One lan internet access, other lan VPN access

Hello,

I need your guidance to configure the following scenario:

I have two RUT951 routers, and I want to establish an IPSec VPN connection between them.

  • Router 1: It has an internet connection via the WAN port. LAN 1 (ports 1 & 2) should be able to access the remote network behind Router 2 via the VPN, but should not have internet access. Port 3 should have internet access but no access to the VPN or LAN 1.
  • Router 2: It has an internet connection via SIM1. LAN 1 (ports 1 & 2) should be able to access the remote network behind Router 1 via the VPN, but should not have internet access. Port 3 should have internet access but no access to the VPN or LAN 1.

It is very important that neither router be accessible from the internet, only via VPN.

Thank you,