IKEv2 IpSec Site2Site with multiple Remote Subnets not working

IKEv2 IpSec Site2Site with multiple Remote Subnets not working

IKEv2 IpSec Site2Site with multiple Remote Subnets not working
IKEv2 IpSec Site2Site with multiple Remote Subnets not working
2025-07-31 18:10:08 - last edited 2025-08-01 05:20:08
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.0 Build 20250428 Rel.18967

Hi there,

 

I have setup a S2S to my LANCOM Gateway at Work. My Main Subnet ist working. I have added another Remotesubnet on my Controller for that tunnel. As i can see unter Insights->VPN Status, there is no other route added for the second Subnet. Communication through the Tunnel with the first is working properly but the second remote Subnet is still not reachable. 

 

Anyone having the same issue or got some advise?

 

 

Greetings

 

Felix

  0      
  0      
#1
Options
1 Accepted Solution
Re:IKEv2 IpSec Site2Site with multiple Remote Subnets not working-Solution
2025-08-01 05:12:30 - last edited 2025-08-01 05:20:08

  @Exylian 

 

I have the same problem with Cisco firewalls, you have to create a tunnel for each network you are going to have in the VPN tunnel. So you have to create a new tunnel where everything is the same except for the remote network.

 

Like this

 

 

 

 

 

 

 

Recommended Solution
  0  
  0  
#4
Options
7 Reply
Re:IKEv2 IpSec Site2Site with multiple Remote Subnets not working
2025-08-01 00:50:15

  @Exylian 

I am not sure what you mean. If you can provide details, it would be better.

If the remote subnet is not accessible, you can consider pinging the remote gateway to verify if it is a problem with the VPN tunnel or your client. 

 

You can refer to this:

  0  
  0  
#2
Options
Re:IKEv2 IpSec Site2Site with multiple Remote Subnets not working
2025-08-01 04:48:03

  @Clive_A 

 

Thank you for your reply!

 

I'll attach some Screenshots to be more specific.

 

S2S Setup with two Remote Subnets S2S Setup with two Remote Subnets

  Insight Status is only showing the first Remote Subnet routed
  First Subnet ist Reachable via Ping from my ER605

 

Second Subnet not Reachable

 

 

For testing purpose my Remote Side (Lancom Gateway) is accepting all adresses (0.0.0.0/0)

My local Network is 192.168.40.254 / 28

My ProviderGateway is 192.168.178.254

Remote Networks are 192.168.147.0/24 & 192.168.66.0/24

 

Hope this makes it more clear :)

  0  
  0  
#3
Options
Re:IKEv2 IpSec Site2Site with multiple Remote Subnets not working-Solution
2025-08-01 05:12:30 - last edited 2025-08-01 05:20:08

  @Exylian 

 

I have the same problem with Cisco firewalls, you have to create a tunnel for each network you are going to have in the VPN tunnel. So you have to create a new tunnel where everything is the same except for the remote network.

 

Like this

 

 

 

 

 

 

 

Recommended Solution
  0  
  0  
#4
Options
Re:IKEv2 IpSec Site2Site with multiple Remote Subnets not working
2025-08-01 05:21:06

  @MR.S 

 

Thank you for that guidance. Actually that works but feels weird and wrong.

  0  
  0  
#5
Options
Re:IKEv2 IpSec Site2Site with multiple Remote Subnets not working
2025-08-01 05:50:04

  @Exylian 

 

YES I agree, I don't really know why that is like this, I see that on Unifi I can choose between router based and policy based VPN, Unifi against Unifi must use Router based, the same with Unifi against Omada, but Unifi against Cisco must use Policy Based, so it seems like there is a default on Omada which is Router Based VPN, I don't know :-)

 

 

 

 

 

 

  0  
  0  
#6
Options
Re:IKEv2 IpSec Site2Site with multiple Remote Subnets not working
2025-08-01 17:10:22

just curious, as i dont have a cisco to muck around with

On the cisco, do you have to add subnets to the VPN as a interface/vlan (like Omada "Networks") or can you add them by IP, and can you not supernet them into a larger IP range per single tunnel ?

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#7
Options
Re:IKEv2 IpSec Site2Site with multiple Remote Subnets not working
2025-08-01 17:33:51

  @GRL 

 

you don't add interface but ip or network objects , yes you can add supernet, groups with ip. there is a lot more choice than on Omada, but it is also more complicated. you can nat vpn tunnels all the way. so if you have the same ip net on two sites you can use nat in vpn to solve that problem. but i like working with different ip net on different sites. it makes things much easier :-)

 

but with Cisco you can create as many ip groups or port groups as you want, I've never been told that I can't create more groups because now you've used up the 16 you have available. so those aren't the problems I struggle with on Omada

 

 

 

 

  0  
  0  
#8
Options