I am trying to configure a l2tp ipsec tunnel with two rb2011uias-2hnd-in’s. I have configured it according to the example given in http://wiki.mikrotik.com/wiki/L2TP_%2B_IPSEC_between_2_Mikrotik_routers and both the tunnel and the IPsec connection are working (I think). That is, I can see installed SA’s. What is not working is that when I try to ping a client from either side of the tunnel, it doensn’t work. I have already tried to put in NAT bypass rules but it is still not working.
The reason I want to make the VPN tunnel is that my family and I will be living abroad for a year, but we still want to use our NAS, which stay at home and we also would still like to be using Netflix. We live in Holland by the way. So basically I want to route all traffic from abroad over the tunnel and break out to the internet in Holland. Could anybody give me some suggestions how to accomplish this?
I am not using the same subnet, it is different subnets. Funny thing is that I can ping the ip addresses of the tunnel, so the tunnel seems to be working fine, but once I go outside, nothing happens. If I ping from the router to for example 192.168.88.1 I get a reply but if I try to ping from the router to a client, nothing happens. So probably I am doing something wrong with routes or NAT but I can’t figure out what it is I am doing wrong. I also double checked my IPSec policies and they seem to be ok.
Maybe I don’t understand it but I don’t have a road warrior setup, I made the site to site L2TP IPSec setup as described in: http://wiki.mikrotik.com/wiki/L2TP_%2B_ … ik_routers
When I look at PPP then it the l2tp connection shows up so I really don’t understand what you mean
You may be forced to use a non bridgeable router, and residential lines doesn’t have fixed ips usually, they vary if you reboot, etc.
I think it’s too soon to know what’s the best tunnelling scheme for your real scenario. One thing is for sure, leave the Holland router firewalled but being able to login remotely, enable ip > cloud and take note of your router’s name. Once in Italy will be the time to get things straight.