Hi, Mikrotik community! After 4 years of using Mikrotik products on my home network, experimenting with Hairpin NAT, using L2PT VPN with Mikrotik cloud service, I need some guidance.
I have a fairly complicated home automation system in my house, controlling most of the electric devices together with software NVR, PLEX and SAMBA.
For about two years I used the Hairpin NAT to access the local network from the outside which worked great but, it just didn’t feel right.
I decided to use L2PT VPN (from the quick set) and it worked but after a few minutes, it used to block the internet access to the phone I was using to access my home network through the VPN.
Recently I changed the phone and there is no option for the insecure VPN connection. The only options are IKE2/IPSec MSCHAPv2, IKEv2/IPSec PSK and IKE2/IPSEC RSA.
I’m learning this stuff as I’m using it so here I am, trying to save myself some time wasted chasing some dead ends. Any opinion, or advice will be very helpfull. Thanks!
Hello,
L2TP/IPsec PSK is secure enough when using a strong pre-shared key for home and it is supported by iOS and Android. However, if you prefer IKEv2 you can use RSA with v6 or EAP with v7 RouterOS.
Keep in mind that once you have done any config manually, you should NEVER touch QuickSet again - it will likely blow away any changes that you previously made.
I tried to set up the VPN on my current configuration without any success. Whatever I have tried it did not establish the connection.
Then I decided to do a factory reset and start all over. Currently, I have the PPPoE internet running with CAP and a working VPN.
The server runs a network shared RAID drive, Blue Iris NVR, Home Assistance VM, Plex server and Node-Red.
Everything seems to be working but whatever I do, I cannot access the Node-Red UI from another device in the network as if something is blocking its 1880 port.
Tried to add passthrough and accept the rule for the top 1880 in firewall settings but still no luck.
Any thoughts?
In the meantime, I will keep banging my head against the wall.
Without seeing your configuration, we would only be guessing.
To export and paste your configuration (and I’m assuming you are using WebFig or Winbox), open a terminal window, and type (without the quotes) “/export hide-sensitive file=any-filename-you-wish”. Then open the files section and right click on the filename you created and select download in order to download the file to your computer. It will be a text file with whatever name you saved to with an extension of .rsc. Suggest you then open the .rsc file in your favorite text editor and redact any sensitive information. Then in your message here, click the code display icon in the toolbar above the text entry (the code display icon is the 7th one from the left and looks like a square with a blob in the middle). Then paste the text from the file in between the two code words in brackets.
Node Red started to load on other computers and then it stopped. This is all after restoring this new configuration. When kids go crazy I keep returning to the old configuration so it is constant back and forth.
I have checked the clock and the time was wrong. Set up the ntp but it would not sync. Checked if I can do the update and noticed: ERROR could not resolve dns name