VPN Site-to-Site with Internet Access through remote site gateway

VPN Site-to-Site with Internet Access through remote site gateway

VPN Site-to-Site with Internet Access through remote site gateway
VPN Site-to-Site with Internet Access through remote site gateway
a week ago - last edited Tuesday
Model: ER8411  
Hardware Version: V1
Firmware Version: 1.3.6 Build 20251028 Rel.12399

Hello Everyone,

 

We have a branch office with an TP-Link ER7206 and we want to connect this branch office through VPN to our main office as if it would be locally. The remote site should use all the resources at our main office but most important, all of the Internet traffic from the branch office should be over the VPN with the gateway on the main office. We have software which looks at the public IP address.

 

We use the latest f/w on an OC220.

 

Can anyone point us to the right direction to achieve the above?

 

Kind regards,

  0      
  0      
#1
Options
1 Accepted Solution
Re:VPN Site-to-Site with Internet Access through remote site gateway-Solution
Monday - last edited Tuesday

  @Theeyeinthesky 

 

if you have a working l2tp site to site, go to remote site and create a policy route like that to rute everything to main site.

 

 

 

 

Recommended Solution
  0  
  0  
#12
Options
13 Reply
Re:VPN Site-to-Site with Internet Access through remote site gateway
a week ago - last edited a week ago

  @Theeyeinthesky 

 

use sd-wan. 

 

gobal settings, sd-wan

 

 

 

or folow this guide

 

https://community.tp-link.com/en/business/stories/detail/502060

 

 

  0  
  0  
#2
Options
Re:VPN Site-to-Site with Internet Access through remote site gateway
a week ago - last edited a week ago

  @Theeyeinthesky 

 

I think I misunderstood your question., you can use wireguard to solve your problem. here is a guide,
on remote site set allowed ip to 0.0.0.0/0 then all trafill will go out to  main office.

 

https://community.tp-link.com/en/business/forum/topic/620506

  0  
  0  
#3
Options
Re:VPN Site-to-Site with Internet Access through remote site gateway
Saturday

  @MR.S 

 

Thanks for the explanation, we have followed the instructions in the link you send me and on remote site set allowed ip to 0.0.0.0/0. The tunnel is working but on the remote site all Internet connections we're dropped also on the VLAN's we didn't add to the WireGuard Peer.

 

What should be the settings on the devices at the Remote Site to direct all Internet (Browsing/connecting) traffic through the tunnel and out of the Gateway of the main Site?

  0  
  0  
#4
Options
Re:VPN Site-to-Site with Internet Access through remote site gateway
Saturday

  @Theeyeinthesky 

 

you are right, it doesn't work between two omada routers, i did a test here with an ER605. it ended up that i had to do a full reset on the router, i have the same router against another wireguard server and there it works with 0,0,0,0/0

you can try with l2tp site to site and policy route on remote site. that should work. i'll see if there is any documentation to find on that.

 

 

  0  
  0  
#5
Options
Re:VPN Site-to-Site with Internet Access through remote site gateway
Saturday - last edited Saturday

  @Theeyeinthesky 

 

I didn't find anything useful, but on short, creating an l2tp server on the main site, then create a user and select network extention mode. define remote network.
vpn pool should not overlap with any of your other networks.

 

 

then create an l2tp client on the remote site, on working mode select routing.

once that is done, go to routing and policy route on the remote site and route what you want via the main site.

 

 

  0  
  0  
#6
Options
Re:VPN Site-to-Site with Internet Access through remote site gateway
Sunday

  @MR.S 

 

Thank you, but this path we already tried, a tunnel was created perfectly but we couldn't get the Internet configured on the remote site to use the gateway/DNS od the Head Quarter.

  0  
  0  
#7
Options
Re:VPN Site-to-Site with Internet Access through remote site gateway
Sunday

Theeyeinthesky wrote

  @MR.S 

 

Thank you, but this path we already tried, a tunnel was created perfectly but we couldn't get the Internet configured on the remote site to use the gateway/DNS od the Head Quarter.

  @Theeyeinthesky 

 

what du you try? wireguard or l2tp?

  0  
  0  
#8
Options
Re:VPN Site-to-Site with Internet Access through remote site gateway
Sunday

  @MR.S 

 

We've tried L2TP with Network Extension Mode and policy routing to (re)direct the Internet traffic through the gateway of the Headquarter. But we couldn't get this working either..

  0  
  0  
#9
Options
Re:VPN Site-to-Site with Internet Access through remote site gateway
Monday - last edited Monday

  @Theeyeinthesky 

 

l2tp works fine, I tested that this weekend. Have you created a policy route? You can do that under network config and route

 

  0  
  0  
#10
Options
Re:VPN Site-to-Site with Internet Access through remote site gateway
Monday

  @MR.S 

 

Can you explain the steps for successful L2TP connection and the Policy Route? Maybe we have made a little (thinking) error about the settings..

  0  
  0  
#11
Options