Troubleshooting VPN Client on Wi-Fi Router Is Not Working
This Article Applies to:
All the Wi-Fi Routers that support VPN Client, such as Archer AX20, Archer AX21, Archer AX90, etc.
Issue Description/Phenomenon:
The Wi-Fi Routers that are being discussed here are the models that support VPN Client, which allows users to connect to a VPN server without the need to install VPN software on each device. If you are unable to connect to a VPN server when trying to configure the VPN client on the TP-Link router, this article provides some suggestions that may help you out.
However, if VPN server on TP-Link router is not working, please follow this thread for troubleshooting: VPN Server Doesn't Work Properly on TP-Link Wi-Fi Routers
Troubleshooting Suggestions & Solution:
Step 1
For OpenVPN, please follow this FAQ How to get configuration files from OpenVPN service providers to get correct configuration file and your VPN service credentials, which is the key to accessing the VPN service.
Step 2
Ensure you can successfully connect to the VPN server using a third-party VPN client software like OpenVPN Connect or OpenVPN or WireGuard App for WireGuard VPN on the local PC/Smartphone. This can ensure the .opvn or .conf file is configured and exported correctly.
For example, If you are trying to connect to NordVPN, please don't use NordVPN App since it doesn't require the .opvn at all.
Note: NordVPN service credentials are different from your NordVPN account credentials, namely your email address and your password. You'll need NordVPN service credentials to connect to the VPN using the manual OpenVPN configuration method in the router.
Step 3
If step 2 is confirmed good, but it still fails to connect to the VPN server when uploading the .opvn file into the TP-Link router, be sure the router's firmware is up-to-date. You can check for the updates on the Tether app or on the router web GUI, or you can download it from the local official website and then install it manually.
Step 4
If it still fails, please check the size of the VPN configuration profile you are trying to upload to the router, and how large that file is. You may download and install the Notepad+ application to delete the useless comment in the profile if that is too large, then try uploading it into the router again.
Step 5
It's also suggested to try TCP protocol on the VPN server if it's currently using UDP, then save the file and upload it into the TP-Link router again to check if that works.
If the VPN connection still fails, please comment below on this topic and be sure to provide the following information:
1. Model number, hardware, and firmware version of your TP-Link Router.
2. What kind of VPN server you are connecting to?
3. What kind of VPN type are you choosing on the TP-Link router, OpenVPN, or PPTP VPN?
4. What kind of VPN Client software you were using on the local PC or phone when it was connecting fine? Please test and make sure you can connect to the server with third-party software, such as OpenVPN Connect for OpenVPN and WireGuard App for WireGuard VPN.
5. Which step did you stuck in, any error message or screenshot?
6. Troubleshooting you've done before, and be sure the .opvn file for OpenVPN or .conf file for WireGuard is included when emailing to support.
Related Articles:
If you are not familiar with the VPN, visit Introduction and Configuration Guide of VPN Function on TP-Link Wireless Routers
If you want to check which model supports the VPN Client, visit Routers supporting the VPN Client.
If you are unable to connect CyberGhost OpenVPN Server, please try Manually create the unified format for OpenVPN profile(CyberGhost OpenVPN Server)
-------------------------------------------------
Have other off-topic issues to report?
Welcome to > Start a New Thread < and elaborate on the issue for assistance.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
@MrHalfpint Sorry to hear that, its unfortunate that the .ovpn aettings i provided did not resolve ur situation. When you use your .ovpn in the client vpn of the router do you need to enter a password or is it without password. If it requires password it wud suggest the password line is encrypted.. the settings i sent you if you use exactly that settings as it is and then ur ca cert key and open in openvpn client. If it works then try in the router and it is connecting suggests the issue is inside ur ca cert or key.
Put all my settings as stated into a .txt followed by ur ca cert and key and ensure of course the ip is correct and udp.
Tey it on client and router if client connects and not router, issue is in one of ur 3 ( ca cert key )
- Copy Link
- Report Inappropriate Content
@SteiniPe I made a little progress.. I'll try adding passwords next..
- Copy Link
- Report Inappropriate Content
@MrHalfpint In my case I couldnt use password, that made it encrypted password,and stuck at connecting. So i generated my user wirh nopass which allowed immediate connected.. Either way your situation is slightly different but it seems to something in that .ovpn file that isnt working for that router, u cud generate a new file if its ur openvpn server with nopass, anyway hope u get it sorted otherwise scroll down and find the TP link support who is responsing here and ask to escalate to support like they did with mine. They can run ur ovpn file and know exactly what it is.. Ive asked them to consider adding more verbosity to router logs because we get no answers there.. lets hope they do.. sorry i cant help u any more than this :/
- Copy Link
- Report Inappropriate Content
Router:AXE5400
Trying to use as a vpn client and it is stuck on connecting.
ovpn file does not have encrypted key and starts with -----BEGIN PRIVATE KEY-----
Any help here?
- Copy Link
- Report Inappropriate Content
@SteiniPe I got this far by deleting the "allow-compression no" in the generated .ovpn. I have a call into my VPN service.. (KeepSolid VPN) No changes with or without passwords.
- Copy Link
- Report Inappropriate Content
Hello...
I have checked the faqs and went through the troubleshooting and my client connection is stuck on connecting.
TpLink AX5400 Wifi 6 Router
Firmware Version:
1.3.5 Build 20230919 rel.12938(4555)
Hardware Version:
Archer AX73 v1.0
Cyberghost via Opvpn.
Works fine from PC/laptop/mobile via open vpn software
This is my config file:
client
remote 87-1-gb.cg-dialup. net 443
dev tun
proto udp
auth-user-pass
resolv-retry infinite
redirect-gateway def1
persist-key
persist-tun
nobind
cipher AES-256-CBC
ncp-disable
auth SHA256
ping 5
ping-exit 60
ping-timer-rem
explicit-exit-notify 2
script-security 2
remote-cert-tls server
route-delay 5
verb 4
<ca>
-----BEGIN CERTIFICATE-----
MIIGWjCCBEKgAwIBAgIJAJxUG61mxDS7MA0GCSqGSIb3DQEBDQUAMHsxCzAJBgNV
BAYTAlJPMRIwEAYDVQQHEwlCdWNoYXJlc3QxGDAWBgNVBAoTD0N5YmVyR2hvc3Qg
Uy5BLjEbMBkGA1UEAxMSQ3liZXJHaG9zdCBSb290IENBMSEwHwYJKoZIhvcNAQkB
FhJpbmZvQGN5YmVyZ2hvc3Qucm8wHhcNMTcwNjE5MDgxNzI1WhcNMzcwNjE0MDgx
NzI1WjB7MQswCQYDVQQGEwJSTzESMBAGA1UEBxMJQnVjaGFyZXN0MRgwFgYDVQQK
Ew9DeWJlckdob3N0IFMuQS4xGzAZBgNVBAMTEkN5YmVyR2hvc3QgUm9vdCBDQTEh
MB8GCSqGSIb3DQEJARYSaW5mb0BjeWJlcmdob3N0LnJvMIICIjANBgkqhkiG9w0B
AQEFAAOCAg8AMIICCgKCAgEA7O8+mji2FlQhJXn/G4VLrKPjGtxgQBAdjo0dZEQz
KX08q14dLkslmOLgShStWKrOiLXGAvB1rPvvk613jtA0KjQLpgyLy9lIWohQKYjj
5jrJYXMZMkbSHBYI9L8L7iezBEFYrjYKdDo51nq99wRFhKdbyKKjDh3e2L2SVEZL
T1ogkK5gWzjvH+mjjtjUUicK+YjGwWOz6I+KKaG4Ve/D/cE6nCLbhHIMMnargZEu
7sqA6BFeS4kEP/ZdCZoTSX2n43XV1q63nJt/v0KDetbZDciFVW9h9SVPG4qT44p0
550N+Mom7zTX7S/ID5T9dplgU8sRGtIMrG0cIMD9zmpFgUnMusCrR7jJFr0sMAve
TbgZg95LmstV6R6WKZkSFdUrE0DHl4dHoZvTFX+1LhwhHgjgDLaosX0vhG/C/7Lp
oVWimd6RRQT3M9o4Fa1TuhfvBzQ20QHrmRV/yKvGNK0xckZ6EZ/QY7Z55ORU15Tg
ab4ebnblYPWoEmn0mIYP3LFFeoR5OS1EX7+j4kPv+bwPGsmpHjxmZyq2Y7sJBpbO
CJgbkn52WZdPBIRDpPdIHQ8pAJC4T0iMK9xvAwWNl/V6EYYNpR97osyEDXn+BTdA
HlhJ5fck9KlwI9mb1Kg1bhbvbmaIAiOLenSULYf3j6rI1ygo3R2cCyybtuAq8M7z
0OECAwEAAaOB4DCB3TAdBgNVHQ4EFgQU6tdK1g/He5qzjeAoM5eHt4in9iUwga0G
A1UdIwSBpTCBooAU6tdK1g/He5qzjeAoM5eHt4in9iWhf6R9MHsxCzAJBgNVBAYT
AlJPMRIwEAYDVQQHEwlCdWNoYXJlc3QxGDAWBgNVBAoTD0N5YmVyR2hvc3QgUy5B
LjEbMBkGA1UEAxMSQ3liZXJHaG9zdCBSb290IENBMSEwHwYJKoZIhvcNAQkBFhJp
bmZvQGN5YmVyZ2hvc3Qucm+CCQCcVButZsQ0uzAMBgNVHRMEBTADAQH/MA0GCSqG
SIb3DQEBDQUAA4ICAQDNyQ92kj4qiNjnHk99qvnFw9qGfwB9ofaPL74zh0G5hEe3
Wgb2o4fqUGnvUNgOu53gJksz3DcPQ8t40wfmm9I1Z8tiM9qrqvkuQ+nKcLgdooXt
EsTybPIYDZ2cWR/5E0TKRvC7RFzKgQ4D77Vbi4TdaHiDV7ZNfU1iLCoBGcYm80hc
UHEs5KIVLwUmcSOTmbZBySJxcSD0yUpS7nlZGwLY6VQrU+JFwDSisbXT4DXf3iSz
p7FzW0/u/SFvWsPHrjE0hkPoZPalYvouaJEHKAhip0ZwSmitlxbBnmm8+K/3c9mL
A5/uXrirfpuhhs8V3lyV2mczVtSiTl6gpi88gc//JY80JeHdupjO25T3XEzY9cpx
ecmkWaUEjLMx4wVoXQuUiPonfILM6OLwi+zUS8gQErdFeGvcQXbncPa4SdJuHkF8
lgiX2i8S8fPGdXvU37E9bdAXwP5nZriYq1s0D59Qfvz+vLXVkmyZp6ztxjKjKole
mPMak0Y5c1Q4RjNF6tmQoFuy/ACSkWy14Tzu2dFp7UiVbGg1FOvKhfs48zC2/IUQ
v1arqmPT/9LVq3B2DVT9UKXRUXX/f/jSSsVjkz4uUe2jUyL+XHX1nSmROTPHSAJ+
oKf0BLnfqUxFkEUTwLnayssP2nwGgq35b7wEbTFIXdrjHGFUVQIDeERz8UThew==
-----END CERTIFICATE-----
</ca>
<cert>
-----BEGIN CERTIFICATE-----
MIIGojCCBIqgAwIBAgIEAa2e4DANBgkqhkiG9w0BAQsFADB7MQswCQYDVQQGEwJS
TzESMBAGA1UEBxMJQnVjaGFyZXN0MRgwFgYDVQQKEw9DeWJlckdob3N0IFMuQS4x
GzAZBgNVBAMTEkN5YmVyR2hvc3QgUm9vdCBDQTEhMB8GCSqGSIb3DQEJARYSaW5m
b0BjeWJlcmdob3N0LnJvMB4XDTI0MDQwMTIyMzkyNloXDTM0MDMzMDIyMzkyNlow
czELMAkGA1UEBhMCUk8xEjAQBgNVBAcMCUJ1Y2hhcmVzdDEYMBYGA1UECgwPQ3li
ZXJHaG9zdCBTLkEuMRMwEQYDVQQDDAp2NkZnNGtjdEdxMSEwHwYJKoZIhvcNAQkB
FhJpbmZvQGN5YmVyZ2hvc3Qucm8wggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIK
AoICAQDGPqjaZezMz68CAExaRj178YTfY5TXyOWj80LD4dgCVO1BKW9fEh5h5/Wh
zGLTroLZacFFsNsS80s29pNVcVbP7NjrxXs5EW0UX4bcGIw3xsyKEZCwhatWPI74
ivVcWemzHB9P405fGU1hleQCdaeya7Pe8/KDTjKswIlccTYLYHNeF5RTCKPMN9eI
W2Uypp//IiJ7NDEns/KvZo+1A4lc+0i+wZWr1J4vM+kTJKyTRwdzlt+p7iUoDfzx
wqw/t5jY+5G2ef4z8ZOvzuKibVyNUirN3YCJNMbjTvGiHvfLB3hFpB3YP0xKgrvT
qoAmfnN7vUtAbrtD+oMiAd0aWi4lFuzr0k5HbyWeOVMHGnE9yw6LcuRj6W3+Ek81
CZbLfEOpkvCSpGJhPqY6vawVtjd8Tx9EZLxF7Q2KMNn0mSiLyClbXMlQ6BgkdHGc
Uro6wzCkblu8Yc6QocdPAnVAwIhYRvniHyyoR6X62pV1znEX9qarkkRRfoqEPR1V
xa3lOSI+kEj0u6BCI2oD9gwwww1bh3QhE+x4GlIrm1ZnskR4MH+BiMYScttPQmsw
lwD5efqmlS3LhlelHnsHDP8AvByyZifjgQjIS0T1Ure3jHrA7ZqKHDf8XNJu56Vp
j/0g4UmyJRkagO89BdPgcqYHmDERUojPQeV+CduWevMRVItKpQIDAQABo4IBNDCC
ATAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBaAwNAYJYIZIAYb4QgENBCcWJUN5YmVy
R2hvc3QgR2VuZXJhdGVkIFVzZXIgQ2VydGlmaWNhdGUwEQYJYIZIAYb4QgEBBAQD
AgeAMB0GA1UdDgQWBBT5237HmDUlFMqnD2to6j64oi46QzCBrQYDVR0jBIGlMIGi
gBTq10rWD8d7mrON4Cgzl4e3iKf2JaF/pH0wezELMAkGA1UEBhMCUk8xEjAQBgNV
BAcTCUJ1Y2hhcmVzdDEYMBYGA1UEChMPQ3liZXJHaG9zdCBTLkEuMRswGQYDVQQD
ExJDeWJlckdob3N0IFJvb3QgQ0ExITAfBgkqhkiG9w0BCQEWEmluZm9AY3liZXJn
aG9zdC5yb4IJAJxUG61mxDS7MA0GCSqGSIb3DQEBCwUAA4ICAQCHPpRkF46cuiaf
1CR1Z5FA/p0awV+qP6SOtLiTwos1ud5FE4icGjL6lhfoKvVQEl6oiWo6ArfGOlex
AxIoumf8qv1eu0oPaMCVEjBayMu53nM/8/ZqJ05jfSXmPLHfhM3JR9wrM1RhWq81
ZhRFDSDrv2vh2tGCt+CWGJF5FOkFH7uc2xBrkvth5gGYjEQpPKz8s/y3OF2DgD23
+ABabAMOCAkYBiSHrpwkgmkjagTLL5Y4nq4GakiZ2kAALKTSnu6gsS8i0CJiYD75
SQjNuJnvZ0f2ljXcHMPg6lVqenmpBYQ6zke77h5LFRF3EG9Hd87TzkgjdEvKRUl0
aEW4mnlDZHPAD3Tbx0dqzUq5VKxMNeb/pGMzVYwA7TfHDGsxuHC9evBMJY6bmXw8
6d0RFgBzXG+fdAK6VmF1hsPpsQ2g8zmFi1qvuxi6uMYUkkHbP5v90VGawbgY1IwK
jgM/6+xK5nDqOuSgb5PDLJrzBfogbB2ZSEarlqYGnU20BxPqfjVooR37S6FCgXVK
9U+ObljRcVPET2IAn60uyjRRx083rYQuh/3IJC8HVpdzWq7RJEZNDDMIN/rpeWjJ
Hp/JQqqWjX0CWVPFRopdlOU6gDXDnlqvUexnNeysGI5kypKYrpim/+b4hrebIJb1
7fJriuB8IJaOznpFBioxEre5/OiD0Q==
-----END CERTIFICATE-----
</cert>
openssl pkey -in secure.key -out plain.key
I must add that I also initially tried with the actual key ( as in <key>......[...].....</key> ) and that also got stuck in connecting.
I also tried IPSec ans it al stays "connecting"... forever....
Please help! :)
- Copy Link
- Report Inappropriate Content
@danoffline Your <Key> does it start with BEGIN PRIVATE KEY or BEGIN ENCRYPTED PRIVATE KEY
- Copy Link
- Report Inappropriate Content
@MrHalfpint Have you tried contacting the support, I know they want to "raise a ticket" sometimes but maybe you could reach out to them, Guy named Noah Wng (Get it, this forum doesnt allow me to spell his name with a "a" because its profanity ;D) sorted me through email support.forum@tp-link.com, im not sure if you are allowed to contact noah directly as I have his email from that ticket as he was CC'd, but if you reach out to them raise a ticket about this forum post, provide them with the details they may be able to help. Just make sure to include the "openVPN configuration file" without IP and Port, he can verify your options if they require fixing.
- Copy Link
- Report Inappropriate Content
@SteiniPe Thanks for all your time and help. I have been in contact with Noah for more than a week and he is doing his best. I've tried installing some beta firmware he sent but still can't get any better results.
There are two (2) things that seem strange.
1) I get the same results when I try to use L2TP/IPSsec protocol.
2) When I remove compression it will say connected but it's not and I get a ? saying server: null and dns:10.80.0.1
All of the generated .ovpn files work with the OPVNClient.
I've sent log files from both the OPVNClient and TPLink (adding "log-append /tmp/smb/G/log.txt" will generate a log to the usb drive) file.
- Copy Link
- Report Inappropriate Content
Information
Helpful: 8
Views: 66348
Replies: 241