MikroTik VPN connection

Hello everybody,

I have a problem with configuring a MikroTik to acces VPN connection. I have to integrate the MikroTik in an industrial manufacturing system and I want to be able to connect with all the devices via VPN (PLCs, Drives, Robots, HMIs etc.). The MikroTik will receive internet via WiFi or via cable (now I did the configuration for WiFi method). There is no problem with the MikroTik receiving internet, but the VPN connection is giving me a hard time and I’m hoping you can help me. I’ll attach a document explaining the steps that I did, with all the configuration ilustrated with pictures.

P.S.: When I try to connect to the VPN via Windows menu I receive the following message: “The L2TP connection attempt failed because the security layer encountered a processing error during initial negotiations with the remote computer”

Thank you for your time and help!

Best regards,
Claudiu
MikroTik VPN.docx (324 KB)

Any exploit in attached docx file? :slight_smile:

Please don’t use L2TP for VPN for prod. nowadays.

Weak cryptographic standards,
Vulnerability to brute-force attacks on pre-shared keys,
Potential backdoors or compromises in IPsec, and Poor performance compared to modern protocols.

If you’re using a VPN, it’s better to opt for OpenVPN, WireGuard, or IKEv2/IPsec with strong cryptographic settings for a more secure and efficient connection.

List of L2TP-Related CVEs
CVE-2023-20227
CVE-2023-21679
CVE-2023-21757
CVE-2022-4129
CVE-2016-10200

Hello,

Thank you for your response, I’ll check the OpenVPN configuration.

Best regards and Happt Holiday!
Claudiu

Can your mikrotik access a public IP, or get a port forwarded to it from the upstream ISP router?
Additionally what is the flow direction of the VPN??

External customers from everywhere to reach machines?
External router to reach machines?
Local Machines to go out internet of another router?
Local Machines to go to link to cloud Server or another router (both via VPN)??