Cannot access multiple network via a pair of ER6120 IPSec VPN (solved)

Cannot access multiple network via a pair of ER6120 IPSec VPN (solved)
Cannot access multiple network via a pair of ER6120 IPSec VPN (solved)
2019-05-18 08:38:25 - last edited 2019-05-18 16:17:52
Model: TL-ER6120
Hardware Version: V3
Firmware Version: 3.0.1 Build 20180724 Rel.80086

Hi all,

We have set up an IPSec LAN to LAN VPN according to doc and KB (see below) but we found that devices can only access the other site's first network which belongs to ER6120 VPN router.

We followed the KB below for our setup:
How to configure IPSec LAN to LAN VPN for multiple subnets using the new GUI (Site A and B)
How to build up a multi-nets network via Multi-Nets NAT feature on TP-Link router with L2+/L3 switches?  (Site A)

Site A:

  • 192.168.2.0 (ER6120 router's subnet)
  • 192.168.7.0 (TL2600 L3 subnet)
  • 192.168.51.0 (TL2600 L3 subnet)

 

Device within these 3 subnets can access each other and access Internet without problems.

 


Site B: (only single subnet)

  • 192.168.6 0 (ER6120 router's subnet)

 

Device access Internet without problems.


Symptom

  • Device at 192.168.2.0 and 192.168.6.0 can access each other without problems.
  • Site B device (i.e. 192.168.6.0) can only access devices at site A in 192.168.2.x,  but not 7.x and 51.x
  • Since Site B has one subnet only, we can't test if .2.x can access site B other than .6.x

 

One very strange finding at site A TL2600

  • TL2600 at Site A itself cannot access subnet other than 2.x, 7.x and 51.x, we test via its web GUI
  • But TL2600 has default gateway setup, and devices in Site A can access Internet without problem
  • So TL2600 is able to route traffic to default gateway (ER6120 at site A), but not traffic from itself?

 

We are not sure if the strange finding is the root cause of the problem, we have tried to add static route at both ER6120 but no help.  Any ideas?  Any additional information required?  Thank a lot all in advance!

 

 

UPDATE: after look at the configuration, finally we figure out that we didn't setup the IPSec VPN for the 7.x 51.x subnet to 6.x subnet respectively.  After setup the IPSec VPN to and from these subnet, everything works!   (Yet TL2600 still cannot ping anything outside its local network - 2.x, 7.x 51.x)
 

1
1
#1
Options
2 Replies
Re:Cannot access multiple network via a pair of ER6120 IPSec VPN (solved)
2019-05-20 08:34:42

Did you configure Multi-NET NAT? I think it should be enough to work fully. I still do not understand, how you setup 3 IPSEC's with different subnets)) if you could share, I would be appreciate.

0
0
#2
Options
Re:Cannot access multiple network via a pair of ER6120 IPSec VPN (solved)
2019-05-20 11:36:41

Hi bertson85

 

You are so great. As you said, we need to configure three VPN tunnels for the different subnets. And I think you still have configured the static routing on site A L3 switch, L3 switch needs to forward the data which destination is site B. So it needs the static routing to forward these data to the router then the data can be forward to VPN tunnel. 

0
0
#3
Options