13
Votes

Openvpn & Ikev2 missing in standalone mode of ER605(aka TL-R605)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
 
13
Votes

Openvpn & Ikev2 missing in standalone mode of ER605(aka TL-R605)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
21 Reply
Re:Openvpn & Ikev2 missing in standalone mode of ER605(aka TL-R605)
2022-01-27 10:51:42 - last edited 2022-02-18 01:23:35

Dear @Ben-91,

 

Ben-91 wrote

Can you confirm that Ikev2 is indeed available in standalone mode on the v2 ? and if yes, any chance to have the same possibility on the v1 ?

 

Yes, Ikev2 is supported in both Standalone and Controller mode on the ER605 V2.

 

The ER605 V1 will support the Ikev2 in Standalone mode on the subsequent firmware update.

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
#12
Options
Re:Openvpn & Ikev2 missing in standalone mode of ER605(aka TL-R605)
2022-01-27 20:30:04

@Fae thanks a lot for this quick answer !

any idea of when the firmware update will be distributed ? I think we're a number of customers waiting for this since August. Thanks in advance, Ben 

#13
Options
Re:Openvpn & Ikev2 missing in standalone mode of ER605(aka TL-R605)
2022-01-28 00:51:14

Dear @Ben-91,

 

Ben-91 wrote

any idea of when the firmware update will be distributed ? I think we're a number of customers waiting for this since August. Thanks in advance, Ben 

 

Sorry that I haven't been informed of the release date for the new firmware.
I'll keep an eye on it and update this post once there is new firmware available.

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
#14
Options
Re:Openvpn & Ikev2 missing in standalone mode of ER605(aka TL-R605)
2022-01-29 07:50:07
Thanks, also interested in OpenVPN capability on ER605 v1 in standalone mode
#15
Options
Re:Openvpn & Ikev2 missing in standalone mode of ER605(aka TL-R605)
2022-02-16 07:13:33

  @Fae Hi Fae, I noticed that the updated firmware for v1 hardware was released recently, and could see that indeed Openvpn was now available. However, it seems that Ikev2 is still missing, do you confirm ? was it what you meant in the subsequent firmware release : after the one including Openvpn ?

Thanks in advance,

 

Benjamin

#16
Options
Re:Openvpn & Ikev2 missing in standalone mode of ER605(aka TL-R605)-Solution
2022-02-18 01:37:47 - last edited 2022-10-28 04:25:23

Dear @Ben-91,

 

Ben-91 wrote

  @Fae Hi Fae, I noticed that the updated firmware for v1 hardware was released recently, and could see that indeed Openvpn was now available. However, it seems that Ikev2 is still missing, do you confirm ? was it what you meant in the subsequent firmware release : after the one including Openvpn ?

 

Have you already upgraded to the new 1.2.0 firmware?

 

I checked my ER605 v1, the Ikev2 has been supported with the 1.2.0 firmware upgrade.

 

 

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
Recommended Solution
#17
Options
Re:Openvpn & Ikev2 missing in standalone mode of ER605(aka TL-R605)
2022-02-19 09:05:28 - last edited 2022-02-20 14:34:35

  @Fae Thanks Fae, you're right, it's present !

Unfortunately I can't manage to establish a client to LAN VPN connection with IKev2 (and neither with IKev1), but I think it's probably due to my limited network skills.

I Don't have any issue to setup L2TP or Openvpn client to LAN connections, but I don't find a way to define correct Ipsec settings and make it work to connect with IKev2. And I did not find clear enough (for me :-)) tutorials to do it.

So I will stay with Openvpn which is a priori a good solution also (except if I finally manage one day to setup Ipsec correctly ;-)), though I would have preferred not to have to install dedicated software on remote clients.

 

Benjamin

 

Complement on Feb 20th : 

@Fae : while I was struggling to make an Ipsec policy work (which I did not manage unfortunately), I asked myself 2 questions :

- Can the L2TP/IPsec VPN mode work with the IKev2 protocol, and not IKev1 ? it would solve my problem I think.

- When trying to setup an Ipsec policy with Ikev2 protocol, for the VPN IP Pool definition it seems that it's not possible to use the same segment than the router LAN port, which would be an issue for me, and a pity because now with L2TP/Ipsec and Openvpn methods, it is possible. Do you confirm ?

 

Thanks in advance,

 

Benjamin

#18
Options
Re:Openvpn & Ikev2 missing in standalone mode of ER605(aka TL-R605)
2022-02-25 08:14:06

 @Fae Hi Fae, sorry to come back to this topic, but I still don't manage to make Ikev2 work with my router used in standalone :-(

 

Just 2 questions :

 

1 - does L2TP/Ipsec vpn mode use the Ikev1, or Ikev2 standard ? (now that Ikev2 is available in standalone mode). If Ikev2 is used, I think it answers my need. And if not, do you think it could be implemented in a next firmware ? (Ikev2 is more secure than IKev1, it includes NAT traversal functionality, and it does not require a dedicated client software as OpenVPN, so I think it would be very useful). 

 

2 - I have difficulties to make my Ipsec policy work, as you can see in https://community.tp-link.com/en/business/forum/topic/534444. My last attemps seem to show that the phase 1 / phase 2 strategies pre-defined by the router do not match with the ones expected by Windows 10 (and possibly by my iPhone). Would you have any advice on what to select, to make it work both for my PC operating Windows 10, and my iPhone operating iOS 15.3.1 ?

 

Many thanks in advance !

 

Benjamin

#19
Options
Re:Openvpn & Ikev2 missing in standalone mode of ER605(aka TL-R605)
2022-02-26 18:50:47

  @Fae 

I've upgraded the firmware on my ER605 which is in standalone mode, could you give an example of what the configuration should look like for the OpenVPN server tab?

I'm a bit confused as to what goes in the local network and IP pool fields as the field after the / has only 2 characters.

 

Thanks!

#20
Options
Re:Openvpn & Ikev2 missing in standalone mode of ER605(aka TL-R605)
2022-02-26 21:37:13 - last edited 2022-02-26 21:38:41

  @Davey_boy hi, for local subnet, it could look like either 192.168.0.0/24 or 192.168.1.0/24, depending on how you defined your lan.

24 means you can have 2^(32-24) = 2^8=256 IP's, corresponding to the last byte value (more precisely 255 from 1 to 255, 0 having a specific use).

For the IP pool, you can set it as follows :

192.168.x.y/z, with :

x = 0 or 1 in my examples - to be set according to your lan definition

y is the starting value of the range

z is set to define the number of IP's of the pool, which is 2^(32-z). If z=32, then only 1 IP possible (y, in this case). If z=31, then 2 IP's. If z=30, then 4 IP's, etc. If you set x to match with your lan subnet (can be useful to ease access to the equipment on your lan), then you will have to set y and z so that this pool does not interfere with already used ranges (e.g. DHCP, static IP's you use,...).

I hope it is clear enough.

In my case, following values work perfectly:

local subnet: 192.168.0.0/24

ip pool : 192.168.0.100/29 (meaning a pool of 8 IP's starting from 192.168.0.100).

 

Benjamin

#21
Options