Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG

Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG

Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG
Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG
a week ago - last edited a week ago
Tags: #VPN
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.0 Build 20250428 Rel.18967

Hi guys!

 

I'm just getting out of options, I'm trying to estabilishing a Site-to-Site VPN with my customer ER605 and my Unifi UCG.

 

Already tried every options from SHA, IKE versions, PSK, PFS but nothing see to work, everytime i get on the logs of the UCG: NO-PROPOSAL-CHOSEN.

  0      
  0      
#1
Options
1 Accepted Solution
Re:Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG-Solution
a week ago - last edited a week ago

  @MR.S 

 

I just found the problem.

 

I need to use the IP on the tunnel configuration on the er605 side, because when he tries to resolve the name, he got the reverse ip instead.

 

When I change it to the IP worked like a charm.

 

 

Thanks for the guidance!

Recommended Solution
  1  
  1  
#12
Options
11 Reply
Re:Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG
a week ago

  @Otavio_Rievert 

 

Setting up a VPN to a UCG is quite simple, you have to make sure that you use a route based on the UCG, you should also not create any manual routing on the UCG, many people make this mistake and the tunnel does not work.

set up the UCG like this and it works.

 

 

 

 

  0  
  0  
#2
Options
Re:Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG
a week ago

  @MR.S 

 

Hi Mr, I just have the same settings like your print.

 

But the connection still refuses to go up.

 

The print below show my UCG:

 

 

Next is the ER605:

 

 

I Already tries we all combinations and the local and remote IDs in auto and not auto.

  0  
  0  
#3
Options
Re:Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG
a week ago

  @Otavio_Rievert 

 

And both have public ip on wan interface? no manual route added on UCG or ER605?

 

  0  
  0  
#4
Options
Re:Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG
a week ago - last edited a week ago

  @Otavio_Rievert 

 

Double check your phase 2 setting - you have DH14 selected as phase two but Mr.S recommended DH5 of phase 2

 

Also, do you have the ER605 as the Initiator ?  its just set as responder in your screenshot and if both are responders they will never connect

  0  
  0  
#5
Options
Re:Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG
a week ago

  @GRL 

 

unifi is not so good at IPsec there is also very little configuration, for example you can't choose local network, only remote network. so all VLANs will go in the tunnel it causes a lot of trouble for Cisco and Mikrotik routers that see these VLANs in VPN and create error messages in the log all the time. you can't choose Initiator Mode or responder mode either. also all unifi routers are painfuly slow with IPsec, even UXG-Enterprise.

 

@Otavio_Rievert 

you also have to make sure that the wan IP is tied to the VPN tunnel, I have had some problems with the WAN ip suddenly not being connected to the VPN interface.

 

 

 

 

  1  
  1  
#6
Options
Re:Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG
a week ago

  @MR.S 

About the public IP, the ER605 have a DMZ and Nat, on the ESP router I define the dmz and the port forwarding. The UCG have his public IP.

 

About the UCG I have to disable all the vlans, the point you make about him put all lans on the ipsec make a big mess on the configs.

 

I think, maybe the problem is with the Remote_ID|Local_ID, but have already tries every combination on these settings too.

 

@GRL, I set the DH like MR.S have recommended, but got the same results.

  0  
  0  
#7
Options
Re:Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG
a week ago

  @Otavio_Rievert 

 

if you have ER605 behind NAT then you have to set it to be initiator. local id name on ER605 you set to Eg ER605, on UCG you have to set Remote Authentication ID to ER605, it should work.

you don't have to disable any VLAN on UCG. ER605 works anyway.

 

  0  
  0  
#8
Options
Re:Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG
a week ago

  @MR.S 

 

So in the Local ID I have to set to NAME and what name? Like fqdn of the wan link or like "Local_ID" like shows in some docs?

 

And on the UCG side, set the Remote Authentication ID the same right?

  0  
  0  
#9
Options
Re:Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG
a week ago

  @Otavio_Rievert 

set whatever you want, but you must have the same name on both routers, set for example ER605 or 1234

  0  
  0  
#10
Options
Re:Cannot make a S2S IPSEC vpn with Er605 and Unifi UCG
a week ago

  @Otavio_Rievert 

 

here is an example that I made now, it is an ER707-M2 behind NAT that has VPN to a UX7 with public IP

 

 

 

 

 

 

  0  
  0  
#11
Options