ER605 VPN Router

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

ER605 VPN Router

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
ER605 VPN Router
ER605 VPN Router
2022-09-07 11:34:30
Model: ER605 (TL-R605)  
Hardware Version: V1
Firmware Version: 1.2.1

Hi,

 

I have a little problem with a ipsec tunnel.

I connect from my router to a Fortigate 100E firewall.

Without problems i can set up my ipsec tunnel, but it only works for 1 remote subnet.

When I add a second one than this subnet is not reachable.

If I change the sequence of my 2 remote subnets, than it it's the other one who isn't accessable.

If I do a tracert to a device in the second remote subnet, he goes outside en not through de ipsec tunnel.

Any idea what goes wrong?

A bug?

 

kind regards,

Frederik

  0      
  0      
#1
Options
6 Reply
Re:ER605 VPN Router
2022-09-08 05:21:12

  @wiwisjtb 

 

I have the same problem against Cisco firewalls, I solved this by creating a VPN profile for each subnet on ER605. you must use the same encryption and password on all tunnels to make it work.

 

  0  
  0  
#2
Options
Re:ER605 VPN Router
2022-09-09 01:05:20 - last edited 2022-10-13 10:29:58

EDIT

  0  
  0  
#3
Options
Re:ER605 VPN Router
2022-09-09 06:12:43

  @wiwisjtb 

 

This is a bit of a strange question, how exactly is the subnet set up?
Is it on the same network segment as the DHCP address pool or is it on a different segment?
Can you give an example and describe it briefly?

 

Does Unreachable mean that the second VPN tunnel cannot be set up?

 

Do you want to build two IPsec VPNs between ER605 and Fortigate 100E firewall?
What is the need for such a setup? I'm a bit curious as to why it's used in this way? To use as a backup?

 

 

Just striving to develop myself while helping others.
  0  
  0  
#4
Options
Re:ER605 VPN Router
2022-09-09 09:49:01

  @shberge 

Didn't work: The local subnet and remote subnet cannot overlap with those of existing Ipsec VPN policies.

  0  
  0  
#5
Options
Re:ER605 VPN Router
2022-09-09 09:50:25
I already tried this, didn't work either.
  0  
  0  
#6
Options
Re:ER605 VPN Router
2022-09-09 09:54:32
Subnetst are different. Location A is 172.20.x.x, location B is 10.0.x.x and 192.168.x.x The tunnel gets up, but only the first subnet is reachable. (10.0.x.x) If I change the remote segment, than 192.168.x.x is reachable and 10.0.x.x not.
  0  
  0  
#7
Options