[SOLVED] LAN-2-LAN IPsec stablished, but can not ping remote lan computers
[SOLVED] LAN-2-LAN IPsec stablished, but can not ping remote lan computers
Hardware Version :
Firmware Version :
ISP :
Hello,
I recently purchase two routers a TL-ER6120 and a TL-R600VPN. I followed this tutorial http://www.tp-link.es/faq-380.html and everithing is OK, I can reach remote TL-ER6120 router from LAN behind TL-R600VPN. However I can not ping any computer outside of local LAN, neither from remote LAN to local computers LAN. I tried to configure static routing, but It don't let me because it overrides VPN routing.
Any help is appreciated, thank you very much.
Kind regards.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
Thanks everybody for comments and help.
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
@malaguna I live the same problem, I wonder if I can solve.
ipsec vpn is active on both sides, but when I want to ping the PC to eat Request timed out. I get an error.
please help me.
- Copy Link
- Report Inappropriate Content
Check if there are IPsec entries in IPsec SA list. It's for confirming IPsec VPN has been established.
And make sure you have used the latest firmware for your router.
- Copy Link
- Report Inappropriate Content
I don't understand why people are posting about default gateway. That's a network adapter setting in windows.
Like really, did you even read the post. Do you even know what IPSec is? Jesus... Infuriating.
So I have the same problem.
However I believe the problem is that the router is NAT'd. Double nat'd that is. You cannot put this device behind a NAT, and expect the tunnel to complete fully.
Sure it can communicate, but the other side cannot. Because it's behind a NAT. You cannot expect outside entities to reach through your top-level router and touch your IPSec router, not without some configuration (forwarding for ipsec: AH 51, TCP && UDP 500, ESP 50, udp 4500).
I'm testing that theory now and will report back within a day or two. If I'm right, then simply exposing the router to the public WAN of the world does the job for this exact issue.
And yes, my IPSec SA listing shows a successfull connection just like you. But zero ping success. It doesn't hop across the tunnel, stops at the vpn router gateway.
Diagnostics tab has a ping utility, and it too cannot reach the other network devices.
I suspect reviewing logs on the other device would reveal the cause (failure to communicate)
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
@malaguna Check your VPN IP pool make sure there is no Ip confilct between Lan IP and VPN IP pool
Go to VPN, L2TP/PPP. Select tab IP Address Pool.
Best practice here is to assignd your Lan DCHP ex: 192.168.1.10 through 192.168.1.200
VPN IP pool 192.168.1.201 through 192.168.1.210
Double check and make sure no devices in either lan had beein assigned manaully with a static ip from your VPN IP pool
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 11295
Replies: 19
Voters 0
No one has voted for it yet.