Client VPN connection of the router not established when Internet WAN is the SFP+ port

Client VPN connection of the router not established when Internet WAN is the SFP+ port

Client VPN connection of the router not established when Internet WAN is the SFP+ port
Client VPN connection of the router not established when Internet WAN is the SFP+ port
2024-10-04 09:55:12 - last edited 2024-10-18 09:23:52
Model: Archer AXE300  
Hardware Version: V1
Firmware Version: Archer AXE300(US)_V1.6_1.0.9 Build 20230525

Hi to all,

my client VPN connection established from the router stopped to work when i move my Internet WAN connection from the 10G Ethernet interface to the SFP+ interface.

I used the client VPN feature (OpenVPN) specifically on one LAN connection,  for using a TV box with an italian service that has IP geographical limitation.

I recently moved to a full fiber operator. I activate the connection with their router and the Archer connected in cascade (same as for the previous provider that was a cable one): all worked fine, Internet and VPN ok and i tested for few days, all OK.

Then, I decided to connect directly my Archer to the fiber, with a SFP+ ONT  on the SFP+ interface.

I discussed with my internet operator, done what was necessary and I got Internet connection working fine: unfortunately, i noticed that the Archer VPN connection is not established (on the Archer web interface remains  "connecting" for ever). No error messages also on system log.

If i try to use the VPN client application on the PC or directly the app on the TV box, the VPN is established.

So, only the VPN connection of the Archer is not working.

It's not an issue of VPN configuration parameters on the Archer, since they were the same when using previous Internet provider and current provider when using 10G WAN interface.

The SFP+ ONT should not be the cause since i have Internet connection and VPN connection if i started from PC or app.

Also no filtering from Internet provider for same reasons.

It's like the Archer is not routing the VPN request to the SFP+ WAN interface.

Anybody experience such issue ?

  0      
  0      
#1
Options
1 Accepted Solution
Re:Client VPN connection of the router not established when Internet WAN is the SFP+ port-Solution
2024-10-18 09:12:07 - last edited 2024-10-18 09:36:38

Ok,

just a final note that may help someone in the future.

About the AXE remaining "connecting" stuck, i made many attempts, even re-performing full VPN configuration using a new OVPN file, with many AXE restart/reboot in between.

At a certain point, without idea of what cured - miracle happens-, i was able to have the connected status on the AXE300, see the expected NordVPN server IP address, but still no VPN functionality for the TV box.

I agree a remote connection with TP-Link support (btw, Fitz -  thank you very much for the help) that troubleshooted the issue.

My ISP provider gives internet via IPv4, but also starting IPv6 usage and i have IPv6 protocol enabled on the AXE300 router (probably i enabled it during configuration to use the new ISP or the SFP+ dongle direct connection, no recall of the story).

Then VPN was established with NordVPN server with IPv4, but traffic was using IPv6 addresses, so " somewhere"  (i'm not that expert, so no idea if this was at NordVPN server level or requested site level, or what...) this mismatch causes not having proper connectivity.

Note that this was happening only when VPN connection is performed by the router, since if i was using an  OpenVPN client on the PC or the NordVPN app on the TV box to perform the VPN connection, everything was working fine.

Finally, the solution was to disable IPv6 protocol on the AXE and then everything returned to work.

 

Recommended Solution
  2  
  2  
#3
Options
2 Reply
Re:Client VPN connection of the router not established when Internet WAN is the SFP+ port
2024-10-11 10:13:44

  @ANDREAAAAAAAAAA 

 

Hi, thanks for posting question here.

To assist you efficiently, I've forwarded your case to the TP-Link support engineers who will contact you with your registered email address later. Please pay attention to your email box for follow-up.

  0  
  0  
#2
Options
Re:Client VPN connection of the router not established when Internet WAN is the SFP+ port-Solution
2024-10-18 09:12:07 - last edited 2024-10-18 09:36:38

Ok,

just a final note that may help someone in the future.

About the AXE remaining "connecting" stuck, i made many attempts, even re-performing full VPN configuration using a new OVPN file, with many AXE restart/reboot in between.

At a certain point, without idea of what cured - miracle happens-, i was able to have the connected status on the AXE300, see the expected NordVPN server IP address, but still no VPN functionality for the TV box.

I agree a remote connection with TP-Link support (btw, Fitz -  thank you very much for the help) that troubleshooted the issue.

My ISP provider gives internet via IPv4, but also starting IPv6 usage and i have IPv6 protocol enabled on the AXE300 router (probably i enabled it during configuration to use the new ISP or the SFP+ dongle direct connection, no recall of the story).

Then VPN was established with NordVPN server with IPv4, but traffic was using IPv6 addresses, so " somewhere"  (i'm not that expert, so no idea if this was at NordVPN server level or requested site level, or what...) this mismatch causes not having proper connectivity.

Note that this was happening only when VPN connection is performed by the router, since if i was using an  OpenVPN client on the PC or the NordVPN app on the TV box to perform the VPN connection, everything was working fine.

Finally, the solution was to disable IPv6 protocol on the AXE and then everything returned to work.

 

Recommended Solution
  2  
  2  
#3
Options