Feature Request: OpenVPN [ovpn] udp tunnels

Looks like thay haven’t managed to make it work like it should so they just cut it off from the software. It would be nice if they talk to us e tell why such important features inside OpenVPN are not going to be implemented.
Sorry mikrotik team… but it sounds like lazy developers trying to not have to debug the code…

Anyway…
+1 for OpenVPN full support!

I also would like to see the ovpn over udp in ros.

I don’t think we need all features of OpenVPN. UDP support requires the same effort as TCP support, which I find hard to believe would be difficult at all. When I configure OpenVPN by hand, it is a single line where I write either “TCP” or “UDP”. Not exactly rocket science. I don’t believe that implementing that should trigger any suicide. Almost every OpenVPN implementation I have worked with is using UDP for performance reasons. The choice to use TCP to me is very strange anyhow.

At least consider to implement UDP. Please!

+1 for UDP on openvpn !

+100500 for ovpn udp lzo

Please add UDP for openvpn !

+1 for udp.

+100999500100999500100999500100999500100999500 for ovpn udp lzo

pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz pleaz

ok just kidding. As stated before nobody cares about +1, please, whatsoever.

I second tls-auth support. I work for an ISP that offers VPN services to our internet connectivity customers and if RouterOS supported TLS auth, we would sell a lot of these devices. The demand for our VPN keeps growing every day, more and more customers are looking to do “whole home VPN”, and are struggling to find an inexpensive, “off the shelf” router that supports this with OpenVPN. I have wished a long time for myself and them ROS could do tls-auth.

+100500 for ovpn udp!!!

+1 for lzo.

We are going to replace all our routers and lzo is a requirement :frowning:

Yes please, OpenVPN is in a urgent need of an update, I can’t understand why this is being ignored for such a long time.

Probably because of RouterOS 7.x :slight_smile:

At first I could not understand either, but now I do:
I thought that there was just a standard OpenVPN daemon running on the MikroTik, which maybe had to be updated to a
recent version and some config widgets added to the GUI.
But in one of the many posts about this subject it was revealed that this is not the case. The OpenVPN on RouterOS is an own
implementation that does only part of the protocol. And of course, extending that to a full version takes a lot of work.

I don’t know why the existing and widely used OpenVPN is not used, but it may be a licensing issue.
I have had another router that once offered OpenVPN and after an update this functionality vanished without explanation.
Maybe the OpenVPN folks are actively pursuing use of their software outside of their conditions (e.g. in a close-source product).

Well if to go on their website you can scroll through the Licensing page and you can clearly see there are 3 types of licensing, the first two are related to their own Access Server implementation and not the case we look for and the third one is the OpenVPN® Open Source Community Software which I suppose is the one most use, so if there are any licensing problems then those must be tied to these two:
• OpenVPN 2 Open Source Software License is governed by GNU General Public License version 2 (GPLv2).
• OpenVPN 3 Open Source Software License is governed by GNU Affero General Public License (AGPL).

That being said I don’t think the case you were explaining is because of licensing as generally GPL is good for everyone, probably it’s mostly tied to the popularity of a service, so if their metrics say that service was used by a low number of customers who purchased their routers then they wouldn’t see any benefit in investing development resources into that, leading to an out of date service and it’s removal as not to receive complaints about a service being offered but not working as it should.

Unless this http://forum.mikrotik.com/t/radius-server-not-working-in-2-8-11/127/1
post has been invalidated. It will be in V7.

Normis & Mr Z Please correct me if I am wrong.

Also I found out and interesting fact about OpenVPN, it is not multl-threaded, it is single threaded, meaing it doesn’t scale with ANY SMP architecture.

Normis and Mrz are the IPSEC and SSTP Implementations in the RouterOS multi-threaded?
Is this and the other issues listed @ https://community.openvpn.net/openvpn/wiki/RoadMap#Threading the reason for the long delay in adding UDP and LZO Comp to OpenVPN?

If it is, do you plan to share how you are solving it with the OpenVPN Authors?

We all know that. But there is no indication whatsoever there will ever be a V7. So that is useless info.
People are waiting for something they can use, don’t want to be referred to some future product that may or may not
become available in 3 years time.

True. I am more curious as to if the issues making it take so long are the ones I brought up.

openvpn clients in routers with tls-auth, udp, compression are industry standard by now… Did Mikrotik ever comment on the openvpn deficiency resp. corrective actions?

While Mirotik plan for 100G ports in upcoming routers maybe they can offer open module spec if they unable to implement ovpn module?

OVPN is one os the main distinct feature of MT. And while ovpn developers at openvpn.net produce one version after another MT developers won’t make good implementation?

Please, please! Ovpn is the Swish Knife in network field so it is a shame not to use it. Yes, this is not that Enterprise thing but a lot of people uses it!