How to configure PPTP/L2TP/OpenVPN Client to access peer server through site-to-site VPN using business router

TL-ER7206 , TL-R605 , ER7206 , ER605
Recent updates may have expanded access to feature(s) discussed in this FAQ. Visit your product's support page, select the correct hardware version for your device, and check either the Datasheet or the firmware section for the latest improvements added to your product. Please note that product availability varies by region, and certain models may not be available in your region.
User’s Application Scenario
Suppose a client is connected to Router A via VPN (PPTP/L2TP/OpenVPN), and Router A and Router B are connected via Site-to-Site VPN. Now the VPN Client wants to access a Server inside Router B through two of these two VPN tunnels.
1. The VPN Client uses PPTP/L2TP VPN
The method of PPTP or L2TP configuration is similar, here L2TP is used as an example
Configuration
Step 1. Create an L2TP VPN Server on Router A.
For a detailed configuration process, please refer to: How to establish an L2TP Server by Omada Gateway in Standalone mode?
Please note that the VPN IP Pool and the LAN IP of Router A need to be set in the same network segment, namely 192.168.0.1/24.
Note: The latest firmware of the router already supports VPN IP and LAN IP in the same network segment.
Step 2. Create an IPsec Site-to-Site VPN between Router A and Router B.
For a detailed configuration process, please refer to How to Set up Site-to-Site Manual IPsec VPN Tunnels on Omada Gateway in Controller Mode?
Here, we have established a VPN Tunnel between router A and router B.
Step 3. Connect to the L2TP Server.
Here, we used a PC connect to the L2TP Server. The IP address of 192.168.0.2 is assigned from the server.
For a detailed configuration process, please refer to: How to configure PPTP/L2TP client on remote PC?
Note: “Use default gateway on remote network” is need to be enabled.
Go to Control Panel –> Network and Internet –> Network and Sharing Center –> Change Adapter Settings, then you will find the L2TP VPN adapters. Right-click the adapter –> Properties –> Networking, Double-click “Internet Protocol Version 4” –> Advanced, then you will find the Advanced TCP/IP settings for the VPN.
Step 4. Verification process
The L2TP Client can access the server behind Router B through Site-to-Site VPN.
2. The VPN Client uses OpenVPN
Configuration
Step 1. Create an OpenVPN Server on Router A.
Go to VPN-->OpenVPN-->OpenVPN Server, create a new OpenVPN Server. Please note that the IP address range entered in Local Network should include all the LAN IP address ranges of Router A and Router B. For example, the range of 192.168.0.1/16 includes 192.168.0.1/24 and 192.168.20.1/24
Because the OpenVPN client will generate a new routing table based on the address range entered here after the connection is successfully established, it is necessary to ensure that the subnet of Router B is within this range before data can enter the OpenVPN Tunnel.
At the same time, set the VPN IP Pool and the LAN IP of Router A in the same network segment.
After the OpenVPN Server is created, wait a few minutes and export the OpenVPN configuration file and sent to clients that need to connect.
Step 2. Create an IPsec Site-to-Site VPN between Router A and Router B.
This step is the same as the above process and will not be repeated here.
Step 3. Connect to the OpenVPN Server.
Here, we used the OpenVPN GUI on the PC to connect to the OpenVPN Server. Import the OpenVPN configuration file into the OpenVPN GUI and connect. The IP address of 192.168.0.10 is assigned from the server side.
By querying the routing table on the PC, it can be found that a route to 192.168.0.1/16 is generated, and the interface is the virtual IP address of OpenVPN.
Step 4. Verification process
The OpenVPN Client can access the server behind Router B through Site-to-Site VPN.
Note: When the VPN Client uses PPTP/L2TP, Router A can be implemented in both Controller mode and Standalone mode. When the VPN Client uses OpenVPN, Router A can only implement this application scenario in Standalone mode.
To get to know more details of each function and configuration please go to Download Center to download the manual of your product.
Related FAQs
- How to configure IPSec LAN to LAN VPN for multiple subnets using the new GUI
- How to access the internet by using VPN Server as a proxy gateway
- What to do if you cannot access the remote network through Client-to-LAN/Site VPN tunnel
- How to set up PPTP & L2TP VPN Server with Omada Gateway in Controller Mode
Is this faq useful?
Your feedback helps improve this site.
What’s your concern with this article?
- Dissatisfied with product
- Too Complicated
- Confusing Title
- Does not apply to me
- Too Vague
- Other
Thank you
We appreciate your feedback.
Click here to contact TP-Link technical support.
Recommend Products

TP-Link Community
Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.
We have updated our Policies. Read Privacy Policy and Terms of Use here.
This website uses cookies to improve website navigation, analyze online activities and have the best possible user experience on our website. You can object to the use of cookies at any time. You can find more information in our privacy policy .
We have updated our Policies. Read Privacy Policy and Terms of Use here.
This website uses cookies to improve website navigation, analyze online activities and have the best possible user experience on our website. You can object to the use of cookies at any time. You can find more information in our privacy policy .
Basic Cookies
These cookies are necessary for the website to function and cannot be deactivated in your systems.
TP-Link
SESSION, JSESSIONID, accepted_local_switcher, tp_privacy_base, tp_privacy_marketing, tp_smb-select-product_scence, tp_smb-select-product_scenceSimple, tp_smb-select-product_userChoice, tp_smb-select-product_userChoiceSimple, tp_smb-select-product_userInfo, tp_smb-select-product_userInfoSimple, tp_top-banner, tp_popup-bottom, tp_popup-center, tp_popup-right-middle, tp_popup-right-bottom, tp_productCategoryType
Youtube
id, VISITOR_INFO1_LIVE, LOGIN_INFO, SIDCC, SAPISID, APISID, SSID, SID, YSC, __Secure-1PSID, __Secure-1PAPISID, __Secure-1PSIDCC, __Secure-3PSID, __Secure-3PAPISID, __Secure-3PSIDCC, 1P_JAR, AEC, NID, OTZ
Zendesk
OptanonConsent, __cf_bm, __cfruid, _cfuvid, _help_center_session, _pendo___sg__.<container-id>, _pendo_meta.<container-id>, _pendo_visitorId.<container-id>, _zendesk_authenticated, _zendesk_cookie, _zendesk_session, _zendesk_shared_session, ajs_anonymous_id, cf_clearance
Analysis and Marketing Cookies
Analysis cookies enable us to analyze your activities on our website in order to improve and adapt the functionality of our website.
The marketing cookies can be set through our website by our advertising partners in order to create a profile of your interests and to show you relevant advertisements on other websites.
Google Analytics & Google Tag Manager
_gid, _ga_<container-id>, _ga, _gat_gtag_<container-id>
Google Ads & DoubleClick
test_cookie, _gcl_au