Can't connect to PPTP vpn server from outside network (ER7212PC)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Can't connect to PPTP vpn server from outside network (ER7212PC)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Can't connect to PPTP vpn server from outside network (ER7212PC)
Can't connect to PPTP vpn server from outside network (ER7212PC)
2023-05-14 05:43:46
Tags: #VPN
Model: ER7212PC  
Hardware Version: V5
Firmware Version: 1.0.3 Build 20230314 Rel.21018

I have created a Client-to-site VPN PPTP server on my ER7212PC router. This router has the WAN IP of 192.168.2.161. It's wan is connected to a Bell router/modem. This router/modem does have TCP 1723 (In addition to opening this port, I've also added the ER router to the DMZ, essentially opening all ports to this device). I'll note I've tried many different setting configurations including L2TP VPN (with the necessary UDP ports open/DMZ).

 

The ER router has the gateway 192.168.0.1 and on it is an ip camera with the address 192.168.0.101. I can take a device that is not connected to the router and connected to the router/modem and connect to the vpn successfully (both a PPTP and an L2TP VPN). For example if a device is connected to the router/modem, it has an ip address of 192.168.2.X and it cannot talk to the ip camera. Using 192.168.2.161 as the vpn address, this device can connect to the vpn and talk to the ip camera.

 

However, my goal here is to allow a device to connect to the vpn over the internet. My impression is that by opening these ports and/or putting the ER router on the DMZ of my router/modem a client should be able to connect to my VPN through my router/modem's public ip address. When I try this it always fails (timesout) as if it cannot connect.

 

I was hoping someone might have an idea what can be done here.

 

-----------------------------------------------

some more information about the router/network configuration.

This router is also a client to a PPTP vpn. It works, Any client of my ER router can communicate with any device on the VPN it is connected to. That vpn is a windows server vpn on a windows server with a dedicated forward facing ip address. The reason I bought this router was thinking that if I have the router connect to this VPN server my ip camera would get an ip address on that vpn. After communicating with tp-link support, they've told me this is not possible, that only the ER router will get an address on the VPN. Which means no other machine on the vpn can see the ip camera. My idea to achieve this is to have the ER router host it's own vpn, which machines could connect to if they need to see the ip camera. However, the problem above has prevented me from doing this. I thought since the ER router itself holds a vpn address, if a machine is able to communicate with the ER router due to it either being on the vpn or it being on the local network of the vpn server it should be able to use the ER router's vpn address to connect to it's VPN server. However, when I try this, I get the same result. I'll also note that my modem/router has a DIFFERENT IP under it's "WAN IP" than is my public IP (this confuses me). I've tried using both as the vpn's address. All three possible addresses give the same error. I wanted to solve this on the weekend so I don't have to spend more work hours fiddling with this, but tp-link support is only open during business hours. If anyone here has a solution, it would be much appreciated.

 

Thanks,

  0      
  0      
#1
Options
2 Reply
Re:Can't connect to PPTP vpn server from outside network (ER7212PC)
2023-05-14 13:49:22
Find out how to put your modem into bridge mode or, at the very least, reserve an ip for the 7212 and configure the modem's DMZ ip to be the fixed ip of the 7212 wan port. You have a NAT traversal issue, google it.
<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#2
Options
Re:Can't connect to PPTP vpn server from outside network (ER7212PC)
2023-05-14 17:53:02 - last edited 2023-05-14 17:56:21

  @d0ugmac1 Thanks for the response.

 

For multiple reasons Bridge mode is not an option for me.

 

Also, as stated in my post the ER router has a static ip address and it is enabled as the DMZ device for the modem. I should mention something that is a little confusing about the modem's DHCP reservation options. To edit this on the modem's interface one has to go to  My Devices->Edit (specific) Device, The the UI lists multiple properties of the given device, it lets you name the device and select an icon. On any Android device connected, one of the properties is IP Type: and it has a radio button for dynamic or reserved (which lets you set the address if reserved). However for the 2 routers I have connected this property type is IP Type: Static IP. No radio buttons exist and I cannot set this. The IP is always the same but if the power goes out (modem resets) this ip can change.

 

I have 2 routers using the modem's wireless as a WAN. One is a tp-link AC1750 it is setup to connect to the modem through wireless for it's WAN source (this is because I can only have my modem in an inconvenient spot and my work station is in the basement). The AC1750 provides multiple ethernet connections for my workstation/media server and broadcasts the wifi my family's personal devices use. You might be wondering, how is your ER router connected to the modem through wifi? I am using a BrosTrend AC1200 WIFI to Ethernet Adapter to provide my ER router with a WAN connection. It works perfectly. Due to this wireless topology and the fact I need a subnet for personal use not under my ER router, I cannot have my modem in bridge mode. However DMZ should offer what I need without using bridge mode.

 

I will also mention since I posted, I signed up for noip. This is a dynamic-dns service supported by the modem. I have it turned on and the modem says it is synchronized. I figured that if I couldn't connect to the VPN through my public ip (which does change fairly frequently), if I setup DDNS it might work, and if that wasn't the source of the problem it will at least make the vpn more user-friendly once I do solve the problem. However, the VPN is just as unreachable through the DDNS host name as it is through my public ip address.

 

Thanks,

 

  0  
  0  
#3
Options