TL-ER6020: PPTP or L2TP client-to-lan can't connect remote network plugged in via lan-to-lan IPSec

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

TL-ER6020: PPTP or L2TP client-to-lan can't connect remote network plugged in via lan-to-lan IPSec

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
TL-ER6020: PPTP or L2TP client-to-lan can't connect remote network plugged in via lan-to-lan IPSec
TL-ER6020: PPTP or L2TP client-to-lan can't connect remote network plugged in via lan-to-lan IPSec
2015-10-14 20:09:24 - last edited 2021-08-21 05:24:22
Model :

Hardware Version : Not Clear

Firmware Version :

ISP :

Hi everyone,

I've recently got myself a TL-ER6020 for small office use.

I've configured IPSec connection to remote network, so I've got this:

192.168.13.0/24 (LAN) <-------- IPSEC ---------> 10.1.1.0/24 (NET1)
TL-ER6020 UNKNOWN


from my LAN network I can easily reach remote NET1 network with all required hosts accessible.

Next I wan't to allow some of my employees to access NET1 through TL-ER6020, so I set it up as VPN server (L2TP, but I've also tried PPTP with the same result)
I configure IP pool for L2TP clients to 192.168.13.50-192.168.13.70 (it's not overlaping with DHCP for LAN, which is set to 192.168.13.100-192.168.13.199)

Everything work's fine, I can easily connect to the created VPN server from mobile client:

192.168.13.50/32 (CLIENT) < -------- L2TP --------> 14.14.14.14 (WAN1)
SMARTPHONE TL-ER6020

With this setup I have full access to LAN hosts, so I can access for instance router setup at 192.168.13.1 (TL-ER6020) from 192.168.13.50 (CLIENT).

My problem is, that I cant access NET1 from CLIENT, so this isn't working:

192.168.13.50/32 (CLIENT) < -------- L2TP --------> 14.14.14.14 (WAN1) | 192.168.13.0/24 (LAN) <-------- IPSEC ---------> 10.1.1.0/24 (NET1)
SMARTPHONE TL-ER6020 UNKNOWN
[FONT=arial]
What I wan't is to be able to access 10.1.1.1 from 192.168.13.50.

I believe this has something to do with te fact, that 192.168.13.50 is in the same IP class as the LAN network. I've tried to switch L2TP IP pool to different IP class: 192.168.14.0/24 (not NAT). After doing so I was able to access 10.1.1.1, but since it's not NAT'ed I can't access the Internet. If I enable Multi-Nets NAT for 192.168.14.0/24, I have access to the Internet, but I lose connectivity with 10.1.1.0/24.

Does anyone have an idea how to have both on the mobile client: access to the Internet via NAT + access to the IPSec network NET1?

[/FONT]
  0      
  0      
#1
Options
1 Reply
Re:TL-ER6020: PPTP or L2TP client-to-lan can't connect remote network plugged in via lan-to-lan IPSec
2015-10-29 09:11:13 - last edited 2021-08-21 05:24:22
hi Koperek, PPTP/L2TP/IPsec VPN are all Point-to-Point, that is say, when you set up a VPN between two side, the two side is connected directly, but it can not relay the data to other Point that is not belong to the two Points.
  0  
  0  
#2
Options