Cannot add route to SDWAN for a VLAN without DHCP server

Cannot add route to SDWAN for a VLAN without DHCP server

Cannot add route to SDWAN for a VLAN without DHCP server
Cannot add route to SDWAN for a VLAN without DHCP server
Monday - last edited Ayer
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.1 Build 20251015 Rel.78291

hi all,

 

as I have learned in my previous post "ACL - allow access to single IP in another VLAN" there is currently no possibility to set granular per IP rules.

I have tried another approach - created VLAN for IoT without DHCP server, which creates a completely isolated VLAN network.

I have installed pfSense firewall on my ESX with one adapter in main LAN and another in IoT LAN and set the required rules. All is working fine, but there is always a "but"....

 

I cannot reach the VLAN from another site via SDWAN, as VLAN without DHCP server doesn't appear in network list of allowed networks as the gateway has no knowledge of the IP range used inside.

I've tried to add a static route on the other site to route the requests towards IoT network to the SDWAN connection - but this route is completely ignored and the traceroute shows that all requests are fouted via WAN port.

The route created by SDWAN config to reach any other LAN has one additional attribute - the Interface name:

SDWAN route

 

And when I try to enter my own route, I'm unable to select SDWAN interface - and when I enter the same next hop as above, that route doesn't work, is ignored.............

SDWAN IoT

 

It seems definitelly that SD-WAN has no info about the IoT network and I see no possibility to add it manually.

I'm using Windows Controller v6.0.0.24

 

Any ideas?

 

/BR ZoloNN ----------------------------------------------------------------------------------- Omada 2x ER605(UN) v2.0 + SG2008P(UN) V3.20 + SG2218 V1.20 + 2x SG2008 V4.20 + 3x EAP615-Wall(EU) V1.0
  0      
  0      
#1
Options
1 Accepted Solution
Re:Cannot add route to SDWAN for a VLAN without DHCP server-Solution
Ayer - last edited Ayer

Hi @GRL and all,

 

yesterday I replaced the SD-WAN with WireGuard site2site tunnel - all is working fine, all networks can be configured and routed through.

 

conclusion: SD-WAN is fine option and easy to configure with one exception: if you use some non-standard network config you'll be in routing trouble......

 

/BR ZoloNN ----------------------------------------------------------------------------------- Omada 2x ER605(UN) v2.0 + SG2008P(UN) V3.20 + SG2218 V1.20 + 2x SG2008 V4.20 + 3x EAP615-Wall(EU) V1.0
Recommended Solution
  0  
  0  
#4
Options
5 Reply
Re:Cannot add route to SDWAN for a VLAN without DHCP server
Monday - last edited Monday

  @ZoloNN 

 

SD-WAN can only connect gateway interface vlans across sites

 

You need to use IPsec VPN instead, where you can assign custom IPs as local and remote targets for each VPN.  As long as the gateway with the VLAN in question has a static route to the network in question this will work from the remote gateway

  2  
  2  
#2
Options
Re:Cannot add route to SDWAN for a VLAN without DHCP server
Monday

Hi @GRL,

 

as I've mentioned in some of my previous posts, I will apparently go back for WireGuard.

SD-WAN is easy to configure and working quite fine - just it seems to be a half-baked solution....

 

/BR ZoloNN ----------------------------------------------------------------------------------- Omada 2x ER605(UN) v2.0 + SG2008P(UN) V3.20 + SG2218 V1.20 + 2x SG2008 V4.20 + 3x EAP615-Wall(EU) V1.0
  0  
  0  
#3
Options
Re:Cannot add route to SDWAN for a VLAN without DHCP server-Solution
Ayer - last edited Ayer

Hi @GRL and all,

 

yesterday I replaced the SD-WAN with WireGuard site2site tunnel - all is working fine, all networks can be configured and routed through.

 

conclusion: SD-WAN is fine option and easy to configure with one exception: if you use some non-standard network config you'll be in routing trouble......

 

/BR ZoloNN ----------------------------------------------------------------------------------- Omada 2x ER605(UN) v2.0 + SG2008P(UN) V3.20 + SG2218 V1.20 + 2x SG2008 V4.20 + 3x EAP615-Wall(EU) V1.0
Recommended Solution
  0  
  0  
#4
Options
Re:Cannot add route to SDWAN for a VLAN without DHCP server
Ayer

  @ZoloNN 

Thank you for your feedback. I will pass it on to the relevant department, where it will be reviewed and taken into consideration.

  0  
  0  
#5
Options
Re:Cannot add route to SDWAN for a VLAN without DHCP server
Ayer

Hi @Ethan-TP,

 

first of all I'll suggest to focus on more granular ACL options like mentioned here: "ACL - allow access to single IP in another VLAN"

If this is solved, the VLAN remains in gateway domain and will be addable to the SD-WAN.

 

I had to use pfSense to set up granular access rules (see picture below) for IoT network - which setup requires non-routed VLAN (the one without DHCP server) which caused this issue...

 

pfSense rules

/BR ZoloNN ----------------------------------------------------------------------------------- Omada 2x ER605(UN) v2.0 + SG2008P(UN) V3.20 + SG2218 V1.20 + 2x SG2008 V4.20 + 3x EAP615-Wall(EU) V1.0
  0  
  0  
#6
Options