Using ER605 as VPN client for streaming devices

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Using ER605 as VPN client for streaming devices

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Using ER605 as VPN client for streaming devices
Using ER605 as VPN client for streaming devices
2023-11-21 14:40:47 - last edited 2023-11-22 00:58:11
Tags: #VPN
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2.2_20231017-rel68869

Please bear with me as I am a networking noobie!


I have introduced an ER605 in my home network for the purposes of having my streaming devices on NordVPN - see diagram below. 

 

Basically the below setup is working including the VPN setup which allows me to view geoblocked content on the streaming devices. However, in order to easily enable and disable VPN's on the ER605 (i.e. switch countries or disable the VPN), I would like to implement some SSH scripting which controls this but which can be run from within the 192.168.10.xxx network.

 

I have tried to setup a static route on the Verizon Router, and it works in the sense that I can ping 192.168.11.1 (ER605) from a device on 192.168.10.xxx, however I can not browse to 192.168.11.1 (e.g. manage the ER605 using a browser) or telnet/SSH etc. Since the ER605 already is behind the Verizon router I am fine with disabling the firewall on the ER605 if that will make it work (if so how?)

 

Any idea how to make this happen?

 

  0      
  0      
#1
Options
7 Reply
Re:Using ER605 as VPN client for streaming devices
2023-11-21 23:56:13 - last edited 2023-11-22 02:15:29

  @mrwassen 

 

Check this post for ER605 remote management configuration. You just need to add there 192.168.10.0/24 network.

If this was helpful click on the arrow pointing upward to make it blue. If this solves your issue, click the star to make it blue and mark the post as a "Recommended Solution".
  2  
  2  
#2
Options
Re:Using ER605 as VPN client for streaming devices
2023-11-22 02:10:01

Hi @mrwassen 

Thanks for posting in our business forum.

If your IP is 192.168.10.0/24, you want to browse the ER605 admin page, use the ER605 WAN IP, 192.168.10.254, and make sure you have enabled Remote Management.

If SSH and from 192.168.10.0/24, you should SSH the IP address 192.168.10.254.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#3
Options
Re:Using ER605 as VPN client for streaming devices
2023-11-22 05:17:43

Thanks both for the suggestions. The good news is that I now can access the router from the 192.168.10.xxx network and open an SSH session.

 

The potentially bad news is that after getting access to the command line, I was unable to find any CLI commands that allow me to manage the configured VPN's. My last hope is that there are some undocumented commands - if not, it seems I will not be able to get to my goal which was to manage the VPN's using scripting :-(.

 

If such VPN related commands are not available on this particular device, could somebody suggest a different device? (there are still 28 days left in the Amazon return window :-))

 

Any help appreciated.

  0  
  0  
#4
Options
Re:Using ER605 as VPN client for streaming devices
2023-11-23 01:33:01

Hi @mrwassen 

Thanks for posting in our business forum.

mrwassen wrote

The potentially bad news is that after getting access to the command line, I was unable to find any CLI commands that allow me to manage the configured VPN's. My last hope is that there are some undocumented commands - if not, it seems I will not be able to get to my goal which was to manage the VPN's using scripting :-(.

CLI guide: https://static.tp-link.com/upload/manual/2023/202307/20230725/1910013378_ER605(UN)2.0_CLI.pdf 

 

If there are no lines mentioning the VPN type you use, or enable/disable it, then we don't provide that line. 

 

mrwassen wrote

If such VPN related commands are not available on this particular device, could somebody suggest a different device? (there are still 28 days left in the Amazon return window :-))

 

Any help appreciated.

 

You may take a look at the open source software like pfSense. Or other pre-build brands like UBNT or Mikrotik. They seem to fully support all configs in command-line mode. Try them out before you make the final choice.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#5
Options
Re:Using ER605 as VPN client for streaming devices
2023-11-23 20:29:26

Thanks again. I ended up implementing a laughably low-tech solution. I will keep the ER605 in place as the VPN client, then insert a $10 ethernet switching device allowing the streaming device switch between the regular network switch or the VPN router (in order to "switch countries"). 

 

On a related note though, I had one more question (also with reference to the diagram in my initial post):

 

Is there any way to allow resources on the 192.168.10.xxx network to access devices on the 192.168.11.xxx network, e.g. RDP sessions. (The opposite direction seems to work fine).

 

I have experimented with setting up static routes on the Verizon router, but am not able to get it to work. Is there a firewall on ER605 I can disable or open a port on?

  0  
  0  
#6
Options
Re:Using ER605 as VPN client for streaming devices
2023-11-23 23:32:38

  @mrwassen 

 

Try configuring a virtual server on ER605 and test if that works for you:

 

If this was helpful click on the arrow pointing upward to make it blue. If this solves your issue, click the star to make it blue and mark the post as a "Recommended Solution".
  0  
  0  
#7
Options
Re:Using ER605 as VPN client for streaming devices
2023-11-24 07:44:34

Thanks for the suggestion. Is it correct that "Virtual Server" in reality is what is known as port forwarding on consumer grade routers? If so this is helpful to some extent, but I was hoping for a way to get more complete access.

 

So without specifying the target IP on the 192.168.11.xxx network, I would like to simply access any client on the .11 network from the .10 without having to setup individual entries. I was thinking this could be achieved using a (static) routing entry of some sort, but I may be wrong?

 

Thanks

 

Dennis

  0  
  0  
#8
Options