How to set up a VPN Server/VPN Client on TP-Link Travel Router
This article applies to: TP-Link Travel Routers
TP-Link Travel Router can act as both VPN server and VPN client to meet all your VPN service needs.
By setting up a VPN server on your router, your connections to the router will become invisible to the internet, helping you access internet resources remotely, securely, and privately. If you set up a VPN Client on your router, all of its connected devices can enjoy the VPN services without installing VPN client software on each device.
VPN Server allows remote devices to access your home network in a secured way through the internet. The router supports four types of VPN Server:
- OpenVPN is somewhat complex but with higher security and more stability, suitable for restricted environments such as campus network and company intranet.
- PPTP VPN is easy to use with the built-in VPN software of computers and mobile devices, but it is vulnerable and may be blocked by some ISPs.
- L2TP/IPSec VPN is more secure but slower than PPTP VPN, and may have trouble getting around firewalls.
- WireGuard VPN is a secure, fast and modern VPN protocol. It is based on the UDP protocol and uses modern encryption algorithms to improve work efficiency.
VPN Client allows devices in your home network to access remote VPN servers, without the need to install VPN software on each device.
Follow steps below to set up your VPN Server on your TP-Link Travel Router. Here we take TL-WR1502X as example.
In the OpenVPN connection, the home network can act as a server, and the remote device can access the server through the router which acts as an OpenVPN Server gateway.
To use the VPN feature, you should enable OpenVPN Server on your router, and install and run VPN client software on the remote device. Please follow the steps below to set up an OpenVPN connection.

- Visit http://tplinkwifi.net, and log in with your TP-Link ID or the password you set for the router.
- Go to Advanced > VPN Server > OpenVPN, and tick the Enable box of OpenVPN.

- Enter the necessary information and save the settings.

- Service Type: Select the service type (communication protocol) for OpenVPN: UDP/TCP.
- Service Port: Enter a VPN service port to which a VPN device connect, and the port number should be between 1024 and 65535.
- VPN Subnet/Netmask: Enter the range of IP addresses that can be leased to the device by the OpenVPN server.
- Client Access: Select your client access type. Select Home Network Only if you only want the remote device to access your home network. Select Internet and Home Network if you also want the remote device to access internet through the VPN server.
- Click GENERATE to get a new certificate.

- Click EXPORT to save the OpenVPN configuration file which will be used by the remote device to access your router.

- Click SAVE.
- Now you need to configure OpenVPN connection on your remote device.
- Visit https://openvpn.net/community-downloads/ to download the OpenVPN software, and install it on your device where you want to run the OpenVPN client utility.
Note: You need to install the OpenVPN client utility on each device that you plan to apply the VPN function to access your travel router. Mobile devices should download a third-party app from Google Play or Apple App Store.
- After the installation, copy the file exported from your router to the OpenVPN client utility’s “config” folder (for example, C:\Program Files\OpenVPN\config on Windows). The path depends on where the OpenVPN client utility is installed.
- Run the OpenVPN client utility and connect it to OpenVPN Server.
PPTP VPN Server is used to create a PPTP VPN connection for remote devices to access your home network.
To use the VPN feature, you need to set up PPTP VPN Server on your router, and configure the PPTP connection on remote devices.
Please follow the steps below to set up a PPTP VPN connection.
- Visit http://tplinkwifi.net, and log in with your TP-Link ID or the password you set for the router.
- Go to Advanced > VPN Server > PPTP, and tick the Enable box of PPTP.

- Enter the necessary information and save the settings.

- Client IP Address: Enter the range of IP addresses (up to 10) that can be leased to the devices by the PPTP VPN server.
- Allow NetBIOS passthrough: Enable it to allow your VPN device to access your Samba server using NetBIOS name.
- Allow unencrypted connections: Enable it to allow unencrypted connections to your VPN server.
- Account List: Add the PPTP VPN connection account (user name and password) for the remote device. You can create up to 16 accounts.

- Now you need to configure PPTP VPN on your remote device. The remote device can use the Windows built-in PPTP software or a third-party PPTP software to connect to PPTP server. Here we use the Windows built-in PPTP software as an example.
1) Go to Start > Control Panel > Network and Internet > Network and Sharing Center.
2) Select Set up a new connection or network.

3) Select Connect to a workplace and click Next.

4) Select Use my Internet connection (VPN).

5) Enter the internet IP address of the router in the Internet address field. Click Create .

6) Enter the User name and Password you have set for the PPTP VPN server on your router, and click Connect.

7) Click Connect Now when the VPN connection is ready to use.

L2TP/IPSec VPN Server is used to create a L2TP/IPSec VPN connection for remote devices to access your home network.
To use the VPN feature, you need to set up L2TP/IPSec VPN Server on your router, and configure the L2TP/IPSec connection on remote devices.

Please follow the steps below to set up the L2TP/IPSec VPN connection.
- Visit http://tplinkwifi.net, and log in with your TP-Link ID or the password you set for the router.
- Go to Advanced > VPN Server > L2TP/IPSec, and tick the Enable box of L2TP/IPSec.

- Enter the necessary information and save the settings.

- Client IP Address: Enter the range of IP addresses (up to 10) that can be leased to the devices by the L2TP/IPSec VPN server.
- IPSec Encryption/ IPSec Pre-Shared Key: Keep IPSec Encryption as Encrypted and create an IPSec Pre-Shared Key.
- Account List: Add the L2TP/IPSec VPN connection account (user name and password) for the remote device. You can create up to 16 accounts.

- Now you need to configure L2TP/IPSec on your remote device. The remote device can use the Windows or Mac OS built-in L2TP/IPSec software or a third-party L2TP/IPSec software to connect to L2TP/IPSec Server. Here we use the Windows built-in L2TP/IPSec software as an example.
- Go to Start > Control Panel > Network and Internet > Network and Sharing Center.
- Select Set up a new connection or network.

- Select Connect to a workplace and click Next.

- Select Use my Internet connection (VPN).

- Enter the internet IP address of the router in the Internet address field. Select Don’t connect now; just set it up so I can connect later. Then click Next.

- Enter the User name and Password you have set for the L2TP/IPSec VPN server on your router, and click Connect.

- Click Close when the VPN connection is ready to use.

- Go to Network and Sharing Center and click Change Adapter Settings.

- Find the VPN connection you created, then double-click it.

- Enter the Username and Password you have set for the L2TP/IPSec VPN server on your router, and click Properties.

- Switch to the Security tab, select Layer 2 Tunneling Protocol with IPsec (L2TP/IPSec) and click Advanced settings.

- Select Use preshared key for authentication and enter the IPSec Pre-Shared Key you have set for the L2TP/IPSec VPN server on your router. Then click OK.

Done! Click Connect to start VPN connection.

WireGuard VPN Server is used to create a Wire Guard VPN connection for remote devices to access your home network.
- Visit http://tplinkwifi.net, and log in with your TP-Link ID or the password you set for the router.
- Go to Advanced > VPN Server > WireGuard, and tick the Enable box of WireGuard.

- View the default WireGuard VPN settings, as shown above. The parameters are automatically filled in, and do NOT change them unless necessary.

- Client Access: Select your client access type. Select Home Network Only if you only want the remote device to access your home network. Select Internet and Home Network if you also want the remote device to access internet through the VPN server.
- (Optional) Click Advanced Settings to display more settings. If DNS is turned on, the router will become the DNS server of the VPN client that establishes a connection with it. Change the Persistent Keepalive time (25 seconds by default) to send out heartbeat regularly, you can also click RENEW KEY to update the private key and public key.
- In Account List, click Add to create an account.


- Username: Give a name to this account.
- Address: Enter the address of the virtual interface assigned to this account. Do NOT change it unless necessary.
- Allowed IPs (client): Traffic sent from the WireGard VPN client to the allowed IPs (client) will be transmitted through the tunnel. By default, all network traffic from clients will be transmitted through the tunnel. Do NOT change it unless necessary.
- Allowed IPs (server): Traffic sent from the WireGard VPN server to the allowed IPs (server) will be transmitted through the tunnel. Do NOT change it unless necessary.
- Pre-shared key: Enable or disable pre-shared key.
- Click SAVE, then a window pops up as below.


- Done. Now connect to the WireGuard server.
- For mobile phones, download WireGuard App from Google Play or Apple Store, then use the App to scan the QR Code to connect to this server.
- For other devices (e.g. TP-Link WireGuard VPN client), Click EXPORT to save the WireGuard VPN configuration file which will be used by the remote device to access your router.
VPN Client is used to create VPN connections for devices in your home network to access a remote VPN server.

To use the VPN feature, simply configure a VPN connection and choose your desired devices on your Deco router, then these devices can access the remote VPN server. Please follow the steps below:
- Visit http://tplinkwifi.net, and log in with your TP-Link ID or the password you set for the router.
- Go to Advanced > VPN Client and enable it.

- Add VPN servers in the Server List, and enable the one you need.

- 
	- In the Server List section, click Add.
- Specify a description for the VPN, and choose the VPN type.
- Enter the VPN information provided by your VPN provider.
 
- OpenVPN: Enter the VPN username and password if required by your VPN provider, otherwise simply leave them empty. Then import the configuration file provided by your VPN provider.  
You can also select Import the CA file or edit the . ovpn file manually, then upload the CA file or manually configure the settings. 
- PPTP: Enter the VPN server address (for example: 218.18.1.73) and the VPN username and password provided by your VPN provider.

- L2TP/IPSec VPN: Enter the VPN server address (for example: 218.18.1.73), VPN username and password, and IPSec pre-shared key provided by your VPN provider.

- WireGuard VPN: Give a description, and click BROWSE to import the WireGuard VPN server configuration. Then you will see the detailed parameters. Do NOT change the parameters unless necessary.

- 
	- Save the settings.
- Specify a description for the VPN, and choose the VPN type.
 
Enter t
- In Device List, add VPN clients that will access the VPN server you have configured.



Done! Now the devices you specified can access the VPN server you enabled.
Get to know more details of each function and configuration please go to Download Center to download the manual of your product.
Is this faq useful?
Your feedback helps improve this site.
 
                      TP-Link Community
Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.
 61061
61061 
             
            