Forward Port through VPN as interface

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Forward Port through VPN as interface

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Forward Port through VPN as interface
Forward Port through VPN as interface
2023-05-19 23:31:54 - last edited 2023-05-19 23:32:59
Model: ER7212PC  
Hardware Version: V5
Firmware Version: 1.0.3 Build 20230314 Rel.21018

I'm trying to do exactly what OP was trying in https://community.tp-link.com/en/smart-home/forum/topic/538506

 

However I have a different router and the solution doesn't seem to apply.

 

My ER router is on a vpn as a client. It has the vpn ip 192.168.1.235. I am trying to forward ports to an ip camera on the router (192.168.0.101). So that if a machine on the VPN goes to my router's vpn ip address it will hit the ip camera. I've forwarded ports but it only seems to work through the router's local WAN IP (192.168.2.161). On the router's port forwarding UI there is an interface drop down, I can select my WAN ports but I cannot select my VPN connection.

 

Is there a way to do this?

 

Thanks,

  0      
  0      
#1
Options
9 Reply
Re:Forward Port through VPN as interface
2023-05-20 02:37:49

  @tantonj 

 

you cannot use port forward to route through the VPN, you must use policy route, which you can find here.

settings, transmition, routing and policy routing

  0  
  0  
#2
Options
Re:Forward Port through VPN as interface
2023-05-20 03:26:12 - last edited 2023-05-20 03:26:52

  @shberge Thanks for the suggestion. I've tried this already, but wasn't sure if I was doing it correctly. Below is a screenshot of my policy. The ip group "ip camera" has the subnet 192.168.0.101/32 (the local ip of the ip camera). However when i try to navigate to my router's vpn ip it does not bring up the ip camera. Any idea what I could be doing wrong here? Thanks,

  0  
  0  
#3
Options
Re:Forward Port through VPN as interface
2023-05-20 03:59:39

  @tantonj 

 

but I'm not quite sure if I understand your setup. if you have a working VPN tunnel, it is not necessary to do anything more if you only want to have access to a camera on a remote site.
remember that when you use the vpn client on the router it is the site client and camera have to be on the site that have vpn server.
if the vpn does not work, you should see in the documentation how vpn is set up, on page 140 the vpn description starts.

 

https://static.tp-link.com/upload/manual/2023/202305/20230516/1910013343_Omada%20SDN%20Controller_User%20Guide_REV5.9.0.pdf

 

when vpn work you should could ping camera on remote site, there is no need for port forward or policy route.

 

  0  
  0  
#4
Options
Re:Forward Port through VPN as interface
2023-05-20 04:07:08

  @shberge 

You have it backwards.

 

The ip camera is on my local network (client of my vpn router). The VPN router has an active client session with a vpn server elsewhere in the world. I can ping any machine on the vpn network. However, I'm trying to get the machines on the vpn network to be able to view MY ip camera. With the vpn router connected to the vpn only the router has a vpn ip. The clients of my ER router do not have their own vpn ips, so machines on the vpn network cannot directly talk to these devices.

 

Theoretically I could just make my own vpn server and have the machines I need to reach my ip camera become clients of that vpn. However, my isp does not let me do this as I'm on a rural wireless internet service and dmz/port forwarding does not work. So my hope was to redirect traffic going towards my vpn router's vpn ip to one of it's clients (my ip camera).

 

I'm guessing the routing policy does not work in this direction. And port forwarding doesn't have the vpn connection as an option on the interface. 

  0  
  0  
#5
Options
Re:Forward Port through VPN as interface
2023-05-20 04:14:58

  @tantonj 

 

ok, understand a bit more now :-) i.e. you cannot route traffic from a VPN Server to a client. so you can just forget about it..
there are occasional exceptions, it is the tp-link omada router which is the vpn server and if it is a server you have control over then you can set up working mode as routing, this also requires that you have a user on the server who is also configured as routing client.

this way you can create a site-to-site with pptp or l2tp vpn, then the traffic will flow both ways

 

  0  
  0  
#6
Options
Re:Forward Port through VPN as interface
2023-05-20 04:19:57

  @shberge 

I do have full control of the vpn server. However it is not tp-link omada or even a router. The VPN server is a windows 2019 server. It currently hosts both a pptp and an l2tp vpn. Do you think this is possible with windows vpn? (I'll need to research site-to-site with windows). I'll also note my router can connect to the server through pptp but not through l2tp (despite using windows vpn client able to connect to both).

 

But I'm really not trying to route traffic from a VPN Server TO a client. The vpn router has an ip address on the vpn, so why can't the router just forward that to one of it's clients?

  0  
  0  
#7
Options
Re:Forward Port through VPN as interface
2023-05-20 04:31:49

  @tantonj 

 

client to server is a one-way communication that is triggered by the client, that's just the way it is. I don't know if you can use windows server in the same way as two tp-link routers. it must then have routing mode to work as you think.

 

Have you tried port forwarding in the usual way then? if it's just a camera, you can use NAT from WAN to LAN. it is not so secure, but you can approve only remote IP in the NAT rule.

 

If you have a dynamic IP, you can use a ddns service such as no-ip

 

 

 

 

 

  0  
  0  
#8
Options
Re:Forward Port through VPN as interface
2023-05-20 04:38:03

  @shberge 

Indeed I have tried all of that (even signing up for paid no-ip account). However, I am on a wireless home internet service. The modem/router's dmz/port forwarding doesn't work. Basically the reason is that my public ip isn't actually my public ip it's like trying to port forward on your lte connection. Not going to work. I even hacked my attena a bit and found another gateway behind my modem/router. Only to see that it's just yet again another gateway before hitting the tower. Basically I can't port forward until the red team hooks up the fiber line (currently my wireless provider is the blue team). Oh the joys of the highly regulated duopoly that is Canadian telecom.

 

Looks like I'm out of luck for now. (Red team has the fiber box on the side of my house, the fiber line down the road, and a cable coiled up at the front of my driveway waiting for someone to come by and hook it up to the node)

  0  
  0  
#9
Options
Re:Forward Port through VPN as interface
2023-05-20 04:45:46

  @tantonj 

 

yes then it will be difficult until you get an internet line with a wan ip on your router. but you can check if you have the option of routing on pptp on the windows server, I don't think so but I don't know. if you have two Omada-compatible routers, it is quite easy to get routing with pptp or l2tp

 

  0  
  0  
#10
Options

Information

Helpful: 0

Views: 507

Replies: 9

Related Articles