ER-605 gateways without port forwarding - access to device

ER-605 gateways without port forwarding - access to device

ER-605 gateways without port forwarding - access to device
ER-605 gateways without port forwarding - access to device
2023-10-23 15:33:21 - last edited 2023-11-01 20:38:19
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2

Hello,
I have two locations (Site A, Site B). The goal is: I would like to access the camera of Site B from Site A.

The challenge is that I cannot enable ports at location B or forward them to the respective device (camera). (This is because it is a mobile network).

 

So I will have to choose the way via a VPN. It would be enough if the camera is reachable, it doesn't have to be the entire network of location B at location A that is reachable.
Unfortunately, IPSec does not work: Auto is set up, but it is not visible under Insights. A manual setup fails with error 24. I suspect it is because of the lack of opening ports at Site B.

 

What possibilities do you see for establishing a VPN connection? Are there technologies (OpenVPN?) that do not require port sharing at location B?

 

Thank you and best regards
Christian

 

 

  0      
  0      
#1
Options
9 Reply
Re:ER-605 gateways without port forwarding - access to device
2023-10-24 02:57:43 - last edited 2023-11-01 20:38:19

Hi @CS2 

Thanks for posting in our business forum.

Unfortunately, there is no service supporting VPN without ports forwarding. Think it from the perspective of networking, any communication requires at least an IP and a TCP/UDP to connect and transfer the data/traffic.

 

You should port forward on both modems if you are not getting the public IPs on both Omada routers. (To check if you have a public IP or not, you should check the IP shown on the WAN details. Don't use the whatsmyip to tell. That's not accurate.)

 

You probably set it up wrong if you use the IPsec. Suggest you double-check yourself with the guide we have. Or seek help from the technical support from us.

IPsec, site to site requires a public IP on each site. Client to site VPN requires one of the ends to have a public IP.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Beta firmware got some NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting Manual ★ ☚ (Disclaimer: Short links are used above solely for guidance to TP-Link subdomains and are safe and tracker-free. Exercise caution with short links from non-official members on forums. We are not liable for external content or damage from non-official members' link use.)
  0  
  0  
#2
Options
Re:ER-605 gateways without port forwarding - access to device
2023-10-25 14:26:18

 

 

Following these instructions, an ER-605 could also function as a "wireguard client": https://community.tp-link.com/en/business/forum/topic/603600

This could be the solution.
Unfortunately, you can only enter an IP address in the Endpoint field and not a domain / dynamic DNS. Can the software be adapted so that dynamic addresses are also allowed in this field?


 

  0  
  0  
#3
Options
Re:ER-605 gateways without port forwarding - access to device
2023-10-25 16:22:25

  @CS2 

 

I do this today with a pair of ER605's.

 

My solution is to put the NAT'd ER605 (your cellular site) as the Client, and your DSL site as the Server for an L2TP IPsec VPN.  You can then advertise the local subnets at the remote sites and have full access to devices without any port forwarding needed.  I use DDNS names and not IP's at either end:

 

Here's a snapshot of what my 'client' end looks like:

 

 

<< Paying it forward, one juicy problem at a time... >>
  1  
  1  
#4
Options
Re:ER-605 gateways without port forwarding - access to device
2023-10-25 19:46:42

  @d0ugmac1 Really good, thanks for your tip and idea.

 

I have now established succesfull a VPN connection in this way (remote site (B) as VPN client). This means that the remote ER-605 has the IP address 192.168.16.2 at the main site (site A).

Screenshot vom Insights:

Site A (main):

Site B (remote):

 

Unfortunately, I cannot access the remote devices. Hence my further question: How can I advertise the local subnets from the remote site (Site B) to the main site (Site A)?

Screenshot of the remote ER-605 (site B):

As far as I understand it: I specify which local networks are to be unlocked. I have selected "all". Shouldn't I be able to access it from the main location?

  0  
  0  
#5
Options
Re:ER-605 gateways without port forwarding - access to device
2023-10-25 20:01:16 - last edited 2023-10-25 20:06:06

  @CS2 

 

Your tunnel IPs should be wholly unrelated to the subnets at either end of the tunnel.  In my case, Server has a 10.x.x.x client subnet, Client has several 192.168.x.x client subnets and the tunnel endpoints are 172.16.x.x.  At the client I tell it remote subnet is 10.x.x.x (at the server) and I specify a subset of all the 192.168.x.x subnets present at the Client.  At the server, the opposite, I specify the subnet of 192.168.x.x subnets as remote and the 10.x.x.x as local.

 

Most annoyingly, the remote subnets do NOT show up in the controller routing table under 'Insights'.

 

Key points on the VPN user you configure at the server end...make sure you tick the LAN extension mode:

 

  

<< Paying it forward, one juicy problem at a time... >>
  1  
  1  
#6
Options
Re:ER-605 gateways without port forwarding - access to device
2023-11-01 19:39:31 - last edited 2023-11-02 16:07:47

 

Hello,
Thank you for your explanations,   @d0ugmac1.


Unfortunately, I don't understand it, or rather, as I understand it, it doesn't work.

Let's assume I have the network "LAN" at the remote location (Site B), which I would like to make available to Site A via VPN. To do this, I would have to make the following settings according to your explanations:
Site B:
- 'local networks': selection of "LAN".
- remote subnets: any IP address range which is not occupied.
Site A:
- 'local networks': for simplicity's sake "All".
- IP pool type: ...Mask
- IP pool: any IP address range which is not occupied and is different from that of site B.

 

To make it more concrete, I have the following subnets:

main site (Site A) remote site (Site B)
guests: 192.168.3.1 / 24 guests: 192.168.14.1 / 24
IoT:  192.168.15.1 / 24 IoT: 192.168.50.1 / 24
LAN: 192.168.188.1 / 24 LAN: 192.168.10.1 / 24
Work: 192.168.189.1 / 24 Work: 192.168.13.1 / 24
VPN: 192.168.16.1 / 24  

 

 

I have set the following for the VPN-IPSec:

1. main site (Site A)

1.1 VPN policy

1.2  VPN user


2. remote site (Site B)

2.1 VPN Policy

 

The VPN connection is established according to Insights. With the IP 172.31.151.1 I can access the remote ER-605. (I assume that it is the one from Site B, as I have no access to this IP with the VPN deactivated.)

Bbut where can I see which clients are now connected via VPN? Or which IP address has now been assigned for remotely?

Do you see a mistake in my configuration?

 

Thank you and sorry, I am not familiar with VPN.

  0  
  0  
#7
Options
Re:ER-605 gateways without port forwarding - access to device
2023-11-02 17:21:39

  @CS2 

 

You have selected the wrong VPN type!  Use L2TP or L2TP+IPsec not PPTP.

 

Maybe set up your first tunnel as L2TP (unencrypted), once that's working, then add in the IPsec layer to encrypt the traffic between sites.

<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#8
Options
Re:ER-605 gateways without port forwarding - access to device
2023-11-03 20:07:13 - last edited 2023-11-03 20:08:55

  @d0ugmac1 

 

Oh okay, I thought that PPTP or L2TP was just the encryption or authentication method. I changed it to L2TP encrypted and the VPN tunnel works.
Insights at Site A:

 

Insights at remote site (Site B):

 

But strangely, I don't see the remote end devices as end devices at Site A?
How do I get the IP addresses of the end devices ((e.g. the camera, see architecture figure in the first post)) connected via VPN tunnel?

 

Thank you one again.

  0  
  0  
#9
Options
Re:ER-605 gateways without port forwarding - access to device
2023-11-03 20:17:45 - last edited 2023-11-03 20:19:32

  @CS2 

 

Remote devices don't have local IP's.  The only way that could happen is if each device was able to establish it's own VPN tunnel back to your NAS site (ie each camera was capable of establishing a PPTP or similar client tunnel directly to the main ER605 or NAS).

 

The easy solution is simply to reserve IP's for the devices you need regular remote access to.  So Camera #1 always gets say a .101 IP, and Camera #2 gets .102 in the remote site's local subnet.  You can then point your NAS at the remote IP of the remote cameras just like you would do to a local camera on the local subnet.

 

So:

 

Remote Cam1 192.168.50.101

Remote Cam2 192.168.50.102

Local Cam1 192.168.15.101

Local Cam2 192.168.15.102

etc.

<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#10
Options

Information

Helpful: 0

Views: 432

Replies: 9

Related Articles