Question How can I get my VPN to work on a new Hauwei B23686-66 Router ?

Jul 6, 2023
2
0
10
I'm tearing my hair out over this problem, I apologize for this being my 1st post, but I didn't know of anywhere better to get help and am at my wits end.

I recently had installed a Hauwei B23686-66, this is an outdoor CPE device paired with an LTE Router. I know this isn't an ideal setup, but sadly I've just moved to the countryside in Morocco, and there is no DSL or Fibre connection out here, plus the coverage distance for both Inwi and Orange is absolute tosh here so I had to get the outdoor CPE to extend the signal strength.

Anyway I am trying to apply the VPN directly on the Router, it only provides a L2TP Protocol for VPN, and GRE VPN whatever that is. Most of the tech here in Morocco is out-dated so I had to register with PrivateVPN as they seem to be the only VPN providing L2TP support these days. The VPN works fine in the app, and I previously had it on another Hauwei LTE Router I had setup prior to this one, so there isn't an issue with connectivity to the VPN's server.

The basic problem is I have put in the VPN precisely, it connects and says "Tunnel create successful" suggesting the VPN is active or atleast functional. But I cannot for the life of me get the VPN to actually work despite this! Whenever I check my IP it still remains in Morocco. I've done this a thousand times over, trying to even connect to different IPs in the hosts range (i.e 193.180.119.66-72)

This is the interface I'm provided to insert the L2TP:

a6RtZ1.png

I don't really understand these settings like Auth Protocol or L2TP Protocol Layer very well, but Layer3 L2TP with MSCHAPv2 is the only combination that worked. Layer2 or any other combination of Auth Protocol results in "connection hang up" or "connection dropped".

Note: I'm aware it says IP Pass Through feature can't be used, but I cannot find this feature anywhere in the settings! It seems other versions of the B23686 have this setting in the Broadband section, searching the manual shows nothing, my Broadband setting page only allows you to insert a SIM Pin, nothing else.

Here is the monitoring page showing the VPN has created a tunnel successfully:
9vNLqW.png


Now I have found the instruction manual which mentioned something about Static Routing needing to be applied in order for Tunnelling to successfully work, as I understand it it says the CPE doesn't automatically route the traffic through the L2TP tunnel., I'm not sure if this is what people term "split-tunnelling", which is why the VPN is inoperable as it doesn't support this? Here is that section in the manual:


wMGvku.png
OA7n9E.png


I included the right image because it also mentions the Lan PC IPs must be in different subnet domains, bit confusing that the text below doesn't match the image IP's, not sure why. I don't really understand all this so this is what I configured:

g4bhlU.png


I have tried the Interface setting! It gives me the option of Data, lan/b0, L2TP, GREVPN, I don't know what any of these are. but I tried L2TP Interface thinking that must be it, and nothing!

I have no clue if this is correct, basically my main device is in the IP range 192.168.2.0-255. And all my other devices in 192.168.1.1-70. I did this because I guess this is what it meant by different subnet domains? :unsure: Though I'm not sure if it's just suggesting this if you want some devices with a VPN and not the others. i.e it's optional, not essential?

I have incorrectly put in the Server IP there. And it is disabled. This was just me farting around with things. Initially this was the Local IP from the L2TP page shown above, which is what Im sure you put for the Gateway IP here...

Once I activate this my internet immediately stops working on my Laptop, not on the other devices which is correct because they aren't in the assigned range, but I just don't get why it won't bloody work! I've been going crazy trying everything, I tried to put the device IP in the same subnet domain. i.e 192.168.1.70-255. I tried re-fetching the L2TP local IP by disabling and re-enabling the VPN, I tried different servers for the VPN, the provided local L2TP IP by the way successfully updates on the static routing page when changed so it's clearly interlinking the two. I've turned off the routers firewall, windows firewall, reset the network countless times, reboot the router after both assigning the VPN and the static route, reset the router completely and tried again, I enabled IPRouting in the registry. I tried to add my phone instead of the pc, and that also stopped connecting too, so it isn't isolated to one device!

I imagine hopefully it's just some silly mistake because I have no clue about what I'm doing.

Again I've tested the VPN and it works so I just have no clue! Any help would be greatly appreciated!!
 
Last edited:
I am not sure if I can be of much help, it has been a very long time since I used just L2TP. Every time I have ever used it I ran ipsec over the top of it.
l2tp and gre are not encrypted so they are not used much for vpn.

You might consider placing another router in front of this equipment that can use more common forms of vpn. Many routers now support wireguard and openvpn. Using a asus router with a merlin firmware image tends to have the most support but I think asus now supports both wiregurad and openvpn in the factory firmware.
 

TRENDING THREADS