Route all traffic on specific Port to IPsec VPN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Route all traffic on specific Port to IPsec VPN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Route all traffic on specific Port to IPsec VPN
Route all traffic on specific Port to IPsec VPN
2024-02-21 10:08:38 - last edited 2024-02-22 01:52:25
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version:

Hi,

I have established a LAN-to-LAN IPsec VPN connection between my ER605 and a remote network.

This is working and from both networks I can access the other local network devices. 

 

I would now like that for one specific Ethernet port on the ER605, all traffic is to be routed through the VPN connection. I.e. for this specific port, a connected device would access internet not through the local WAN but through the VPN tunnel.

 

How would I do this?

 

I would have expected that I would need to

1) Create a new VLAN and assing it to the required port

2) Create IP_Group for VLAN

3) Create Policy Routing with created IP_Group as Source IP and VPN as WAN.

Unfortunately, the Selectable WAN is only the local WAN and the UBS-Modem, not the VPN connection.

 

Any hints what I would need to do?

  0      
  0      
#1
Options
2 Accepted Solutions
Re:Route all traffic on specific Port to IPsec VPN-Solution
2024-02-21 11:10:06 - last edited 2024-02-22 01:52:28

  @coogee86 

 

you cannot route all traffic through IPsec site to site,

policy routing only works on PPTP L2TP and WAN interface.

 

 

Recommended Solution
  1  
  1  
#2
Options
Re:Route all traffic on specific Port to IPsec VPN-Solution
2024-02-22 01:51:15 - last edited 2024-02-22 01:52:25

Hi @coogee86 

Thanks for posting in our business forum.

1. Figure out what IPsec site-to-site is made for. Your whole request will be explained.

2. Use the client-to-site and set up Policy Routing. L2TP is supported.

3. A VPN tunnel cannot be limited to a specific port. It is not on layer 1. And you cannot designate it to layer 1 anyway.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#3
Options
2 Reply
Re:Route all traffic on specific Port to IPsec VPN-Solution
2024-02-21 11:10:06 - last edited 2024-02-22 01:52:28

  @coogee86 

 

you cannot route all traffic through IPsec site to site,

policy routing only works on PPTP L2TP and WAN interface.

 

 

Recommended Solution
  1  
  1  
#2
Options
Re:Route all traffic on specific Port to IPsec VPN-Solution
2024-02-22 01:51:15 - last edited 2024-02-22 01:52:25

Hi @coogee86 

Thanks for posting in our business forum.

1. Figure out what IPsec site-to-site is made for. Your whole request will be explained.

2. Use the client-to-site and set up Policy Routing. L2TP is supported.

3. A VPN tunnel cannot be limited to a specific port. It is not on layer 1. And you cannot designate it to layer 1 anyway.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#3
Options