site-2-site IPsec not working with FQDN only with IP as remote-gateway

site-2-site IPsec not working with FQDN only with IP as remote-gateway

site-2-site IPsec not working with FQDN only with IP as remote-gateway
site-2-site IPsec not working with FQDN only with IP as remote-gateway
Friday - last edited 3 hours ago
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.3 Build 20251029 Rel.18054

I have configured all my gateways through an omada controller. I recently updated one ER605 V2 to actual firmware 2.3.3. Now my IPsec tunnels wont work. It came out, that FQDN entries as remote-gateway are not working, when entering an IP Adresse, the tunnels work again. Why is that and is there a workaround for that? Will this feature be repaired in future releases? I also have several ER7206, does anybody know, if this problem exists there in actual firmware?

  0      
  0      
#1
Options
1 Accepted Solution
Re:site-2-site IPsec not working with FQDN only with IP as remote-gateway-Solution
6 hours ago - last edited 3 hours ago

  @gerv_d 

Please try deleting it and re-configuring. If the issue persists, let me know.

Recommended Solution
  1  
  1  
#4
Options
4 Reply
Re:site-2-site IPsec not working with FQDN only with IP as remote-gateway
20 hours ago

  @gerv_d 

 

FQDN works fine on all Omada routers, including the ER605, I've used it for years without any problems. But you can try deleting the VPN configuration and re-entering it. Also restart the router if you haven't done so.

 

also check the dns server on the internet interface. also set static dns, for example 1.1.1.1 and 1.0.0.1

 

  0  
  0  
#2
Options
Re:site-2-site IPsec not working with FQDN only with IP as remote-gateway
6 hours ago

  @gerv_d 

 

I can confirm what MR.S has said, i have recently changed our company DNS records with an additional A record pointing directly to our WAN IP, so i could use FQDN instead of IP on both remote site-to-site and dial-in VPN users (allowing me to change the IP in the future and not have to reconfigure dozens of clients, just the DNS record) and it works fine

  0  
  0  
#3
Options
Re:site-2-site IPsec not working with FQDN only with IP as remote-gateway-Solution
6 hours ago - last edited 3 hours ago

  @gerv_d 

Please try deleting it and re-configuring. If the issue persists, let me know.

Recommended Solution
  1  
  1  
#4
Options
Re:site-2-site IPsec not working with FQDN only with IP as remote-gateway
3 hours ago

  @Ethan-TP 
Thank you, deleting all IPSec configs, reboot and make a fresh new config solved my problem. I can now connect to FQDN addresses again!

  0  
  0  
#5
Options