er605 client to LAN VPN setup - tunnel active but no access to remote network

er605 client to LAN VPN setup - tunnel active but no access to remote network

er605 client to LAN VPN setup - tunnel active but no access to remote network
er605 client to LAN VPN setup - tunnel active but no access to remote network
2025-06-26 14:20:34 - last edited 2025-06-30 01:11:23
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.0 Build 20250428 Rel.18967

I have two ER605s:

 

One (Router 1) running an OpenVPN server on a non-NAT network with a static IP address.  This is accessible through the Windows OpenVPN client.  I can connect, I can see the remote network, I can see the internet, my public IP address is the one on the remote network - exactly what I want.  I've also set up a GL-iNet router to connect to this OpenVPN server, and I can see mostly what I need, although the internet DNS isn't working properly, I didn't labour on that too much as I only connected it to see if it would connect.

The other (Router 2) is running an OpenVPN client on a dynamic IP address, behind NAT.

 

I'm trying to connect Router 2 to the Router 1 network and no matter what I do, I cannot see the remote network in any way.  I've followed various sets of instructions to connect these two routers, but none of them ever seemed to fit my scenario exactly so I'm convinced that in my translation to my scenario, I'm missing something.

 

This is my tunnel list, it's showing as working there:

This is the client set up:

Any pointers on what else I might need to change?  Or any more information needed?

 

Thanks

 

Dave

  0      
  0      
#1
Options
1 Accepted Solution
Re:er605 client to LAN VPN setup - tunnel active but no access to remote network-Solution
2025-07-15 22:22:22 - last edited 2025-07-15 22:22:26

  @David-Mc 

 

Eventually, after much messing, I scrapped one of my er605s and got a fr205 and that one works using an OpenVPN client/server setup.

 

So no reeal fix except maybe the er605 is faulty

Recommended Solution
  0  
  0  
#12
Options
11 Reply
Re:er605 client to LAN VPN setup - tunnel active but no access to remote network
2025-06-26 15:17:31

  @David-Mc 

 

Which OpenVPN Server are you using? If you import the OVPN file to your PC, do you get a username and password or just a password when you log in to the OpenVPN server?

 

  0  
  0  
#2
Options
Re:er605 client to LAN VPN setup - tunnel active but no access to remote network
2025-06-26 15:50:36

  @MR.S 

 

Thanks for your response.  This is the setup for the other er605 that's running the OpenVPN server:

 

  0  
  0  
#3
Options
Re:er605 client to LAN VPN setup - tunnel active but no access to remote network
2025-06-26 15:54:13

  @David-Mc 

 

if you try from an OpenVPN client from the pc then? does it work? vpn ip pool should not overlap any of the other networks you have, use an ip pool that is not in use elsewhere

 

 

  0  
  0  
#4
Options
Re:er605 client to LAN VPN setup - tunnel active but no access to remote network
2025-06-26 16:21:53
Hi, yes, from the OpenVPN client on my PC, the connection works fine.
  0  
  0  
#5
Options
Re:er605 client to LAN VPN setup - tunnel active but no access to remote network
2025-06-27 01:31:09

  @David-Mc 

David-Mc wrote

I have two ER605s:

 

One (Router 1) running an OpenVPN server on a non-NAT network with a static IP address.  This is accessible through the Windows OpenVPN client.  I can connect, I can see the remote network, I can see the internet, my public IP address is the one on the remote network - exactly what I want.  I've also set up a GL-iNet router to connect to this OpenVPN server, and I can see mostly what I need, although the internet DNS isn't working properly, I didn't labour on that too much as I only connected it to see if it would connect.

The other (Router 2) is running an OpenVPN client on a dynamic IP address, behind NAT.

 

I'm trying to connect Router 2 to the Router 1 network and no matter what I do, I cannot see the remote network in any way.  I've followed various sets of instructions to connect these two routers, but none of them ever seemed to fit my scenario exactly so I'm convinced that in my translation to my scenario, I'm missing something.

 

This is my tunnel list, it's showing as working there:

 

This is the client set up:

 

Any pointers on what else I might need to change?  Or any more information needed?

 

Thanks

 

Dave

If you want to create a site-to-site, you should set the IPsec.

The config looks good for both sites.

Are you able to ping the other site gateway IP address? 

  0  
  0  
#6
Options
Re:er605 client to LAN VPN setup - tunnel active but no access to remote network
2025-06-27 07:55:35

  @Clive_A 

 

I did initially try the site-to-site IPSec option but because I'm behind NAT/dynamic IP address on one site, and the case study in the instructions was based on static IP at both ends, I didn't/couldn't work out the substitutions I needed to make.  Is this actually possible without static at both ends? 

 

I can't remember if I could ping the other gateway, I'll check that.

  0  
  0  
#7
Options
Re:er605 client to LAN VPN setup - tunnel active but no access to remote network
2025-06-27 08:10:29

  @David-Mc 

David-Mc wrote

  @Clive_A 

 

I did initially try the site-to-site IPSec option but because I'm behind NAT/dynamic IP address on one site, and the case study in the instructions was based on static IP at both ends, I didn't/couldn't work out the substitutions I needed to make.  Is this actually possible without static at both ends? 

 

I can't remember if I could ping the other gateway, I'll check that.

SD-WAN then. SD-WAN could be an option for the site that does not have a public IP.

  0  
  0  
#8
Options
Re:er605 client to LAN VPN setup - tunnel active but no access to remote network
2025-06-28 06:27:09

  @David-Mc 

 

Site-to-site IPsec vpn works fine if one site is a dynamic IP, as long as one end is a static ip

 

You set the dynamic IP end as the initiator, and the static IP end as the responder with the "remote gateway" set to 0.0.0.0

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#9
Options
Re:er605 client to LAN VPN setup - tunnel active but no access to remote network
2025-06-29 15:19:58

  @GRL 

 

Hi

 

I tried that previously and I couldn't get past the error: For an IPsec policy with the same IP address at both ends, the parameters in Phase-1 should be kept the same.

 

As soon as I took out 0.0.0.0 and put in a random IP address the error stopped but obviously that's not what I want.  Do you know what the above error message means?

  0  
  0  
#10
Options
Re:er605 client to LAN VPN setup - tunnel active but no access to remote network
2025-06-29 15:26:41 - last edited 2025-07-15 22:22:50
Ignore this one, I just found out that having an L2TP VPN on there caused this.
  0  
  0  
#11
Options