VPN Client default gateway

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

VPN Client default gateway

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
VPN Client default gateway
VPN Client default gateway
2023-05-29 17:52:53 - last edited 2023-05-30 10:12:11
Model: Archer AXE75  
Hardware Version: V1
Firmware Version: 1.1.6 Build 20221208 rel.72102(4555)

I have to access my customer's VPN.

He provided me the .ovpn (OpenVPN) client conf file.

 

If I use the .ovpn file directly on my PC, in a OpenVPN client, everything works fine. I can reach the remote networks and my default traffic (not for the VPN networks) goes directly to the Internet.

 

When I use the same file on my router AXE75, _ALL_ traffic goes through the VPN!!! Why?

I want that _ONLY_ the traffic towards my customer networks (which his VPN server pushes) to go over the VPN. Like my PC does.

 

Can anyone support?

  0      
  0      
#1
Options
1 Accepted Solution
Re:VPN Client default gateway-Solution
2023-05-30 05:33:56 - last edited 2023-05-30 10:12:11

  @PBraga 

 

Hello, thank you for posting on the TP-Link Community.

 

For the issue you reported, please open the .ovpn client conf file and add the following 4 lines, then please test if the problem can be resolved.

route 0.0.0.0 192.0.0.0 net_gateway
route 64.0.0.0 192.0.0.0 net_gateway
route 128.0.0.0 192.0.0.0 net_gateway
route 192.0.0.0 192.0.0.0 net_gateway

Nice to Meet You in Our TP-Link Community. Check Out the Latest Posts: Archer GE550 - BE9300 Tri-Band Wi-Fi 7 Gaming Router EasyMesh Is Available When Wi-Fi Routers Work in AP Mode as A Controller. Archer BE550 New Software Enhances System Stability and Optimizes MLO Network Stability. TL-WA3001 Supports EasyMesh, Speed Limit, Guest Network in AP Mode and/or Multi-SSID Mode. If you found the post or response helpful, please click Helpful. If an answer solves your problem, click "Recommended Solution" so that others can benefit from it.
Recommended Solution
  2  
  2  
#2
Options
6 Reply
Re:VPN Client default gateway-Solution
2023-05-30 05:33:56 - last edited 2023-05-30 10:12:11

  @PBraga 

 

Hello, thank you for posting on the TP-Link Community.

 

For the issue you reported, please open the .ovpn client conf file and add the following 4 lines, then please test if the problem can be resolved.

route 0.0.0.0 192.0.0.0 net_gateway
route 64.0.0.0 192.0.0.0 net_gateway
route 128.0.0.0 192.0.0.0 net_gateway
route 192.0.0.0 192.0.0.0 net_gateway

Nice to Meet You in Our TP-Link Community. Check Out the Latest Posts: Archer GE550 - BE9300 Tri-Band Wi-Fi 7 Gaming Router EasyMesh Is Available When Wi-Fi Routers Work in AP Mode as A Controller. Archer BE550 New Software Enhances System Stability and Optimizes MLO Network Stability. TL-WA3001 Supports EasyMesh, Speed Limit, Guest Network in AP Mode and/or Multi-SSID Mode. If you found the post or response helpful, please click Helpful. If an answer solves your problem, click "Recommended Solution" so that others can benefit from it.
Recommended Solution
  2  
  2  
#2
Options
Re:VPN Client default gateway
2023-05-30 10:11:20 - last edited 2023-05-30 10:20:28

  @Sunshine , thank you very much.

It did the trick ;)

 

 

BTW, is there a way to view more router conf details? Mainly the dynamic ones like routing tables, NAT table, name servers, etc.?

Some kind of CLI (even if read-only) where I could execute some ifconfig, nslookup, even ping and tracert, etc.

 

I'm checking where the traffic is going through, by using traceroute (tracert in windows) on a device connected to my LAN :P

  0  
  0  
#3
Options
Re:VPN Client default gateway
2023-05-31 05:50:22

  @PBraga 

 

Hello, for the routing table, you could check it on the router web interface: Advanced->Network->Routing, but I am afraid CLI etc. are not supported.

Nice to Meet You in Our TP-Link Community. Check Out the Latest Posts: Archer GE550 - BE9300 Tri-Band Wi-Fi 7 Gaming Router EasyMesh Is Available When Wi-Fi Routers Work in AP Mode as A Controller. Archer BE550 New Software Enhances System Stability and Optimizes MLO Network Stability. TL-WA3001 Supports EasyMesh, Speed Limit, Guest Network in AP Mode and/or Multi-SSID Mode. If you found the post or response helpful, please click Helpful. If an answer solves your problem, click "Recommended Solution" so that others can benefit from it.
  0  
  0  
#4
Options
Re:VPN Client default gateway
2023-06-04 23:17:55

  @Sunshine 

 

Hi, thank you very much! I did found the routing table. yes

 

 

BTW, as you were able to answer this .ovpn issue on the Archer AXE75, I do have an issue, with completely opposite behavior, on another TP-Link router (business line), the ER605 (TL-R605). I'm hopping you could provide some useful hints as well... angel

 

In this case, using the very same .ovpn configuration file I have the opposite behavior :( . No traffic over the VPN, because I have NO routes for the tunnel in the routing table!!

I only have the local VPN network (you know, no "next hop", just the network on the tunnel interface).

It seems that the router doesn't learn the routes pushed by the VPN server!

 

Do you have any ideas that you could share? :)

Thanks in advance anyway.

 

 

--

PS: I posted a question regarding this issue with the complete information:

https://community.tp-link.com/en/business/forum/topic/610858

 

  0  
  0  
#5
Options
Re:VPN Client default gateway
2023-06-06 07:55:39

  @PBraga 

 

Hello, do you mean the .ovpn configuration file used on ER605 also added the 4 lines I sent you?

If you remove the 4 lines for ER605, will it work as expected? If it still doesn't work properly, it is recommended to start a new thread on the business community.

Nice to Meet You in Our TP-Link Community. Check Out the Latest Posts: Archer GE550 - BE9300 Tri-Band Wi-Fi 7 Gaming Router EasyMesh Is Available When Wi-Fi Routers Work in AP Mode as A Controller. Archer BE550 New Software Enhances System Stability and Optimizes MLO Network Stability. TL-WA3001 Supports EasyMesh, Speed Limit, Guest Network in AP Mode and/or Multi-SSID Mode. If you found the post or response helpful, please click Helpful. If an answer solves your problem, click "Recommended Solution" so that others can benefit from it.
  0  
  0  
#6
Options
Re:VPN Client default gateway
2023-06-06 10:22:23

Hi  @Sunshine ,

 

I tried the pristine version (without your 4 lines) first. It didn't work.

Then I tried the version with the 4 lines. It didn't work either :(

 

I already started a thread on the business comunity.

 

Thank you for your time :)

 

  0  
  0  
#7
Options