L2TP tunnel between two sites not allowing all traffic

L2TP tunnel between two sites not allowing all traffic

L2TP tunnel between two sites not allowing all traffic
L2TP tunnel between two sites not allowing all traffic
Thursday - last edited Friday
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.0

Hi,

for the past couple days I have been trying to fix a L2TP site to site connection between two ER605's both managed by the same Omada controller.
A couple days ago, the connection between the two sites started sporadically failing. Since then I have re-created the Tunnel, but I was unable to restore normal operation.

My setup:
Two sites,:

  • A with a public static IP 
  • B behind a CG NAT

Both have a ER605, same hardware and software version. Both are managed using a Omada Software controller (Version: 5.15.24.19)

 

Site A has the following VPN server config:

And the following user for Site B:

 

Site B has the following VPN client config:



Now, with this config I can see the VPN tunnel under Insights > VPN. Both IPSEC and L2TP.
I can also ping machines from A to B and the other way round. I can ssh from B to A, but not the other way round. I cannot access any HTTP resources in either direction.
So the tunnel must be at least partially working, as the ICMP packets are getting trough, but somehow HTTP and SSH in one direction is blocked.

Does anyone have any advice on this matter? I was unable to gleam any useful information from the logs.

  0      
  0      
#1
Options
1 Accepted Solution
Re:L2TP tunnel between two sites not allowing all traffic-Solution
Friday - last edited Friday

  @Perondas 

Consider a firewall setting on your system which blocks the access. 

Recommended Solution
  1  
  1  
#3
Options
4 Reply
Re:L2TP tunnel between two sites not allowing all traffic-Solution
Friday - last edited Friday

  @Perondas 

Consider a firewall setting on your system which blocks the access. 

Recommended Solution
  1  
  1  
#3
Options
Re:L2TP tunnel between two sites not allowing all traffic
Sunday
I have attempted connections from multiple devices, I am certain that the issues is the network, not the end devices.
  0  
  0  
#4
Options
Re:L2TP tunnel between two sites not allowing all traffic
Sunday

  @Perondas 

Perondas wrote

I have attempted connections from multiple devices, I am certain that the issues is the network, not the end devices.

Then try the Wireguard instead. Let's see. 

  0  
  0  
#5
Options
Re:L2TP tunnel between two sites not allowing all traffic
Sunday

  @Perondas 

 

Do you have an WAN-IN or LAN>WAN gateway ACLs at either site blocking ports 22. 80 or 443? - or if the devices are behind a L2+ / L3 switch do you have any switch rules blocking the same?

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#6
Options