Limited LAN Access via VPN (ER706W-4G / WireGuard) – Omada Controller Not Reachable

Limited LAN Access via VPN (ER706W-4G / WireGuard) – Omada Controller Not Reachable

Limited LAN Access via VPN (ER706W-4G / WireGuard) – Omada Controller Not Reachable
Limited LAN Access via VPN (ER706W-4G / WireGuard) – Omada Controller Not Reachable
2025-05-14 21:55:57
Model: ER706W-4G  
Hardware Version: V1
Firmware Version: ER706W-4G_V1_1_0 3.20241021.58644(4555)

Hi everyone,

last week I deployed a brand-new ER706W-4G router at my remote office to replace an older device. It’s currently running with an OC200 Controller, and everything has been working fine so far. However, I’ve run into a strange issue I’m hoping someone can help with.

I’m currently using the 4G connection exclusively for testing purposes and haven’t added a second WAN connection yet. For remote management, I set up a VPN connection using WireGuard. The handshake is successful, and I can connect to the network without any problems.

The issue is that I can only reach some devices on the local network — mainly simple web-based interfaces like those of IP phones — but not all. Strangely enough, I can access the router’s admin interface, but not the Omada Controller, which is on the same subnet.

I’ve tested this setup in both standalone and controller-managed modes, using both WireGuard and SSL VPN — same results in both cases. There are no ACLs in place, and the router configuration is still close to factory defaults.

Could this be related to the 4G connection? I do receive a public IPv4 address from the mobile provider.

Any suggestions or insights would be greatly appreciated. Thanks in advance!

Best regards

  0      
  0      
#1
Options
5 Reply
Re:Limited LAN Access via VPN (ER706W-4G / WireGuard) – Omada Controller Not Reachable
2025-05-14 22:49:15

  @Schwaus 

 

Have you added all necessary IP ranges / NEtworks to the "local networks" config of the VPN?

 

 

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#2
Options
Re:Limited LAN Access via VPN (ER706W-4G / WireGuard) – Omada Controller Not Reachable
2025-05-15 01:45:44

Hi  @Schwaus 

Schwaus wrote

Hi everyone,

last week I deployed a brand-new ER706W-4G router at my remote office to replace an older device. It’s currently running with an OC200 Controller, and everything has been working fine so far. However, I’ve run into a strange issue I’m hoping someone can help with.

I’m currently using the 4G connection exclusively for testing purposes and haven’t added a second WAN connection yet. For remote management, I set up a VPN connection using WireGuard. The handshake is successful, and I can connect to the network without any problems.

The issue is that I can only reach some devices on the local network — mainly simple web-based interfaces like those of IP phones — but not all. Strangely enough, I can access the router’s admin interface, but not the Omada Controller, which is on the same subnet.

I’ve tested this setup in both standalone and controller-managed modes, using both WireGuard and SSL VPN — same results in both cases. There are no ACLs in place, and the router configuration is still close to factory defaults.

Could this be related to the 4G connection? I do receive a public IPv4 address from the mobile provider.

Any suggestions or insights would be greatly appreciated. Thanks in advance!

Best regards

You can use these guides to troubleshoot:
Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced. ● I don't provide ETA for any products/features. No comment.
  0  
  0  
#3
Options
Re:Limited LAN Access via VPN (ER706W-4G / WireGuard) – Omada Controller Not Reachable
2025-05-15 17:17:49

  @GRL 

 

I think so. Iam currently testing with Wireguard. So to get things a little bit more precise this is my Network:

 

LAN-Range: 192.168.99.xxx/24

IP-Adress ER706 in LAN: 192.168.99.250

Wireguard Network: 192.168.90.xx

Wireguard Local Adress of Router: 192.168.90.1 (Screenshots below)

 

This is my configuration on the Client:

[Interface]
PrivateKey = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Address = 192.168.90.10/32
DNS = 9.9.9.9, 1.1.1.1

[Peer]
PublicKey = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
AllowedIPs = 0.0.0.0/0
Endpoint = my.domain.xx:51820

 

And this is the Wireguard-config on the ER706W:

 

 

Ive deleted the Public Key for the Screenshot.

 

Handshake works well and i see traffic going through the tunnel. I can ping the Router and also open the management webinterface at 192.168.99.250 and some of my lan devices like an IP-Phone on 192.168.99.50 or so but nothing else. I got a PBX on 192.168.99.4 that doesnt work and a webserver on 192.168.99.45 neither.

 

When try to ping a host on the net that i cannot open i get a timeout, ping to my IP-Phone on 192.168.99.50 works well.

 

The same behaviour is seen when i switch to the DSL line on the router, so it is not a fault of the 4G connection.

  0  
  0  
#4
Options
Re:Limited LAN Access via VPN (ER706W-4G / WireGuard) – Omada Controller Not Reachable
2025-05-15 17:26:04

  @Clive_A 

 

Thank you for the guides!

 

I worked through but no luck.

 

I can connect to VPN, Handshake works well and i see traffic coming through. Firewalls and Anti-Virus is off for testing. I can ping the internal LAN Adress of my Router at 192.168.99.250 and some of the other Devices (mainly webservers) when connected to VPN.

Currently im testing wireguard with a static ip on 4G and a DDNS config on my DSL line, but they both got the same results. I really have no ideas left.

  0  
  0  
#5
Options
Re:Limited LAN Access via VPN (ER706W-4G / WireGuard) – Omada Controller Not Reachable
2025-05-16 00:30:32

  @Schwaus 

Schwaus wrote

  @Clive_A 

 

Thank you for the guides!

 

I worked through but no luck.

 

I can connect to VPN, Handshake works well and i see traffic coming through. Firewalls and Anti-Virus is off for testing. I can ping the internal LAN Adress of my Router at 192.168.99.250 and some of the other Devices (mainly webservers) when connected to VPN.

Currently im testing wireguard with a static ip on 4G and a DDNS config on my DSL line, but they both got the same results. I really have no ideas left.

Looks like it's merely a config problem from your other reply to GRL.
If you have not tried any sort of config video or guide, that's why.

It's not a problem with the router/clients. Just a misconfig. Wireguard is not easy for a new user who has not used OVPN before. All the stuff gotta be scripted yourself.

 

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced. ● I don't provide ETA for any products/features. No comment.
  0  
  0  
#6
Options