Community discussions

MikroTik App
 
ediaz
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 59
Joined: Tue May 22, 2012 10:38 am

Connection between pptp users and ipsec network.

Wed Apr 17, 2013 7:30 pm

Hi,

I've got a mikrotik router that was currently being used for pptp access to an office. This worked perfectly.
Last week we stablised an IPSec site-to-site connection to a provider, which worked. We can connect from the office to the remote site without a flaw.

The problem arises when we try to get our pptp users to access the IPSec remote network. It does not work at all.

Any clues or pointers?
 
User avatar
joshaven
Member
Member
Posts: 438
Joined: Fri May 06, 2011 1:50 am
Location: USA
Contact:

Re: Connection between pptp users and ipsec network.

Sat Apr 20, 2013 3:34 am

I would guess that the pptp users don't have a route to the IPSec connected network or that the IPSec connected network doesn't have a route to the pptp users. Both ends need to know about each other or e following a default route to the concentrating router.
 
gotsprings
Forum Guru
Forum Guru
Posts: 2120
Joined: Mon May 14, 2012 9:30 pm

Re: Connection between pptp users and ipsec network.

Sat Apr 20, 2013 3:40 am

Yup.. route.

If you use a PPtP VPN on the same network... ala 192.168.0.0/24 VPN address 192.168.0.199. Assuming you have proxy-arp on... then you cn use the network. Then the IpSEC setup which relies on the network traffic being sent to the far side... well there you have it.
 
ediaz
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 59
Joined: Tue May 22, 2012 10:38 am

Re: Connection between pptp users and ipsec network.

Mon Apr 22, 2013 7:28 pm

You were right! There was a route problem.

Is there any way to "push" routes using PPTP? I use to configure Openvpn in Linux with the push route option and it worked very well, but PPTP is a pain in the *ss.
 
User avatar
joshaven
Member
Member
Posts: 438
Joined: Fri May 06, 2011 1:50 am
Location: USA
Contact:

Re: Connection between pptp users and ipsec network.

Mon Apr 22, 2013 10:09 pm

It looks like no... I don't see the option, plus normis seems to be answering no in this chain:
http://forum.mikrotik.com/viewtopic.php?f=10&t=28131

Who is online

Users browsing this forum: josser and 130 guests