Weird, I followed the instructions in the link above and I was able to get the VPN to work with my BGW320-500->TL-R605 running IP Passthru. What is the error you’re receiving?
Correct, I have to hop on cell to VPN in. I did try from my guest network but I don’t think TP-Link allows for hairpin routing (could be wrong on that though).
Turns out I entered the MAC address for the router from the controller page and it was different from the one in the AT&T router by one byte (the last two hex values).
So close that I missed it. Now that the MAC address is correct it connects just fine.