WAN ports
2015-08-05 05:44:23 - last edited 2021-08-21 05:09:31
Model :

Hardware Version : Not Clear

Firmware Version :

ISP :

Hello to all,

I'm using two TP-Link TL-ER604W. For each router I have two different ISPs each configured on both WANs - ISP1 on WAN1 and ISP2 on WAN2. I had set under load balancing section the link back up option to "Backup when any primary WAN failed". I had set WAN1 as primary and WAN2 as secondary. In this configuration WAN2 starts only when WAN1 port is down or there is no traffic. So I had mad the WANs redundant.

Next step was to set a VPN between both router. I had established successfully one VPN tunnel (VPN1) over WAN 1 on both routers.

Next step was to set another VPN tunnel (VPN2) to have redundancy on the VPN too with almost the same settings (same local and remote subnets) and different IKE and IP sec settings and all to go through WAN2. This is where I've got the problem. When I trying to save the IPSec setting with same local and remote subnets which were saved already in the first VPN tunnel (VPN1) I receive the following message "This Policy is in conflict with the No.1 IPsec Policy. The Policies cannot have the same Local Subnet and Remote Subnet." here Policy No.1 is VPN1.
Some how the router do NOT recognize the configuration of the "Link back up" option because WAN2 is not active until there is something wrong with WAN1. So following this logic I should be able to save and establish such tunnel only when WAN1 is not active and if it is not active that means that VPN1 will not be active. So there will be no overlapping or same routing in same time between VPN1 and VPN2 and I should be able to save the IPSec Policy.

I do need some help from anyone who had performed such or close to this scenario configuration to achieve my goal - redundancy on WAN port and redundancy on VPN tunnels. How to configure this with TL-ER604W?

Thank you in advance to the responders
  0      
  0      
#1
Options
5 Reply
Re:2 VPN tunnels with same subnets through different WAN ports
2015-08-11 11:50:10 - last edited 2021-08-21 05:09:31
Not possible. Software/Firmware limitation.
  0  
  0  
#2
Options
Re:2 VPN tunnels with same subnets through different WAN ports
2015-08-11 16:44:52 - last edited 2021-08-21 05:09:31
It should be possible. I had set up such scenario on 2 Linksys router which are 7 years old. This should be possible. The logic is in place. This scenario should be working only when you have primary and secondary WAN activated. Otherwise I would agree that there will be a conflict. Any one from TP-Link to replay please?

BR,
  0  
  0  
#3
Options
Re:2 VPN tunnels with same subnets through different WAN ports
2015-08-12 12:15:06 - last edited 2021-08-21 05:09:31
What 2 linksys routers model numbers?
  0  
  0  
#4
Options
Re:2 VPN tunnels with same subnets through different WAN ports
2015-08-12 16:45:02 - last edited 2021-08-21 05:09:31
RV-042 is the model.
  0  
  0  
#5
Options
Re:2 VPN tunnels with same subnets through different WAN ports
2015-08-13 07:53:36 - last edited 2021-08-21 05:09:31
Both RV-042 and the TL-ER604W have the same configurable settings. How did you get it working on the cisco RV-042. Just repeat the steps on the TL-ER604W
  0  
  0  
#6
Options