Omada Router as VPN client

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
12

Omada Router as VPN client

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Omada Router as VPN client
Omada Router as VPN client
2023-06-23 20:08:52
Tags: #VPN
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.1.2

Hi! smiley

In Site Settings -> VPN -> VPN:
I'm trying to figure out how to connect this router to an external VPN server of mine.
(This Omada router is connected only through an LTE network, external modem using passthrough to the WAN ethernet port. On this network IPv6 is flaky, and the IPv4 is CGNAT, so I'm looking to setup a connection to be able to get in from the outside.)

 

According to the docs, Site-to-Site is for connecting Omada Sites.

In this case, then, I would have to setup Client-to-Site.

 

So I did setup a Client-to-Site VPN, defining my router as a VPN client - OpenVPN using Certificate.

I specified the IPv4 and port number of the Remote Server and chose WAN as the WAN, and I imported the ovpn config file.
When I hit Apply, it was enabled, and it looks like it's working.


... Except ... Where can I see/utilize this VPN tunnel?
I can't find it anywhere, it's not an available interface in ACL's or anywhere that I can seem to find.
So I don't actually know if it's working/what it's doing (if anything).

There's nothing showing in Insights -> VPN Status -> OpenVPN/PPTP/L2TP -> Client ... So I guess not much is happening.

But how is it supposed to be used/seen?

 

(My preferred VPN setup would be Wireguard, but in Omada it's only WG server, not client, it seems.)

  1      
  1      
#1
Options
12 Reply
Re:Omada Router as VPN client
2023-06-26 07:29:05

  @flips01 

 

Did you use a PC as the OpenVPN client to connect to the server for testing?

Can you ping through the server IP from ER605 LAN after you import the ovpn file?

Just striving to develop myself while helping others.
  0  
  0  
#2
Options
Re:Omada Router as VPN client
2023-06-26 11:41:40

Virgo wrote

  @flips01 

 

Did you use a PC as the OpenVPN client to connect to the server for testing?

Can you ping through the server IP from ER605 LAN after you import the ovpn file?

 

Not sure I follow you. I tried setting the ER605 up as OpenVPN client. It doesn't seem to show up anywhere.

I tried pinging ER605 IP's from the other side to see if there was any connection, but no response.

But I feel blind, there's no info, I dunno how to debug ...

(Or how the client is supposed to act/work? Why should I be able to add a client like this, if I can't use that VPN client interface in ACL rules etc.?)cool

  0  
  0  
#3
Options
Re:Omada Router as VPN client
2023-06-27 01:44:08

  @flips01 

 

There must be something wrong during this procedure. Use a PC to prove the openVPN is working fine, you can open the openVPN GUI on the PC and import the file to test.

I don't think you can choose the VPN tunnel in the ACL rules, at least I can't choose it. 

Just striving to develop myself while helping others.
  0  
  0  
#4
Options
Re:Omada Router as VPN client
2023-06-27 21:34:04

Virgo wrote

  @flips01 

 

There must be something wrong during this procedure. Use a PC to prove the openVPN is working fine, you can open the openVPN GUI on the PC and import the file to test.

I don't think you can choose the VPN tunnel in the ACL rules, at least I can't choose it. 

I confirmed using both macOS version and Android version of OpenVPN Connect that it actually works.

I just can't see how/that it works on the ER605 ...

  0  
  0  
#5
Options
Re:Omada Router as VPN client
2023-06-28 03:08:33

  @flips01 

 

If the settings are correct, the VPN tunnel will be shown on the Controller. What is the OpenVPN server? Did you set it on another router?

Can you share a screenshot of VPN settings on the ER605?

Just striving to develop myself while helping others.
  0  
  0  
#6
Options
Re:Omada Router as VPN client
2023-07-01 15:22:06 - last edited 2023-07-01 18:56:09

The VPN server is a Linux VPS. I can connect to it using OpenVPN connect for Mac and for Android, only import the file, and then it works.

 

Then loading the config in the Omada controller, I have some manual setting in addition to the file.

 

I'm not entirely sure if Local Network Type should be Local Networks, and if so the significance (should I select All, or what does it try to do?

I've tried setting a Custom IP, defining 10.8.0.5/24 (which is what the ovpn client gets when I connect from the other clients, the server has 10.8.0.1/24). I also tried leaving it at Network, and then selecting different networks/VLANs. I even tried creating the 10.8.0.0/24 network in the controller, and selecting that here.

Still doesn't work.

I shows as enabled no matter what I do:

But VPN status is empty:

In the Omada controller/system, I don't see where I can debug/read what it tries.

On the VPN server side, it doesn't look like it's trying/reaching the server at all. (No log entry, like it is if I connect using the Mac or Android phone.)

 

Edit: The only thing I find in the log on the controller (searching for VPN) is stuff like this (showing my config changes)/attempts:

  The LAN(OVPN-client) IP address/mask of MyVPN were changed to 10.8.0.5/255.255.255.0.

Does that mean that the VPN client only tries connecting using the LAN, not the WAN-side?

  0  
  0  
#7
Options
Re:Omada Router as VPN client
2023-07-03 02:39:47

  @flips01 

 

It's weird, maybe the vpn server supports a higher encryption method, but the omada router doesn't.

Here is a new Beta firmware for ER605 V2, you can try to upgrade it to test.

Just striving to develop myself while helping others.
  0  
  0  
#8
Options
Re:Omada Router as VPN client
2023-07-03 08:01:58

  @Virgo 

Thanks, trying that beta, as it also adds IPv6 ACL support, it seems. Also nice to subscribe to that thread to keep up with the changelog ... :)

Just upgraded. Still no contact over VPN, though. (It's no big deal, but if anyone actually uses this OpenVPN client, please chime in.)

It would be nice if I could track a log seeing what it's trying to do ...

  0  
  0  
#9
Options
Re:Omada Router as VPN client
2023-07-03 12:26:30

  @flips01 

I am using ER605 v1 as OpenVPN client and it is working (slow, but working). OpenVPN connection is not shown in Insight - it is really dumb, but tunnel is established.

  0  
  0  
#10
Options
Re:Omada Router as VPN client
2023-07-03 15:15:30

  @Libik Cool, thanks. If you search the log for VPN or ovpn, no entries showing that it's connecting?

I see nothing besides entries telling that I changed the config ... cool

  0  
  0  
#11
Options

Information

Helpful: 1

Views: 1344

Replies: 12

Tags

Related Articles