Cannot add route to SDWAN for a VLAN without DHCP server

Cannot add route to SDWAN for a VLAN without DHCP server

Cannot add route to SDWAN for a VLAN without DHCP server
Cannot add route to SDWAN for a VLAN without DHCP server
21 hours ago
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.1 Build 20251015 Rel.78291

hi all,

 

as I have learned in my previous post "ACL - allow access to single IP in another VLAN" there is currently no possibility to set granular per IP rules.

I have tried another approach - created VLAN for IoT without DHCP server, which creates a completely isolated VLAN network.

I have installed pfSense firewall on my ESX with one adapter in main LAN and another in IoT LAN and set the required rules. All is working fine, but there is always a "but"....

 

I cannot reach the VLAN from another site via SDWAN, as VLAN without DHCP server doesn't appear in network list of allowed networks as the gateway has no knowledge of the IP range used inside.

I've tried to add a static route on the other site to route the requests towards IoT network to the SDWAN connection - but this route is completely ignored and the traceroute shows that all requests are fouted via WAN port.

The route created by SDWAN config to reach any other LAN has one additional attribute - the Interface name:

SDWAN route

 

And when I try to enter my own route, I'm unable to select SDWAN interface - and when I enter the same next hop as above, that route doesn't work, is ignored.............

SDWAN IoT

 

It seems definitelly that SD-WAN has no info about the IoT network and I see no possibility to add it manually.

I'm using Windows Controller v6.0.0.24

 

Any ideas?

 

/BR ZoloNN ----------------------------------------------------------------------------------- Omada 2x ER605(UN) v2.0 + SG2008P(UN) V3.20 + SG2218 V1.20 + 2x SG2008 V4.20 + 3x EAP615-Wall(EU) V1.0
  0      
  0      
#1
Options
2 Reply
Re:Cannot add route to SDWAN for a VLAN without DHCP server
21 hours ago - last edited 21 hours ago

  @ZoloNN 

 

SD-WAN can only connect gateway interface vlans across sites

 

You need to use IPsec VPN instead, where you can assign custom IPs as local and remote targets for each VPN.  As long as the gateway with the VLAN in question has a static route to the network in question this will work from the remote gateway

  0  
  0  
#2
Options
Re:Cannot add route to SDWAN for a VLAN without DHCP server
20 hours ago

Hi @GRL,

 

as I've mentioned in some of my previous posts, I will apparently go back for WireGuard.

SD-WAN is easy to configure and working quite fine - just it seems to be a half-baked solution....

 

/BR ZoloNN ----------------------------------------------------------------------------------- Omada 2x ER605(UN) v2.0 + SG2008P(UN) V3.20 + SG2218 V1.20 + 2x SG2008 V4.20 + 3x EAP615-Wall(EU) V1.0
  0  
  0  
#3
Options