Site-to-site and client-to-site VPN

Site-to-site and client-to-site VPN

Site-to-site and client-to-site VPN
Site-to-site and client-to-site VPN
2025-11-15 22:28:07 - last edited 2025-11-17 09:42:40
Tags: #VPN
Model: ER707-M2  
Hardware Version:
Firmware Version:

Hi!

 

I have two sites (A and B) connected to each other via IPsec manual and completely managed by an Omada Software Controller located in Site A.

In both sites I use an ER707-M2 as gateway.


Now I have the requirement to add a client-to-site VPN, so clients can connect from remote.

However, adding an L2TP over IPsec server to site A in combination with the existing VPN seems impossible due to incompatible IPsec settings.

 

Is there any way to make this combination of site-to-site and client-to-site VPN work?

 

Thank you very much in advance!

  0      
  0      
#1
Options
1 Accepted Solution
Re:Site-to-site and client-to-site VPN-Solution
2025-11-17 09:42:35 - last edited 2025-11-17 09:42:40
Recommended Solution
  0  
  0  
#5
Options
5 Reply
Re:Site-to-site and client-to-site VPN
2025-11-15 23:22:45

  @effenn 

 

No

 

You can use IPsec client to site VPN, OpenVPN or Wireguard without conflict

  0  
  0  
#2
Options
Re:Site-to-site and client-to-site VPN
2025-11-16 15:32:00

  @GRL Thanks for your reply.

 

So, I assume that changing to L2TP over IPsec would the a good solution in this case.

Can you tell me, if first changing the gateway in site B to be the L2TP client, then the gateway in site A to be the L2TP server will work without resetting any of the devices?

Or do you know a better way to change the setup without resetting?

 

Thanks again!

  0  
  0  
#3
Options
Re:Site-to-site and client-to-site VPN
2025-11-17 07:59:39

  @effenn 

 

L2TP wont work for remote sites that need omada management as it NATs the IP addresses , remote sites can only be managed over SD-WAN or IPsec

  0  
  0  
#4
Options
Re:Site-to-site and client-to-site VPN-Solution
2025-11-17 09:42:35 - last edited 2025-11-17 09:42:40
Recommended Solution
  0  
  0  
#5
Options
Re:Site-to-site and client-to-site VPN
2025-11-17 20:38:56

  @GRL 

Thanks again, I will look into the SD-WAN functionality.

 

  @Ethan-TP

Thank you, I have seen this guide earlier, but was hoping to be able to connect to site A directly.

Anyways, I will set this up tomorrow and use this until I have time to learn about the SD-WAN.

  0  
  0  
#6
Options