Community discussions

MikroTik App
 
drfunk89
newbie
Topic Author
Posts: 33
Joined: Fri Nov 20, 2009 6:17 pm
Contact:

Mikrotik routing through to VPN

Wed Aug 11, 2010 5:16 pm

I have one Mikrotik, one set of computers on a 192.168.0.0/24 network plugged into one interface and one other computer plugged into the other interface of the MT on a 192.168.100.0/24 network. The second single computer has several OpenVPN servers running on it accepting multiple incoming OpenVPN connections. I have tried to route through to the OpenVPN subnets by setting the destination network as 192.168.2.0/24 (the remote OpenVPN subnet) and the gateway as 192.168.100.1...but no luck!

I need people on the 192.168.0.0/24 to see through to the remote OpenVPN subnet via the single computer on the second network!

Does this make sense and can anyone help!?

Thanks!
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: Mikrotik routing through to VPN

Wed Aug 11, 2010 5:30 pm

Unless I'm misreading what you're asking, it should be sufficient to set up a route on the router to 192.168.2.0/24 via the IP address of the OpenVPN computer. I'm assuming 192.168.100.1 is the IP of the router on the network that computer is on - that won't work.
At that point the OpenVPN machine must be set up to tunnel traffic for other clients as a gateway, and not just as an endnode in an OpenVPN connection.
 
drfunk89
newbie
Topic Author
Posts: 33
Joined: Fri Nov 20, 2009 6:17 pm
Contact:

Re: Mikrotik routing through to VPN

Wed Aug 11, 2010 5:41 pm

Yeah your right, it goes 192.168.0.0/24>>>>>>>>>>192.168.0.1-----Mikrotik-------192.168.100.1>>>>>192.168.100.2>>>>>192.168.2.0/24

I did routing through using that rule you said. Didnt work. Would there anything on Windows i would need to change, ie. Internet Connection Sharing on the 192.168.100.2 machine?? In the OpenVPN config i have "pushed 192.168.0.0" but to no avail!

Could it be a firewall thing on the MT i need to change or not?
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: Mikrotik routing through to VPN

Wed Aug 11, 2010 5:46 pm

Shouldn't be unless you're explicitly dropping traffic. The default firewall ruleset permits all traffic.

The routing really is very simple: the router receives packets for 192.168.2.0/24 and forwards it to 192.168.100.2. One single, simple route. I have no idea how to set up an OpenVPN gateway on a Windows machine, but that is sort of out of the scope of a Mikrotik forum.

Run Wireshark on that OpenVPN machine and see if you receive packets from 192.168.0.0/24 destined to 192.168.2.0/24. If you do, the router is set up correctly and you need to configure the OpenVPN machine differently. If you see a lot of packets from 192.168.100.1 for 192.168.2.0/24 you have a NAT rule that isn't granular enough and the router is NAT'ing traffic to itself on that interface. That wouldn't be a problem as such and wouldn't break connections, though - just pre-empting what you might see when capturing packets.
 
drfunk89
newbie
Topic Author
Posts: 33
Joined: Fri Nov 20, 2009 6:17 pm
Contact:

Re: Mikrotik routing through to VPN

Wed Aug 11, 2010 5:49 pm

Thanks, i'll do some testing! I didnt imagine it was a Mikrotik problem just thought i'd double check...
 
rafiullah61
just joined
Posts: 6
Joined: Wed Aug 11, 2010 5:32 pm

Re: Mikrotik routing through to VPN

Wed Aug 11, 2010 6:47 pm

hi
i have satellite internet or dsl AZTEC605eu modem i want to route my satellite ip into mikrotik router 3.30 for satellite is downlink and dsl for up link
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: Mikrotik routing through to VPN

Sat Aug 14, 2010 4:18 pm

A) what does this have to do with OpenVPN?
B) asymmetric routing through different circuits that NAT to different public IPs doesn't work. Unless you have routed IPs you own behind both circuits and both providers have routes to them through themselves you can't do that.

Who is online

Users browsing this forum: anav, Google [Bot] and 202 guests