Cannot connect to L2TP VPN from inside the LAN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Cannot connect to L2TP VPN from inside the LAN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Cannot connect to L2TP VPN from inside the LAN
Cannot connect to L2TP VPN from inside the LAN
2014-04-27 04:13:59 - last edited 2021-08-21 03:56:13
Region : UnitedStates

Model : TL-ER6120

Hardware Version : V1

Firmware Version :

ISP :


I've got a new network implementation in which I have all wireless LAN communications on a separate VLAN and subnet. That all is working great, but there are instances where we would like to allow some wireless clients to access the primary VLAN. I intended to do this by connecting the clients to the L2TP VPN that is already in place for external employees, however all attempts to connect to the L2TP tunnel from inside the LAN fail.
This fails for clients on either VLAN
[*]PPTP works inside the LAN, but I don't want PPTP active on this router
[*]Credentials and shared keys are correct

[*]L2TP connections from the WAN work great.
[*]Failure seems to be on the encryption negotiation and returns Windows error 789.
[*]We have tested the same laptop from both inside and outside the LAN. The laptop connects fine from outside the network over WAN. Inside the network it fails, even when changing the IP Address to the LAN IP of the router.
[*]I am using the simplest IPSEC L2TP tunnel as defined in the TP-Link documentation and am not using IKE or detailed IPSEC policies.


The router in question is a TP-Link ER6020. I am trying to first solve this issue first within the primary VLAN and am not even involving the secondary VLAN yet so that really isn't a factor. I suspect that this might be a NAT problem of some kind but I am not sure.
  0      
  0      
#1
Options
2 Reply
Which VPN did you use?
2014-04-29 17:16:44 - last edited 2021-08-21 03:56:13
Which VPN did you use?
  0  
  0  
#2
Options
Re:Cannot connect to L2TP VPN from inside the LAN
2014-04-30 23:40:14 - last edited 2021-08-21 03:56:13
I was using the basic L2TP VPN (no IKE). After several days of messaging with TP-Link support it turns out that the firmware on the ER6020 will not allow a VPN client that has an internal IP address to connect to any VPN that requires a Client ID in the tunnel profile. PPTP works because PPTP does not care about the source IP Address of the connecting client. Instead bothing to determine if there will be a conflict of any kind with the device IP, it simply disallows it from joining the tunnel to prevent possible IP conflicts. TP-Link's response was "not the common use of VPN" though I know that there are institutions that use similar setups to restrict access and encrypt network traffic.
  0  
  0  
#3
Options