setting up er7206 with ipsec vpn and access control

setting up er7206 with ipsec vpn and access control

setting up er7206 with ipsec vpn and access control
setting up er7206 with ipsec vpn and access control
2024-10-04 20:16:32 - last edited 2024-10-08 03:31:53
Model: ER7206 (TL-ER7206)  
Hardware Version: V2
Firmware Version: 2.1.2 Build 20240324 Rel.46738

trying to set up ipsec tunnel and configure the firewall on an ER7206.  Manual configuration.  The IPSEC tunnels are working properly; however, when I put a deny rule in access control the router does not allow any traffic to pass through the tunnel (although the tunnel remains UP).  I've tried adding the IP addresses of the remote endpoints to the access rules but this doesn't work - as soon as I change the "deny" rule to BLOCK it shuts down the software on the remote endpoints.  Any ideas?  I've also set up access control rules to allow the ipsec ports to pass through but no luck.

 

 

  0      
  0      
#1
Options
2 Accepted Solutions
Re:setting up er7206 with ipsec vpn and access control-Solution
2024-10-05 09:34:21 - last edited 2024-10-08 03:31:21

  @sambamcunningha 

 

you have to set it up like this, here is a rule I use to allow some remote lan, first I block all private nets rfc1918 then I open for those who should have access.

 

 

WAN in to block remote lan, LAN->WAN to block lan out.

Recommended Solution
  0  
  0  
#2
Options
Re:setting up er7206 with ipsec vpn and access control-Solution
2024-10-07 17:31:57 - last edited 2024-10-08 03:30:55

  @sambamcunningha 

 

I think I have this resolved.  Thank you for your assistance.

Recommended Solution
  0  
  0  
#11
Options
10 Reply
Re:setting up er7206 with ipsec vpn and access control-Solution
2024-10-05 09:34:21 - last edited 2024-10-08 03:31:21

  @sambamcunningha 

 

you have to set it up like this, here is a rule I use to allow some remote lan, first I block all private nets rfc1918 then I open for those who should have access.

 

 

WAN in to block remote lan, LAN->WAN to block lan out.

Recommended Solution
  0  
  0  
#2
Options
Re:setting up er7206 with ipsec vpn and access control
2024-10-05 22:12:28

  @MR.S 

 

I'm not sure this would work for me.  Block just the rfc1918 addresses would not prevent all of the public IP's that currently have access.

 

How are you setting up the Remote_LAN IP Group?

  0  
  0  
#3
Options
Re:setting up er7206 with ipsec vpn and access control
2024-10-06 04:45:43

  @sambamcunningha 

 

it suddenly became a bit unclear to me what kind of vpn tunnel you have, you say ipsec vpn so I assumed it was site-to-site ipsec vpn. maybe you can explain in more detail what kind of ipsec vpn you have.

 

  0  
  0  
#4
Options
Re:setting up er7206 with ipsec vpn and access control
2024-10-06 05:09:48

  @MR.S

it is a site to site IPSEC VPN tunnel.  The ER7206 is the host site, and another vendor's routers are on the remote ends of the tunnel.  So, two different site to site tunnels with the ER7206 being the host site.

 

  0  
  0  
#5
Options
Re:setting up er7206 with ipsec vpn and access control
2024-10-06 06:00:59 - last edited 2024-10-08 03:31:19

  @sambamcunningha 

 

Ok, so you want to block WAN public ip for everyone exept for those who are going to VPN or do you want to block traffic that is inside the VPN tunnel?

it would be easier if you could show a screenshot of your configuration

 

  0  
  0  
#6
Options
Re:setting up er7206 with ipsec vpn and access control
2024-10-07 14:56:56

  @MR.S 

I thought I had...here you go

 

  0  
  0  
#7
Options
Re:setting up er7206 with ipsec vpn and access control
2024-10-07 16:35:27
  0  
  0  
#8
Options
Re:setting up er7206 with ipsec vpn and access control
2024-10-07 17:30:55
  0  
  0  
#9
Options
Re:setting up er7206 with ipsec vpn and access control
2024-10-07 17:31:25
File:
accesslisttplink.pdfDownload
  0  
  0  
#10
Options
Re:setting up er7206 with ipsec vpn and access control-Solution
2024-10-07 17:31:57 - last edited 2024-10-08 03:30:55

  @sambamcunningha 

 

I think I have this resolved.  Thank you for your assistance.

Recommended Solution
  0  
  0  
#11
Options