VPN ikev2 with more than one LANs doesn't work
VPN ikev2 with more than one LANs doesn't work
Hello I have the following network topology
On building A exists a omada hardware controller wherewith I can manage network devices on building A and building B through port forwarding configuring on SDN Router (TL-R605) and ISP modem (ISP Modem 1) both. I want to connect this two buildings (networks) to communicate each other. The only way to achieve this is VPN. I have the following configurations:
Configuration VPN of Building A:
Configuration VPN of Building B:
The IKEv2 is taken automatically on both building.
And after that configuration VPN is not working.
I want your help, dear colleagues. If I find the solution first, I will post here it.
Thanks in advance
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
I finally succeeded. I created a 2nd VPN Policy in Building A by setting LAN2 as the remote subnet, ie the LAN of the 2nd floor of Building B (192.168.103.0/24). The 1st VPN Policy has the LAN of the 1st floor of Building B (192.168.102.0/24). Similarly for Building B I created a 2nd VPN Policy by setting Local Networks LAN2. The 1st VPN Policy has LAN1.
Those configurations have done with IKEv1. Also I have to mention that in case of doing on LAN on both building IKEv2 still not working
Thank you very much for your time
- Copy Link
- Report Inappropriate Content
Or if you want to use IKEv2, VPN connecion should work like this:
Building A configuration
Building B Configuration
- Copy Link
- Report Inappropriate Content
Have you adopted both R605 on the Controller?
This is a new instruction from TP-Link and hope this one can help you.
Auto mode: How to set up site-to-site Auto IPsec VPN Tunnels on Omada Gateway in Controller Mode?
Manually: How to Set up Site-to-Site Manual IPsec VPN Tunnels on Omada Gateway in Controller Mode?
- Copy Link
- Report Inappropriate Content
Also, the WAN IP of your R605s is a private IP, please make sure your modem can pass through IPsec VPN data, otherwise, it's better to change the modem to bridge modem mode.
- Copy Link
- Report Inappropriate Content
@xperiments Thanks fot the response. I forgot to mention that with IKEV1 (with one LAN on both buildings) vpn is working fine. Also I have adopted router TL-R605 (on both buildings) on omada hardware controller
- Copy Link
- Report Inappropriate Content
All remote subnet is wrong. you have to use
192.168.101.0/24
192.168.102.0/24
192.168.103.0/24
/shberge
- Copy Link
- Report Inappropriate Content
@shberge I use this format and nothing works. So, the problem arise from something else
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
This is my config between two ER605, semilar config in both site. exept remote subnet and wan ip :-)
- Copy Link
- Report Inappropriate Content
with wan ip doesnt work because Omada gateway is behind a NAT device.@shberge
- Copy Link
- Report Inappropriate Content
Do you have som ACL roule on gateway, Switch or EAP that block?
You can also enable alert on ipsec to get alert when connect or disconnect
- Copy Link
- Report Inappropriate Content
Ok, but IKev1 work behind NAT? that strange.
Ok then you have to nat ipsec port to your ER605 to get it to work.
I think that is UDP port 500 and 4500
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 2689
Replies: 18
Voters 0
No one has voted for it yet.