Ok i’am explain in more detail.
I want not only Site-to-Site VPN, but also L2 bridging.
Configured PPTP + BCP Bridging like in this instruction http://wiki.mikrotik.com/wiki/Manual:BCP_bridging_(PPP_tunnel_bridging)
or another config - L2TP + EoIP bridge
http://wiki.mikrotik.com/wiki/Manual:Interface/L2TP
https://ru.scribd.com/document/48678295/Mikrotik-VPN
The result is the same.
Host1 <–LAN 192.168.0.0–>[bare metal Mikrotik]<—Internet—>[CHR vm Mikrotik]<–LAN 192.168.0.0> Host2
Ping test (LAN):
Host1 → CHR vm Mikrotik - OK
Host1 → Host2 - Fail
bare metal Mikrotik → CHR vm Mikrotik - OK
bare metal Mikrotik → Host2 - Fail
Host2 → bare metal Mikrotik - Fail
Host2 → Host1 - Fail
CHR vm Mikrotik → bare metal Mikrotik - OK
CHR vm Mikrotik → Host1 - OK
CHR vm Mikrotik (PPTP server):
[admin@MikroTik] > interface pptp-server print detail
Flags: X - disabled, D - dynamic, R - running
0 DR name="<pptp-ppp1>" user="ppp1" mtu=1450 mru=1460
client-address="xx.xx.xx.xx" uptime=39m6s
encoding="MPPE128 stateless"
[admin@MikroTik] > interface bridge print
1 R name="bridge_local" mtu=1500 actual-mtu=1500 l2mtu=65535 arp=enabled
arp-timeout=auto mac-address=00:50:56:01:07:95 protocol-mode=rstp
priority=0x8000 auto-mac=no admin-mac=00:50:56:01:07:95
max-message-age=20s forward-delay=15s transmit-hold-count=6
ageing-time=5m
[admin@MikroTik] > interface bridge port print
Flags: X - disabled, I - inactive, D - dynamic
# INTERFACE BRIDGE PRIORITY PATH-COST HORIZON
0 ether1 bridge_local 0x80 10 none
1 D <pptp-ppp1> bridge_local 0x80 10 none
[admin@MikroTik] > ip address print
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK INTERFACE
0 yy.yy.yy.yy/24 yy.yy.yy.yy ether2
1 192.168.120.1/24 192.168.120.0 bridge_local
bare metal Mikrotik (PPTP client):
[admin@MikroTik] > interface pptp-client print detail
Flags: X - disabled, R - running
0 R name="pptp-out1" max-mtu=1450 max-mru=1450 mrru=disabled
connect-to=yy.yy.yy.yy user="ppp1" password="xxx"
profile=ppp_bridging keepalive-timeout=disabled add-default-route=no
dial-on-demand=no allow=mschap1,mschap2
[admin@MikroTik] > interface bridge print
1 R name="bridge_local" mtu=1500 l2mtu=1588 arp=enabled
mac-address=4C:5E:0C:98:B9:BB protocol-mode=rstp priority=0x8000
auto-mac=no admin-mac=4C:5E:0C:98:B9:BB max-message-age=20s
forward-delay=15s transmit-hold-count=6 ageing-time=5m
[admin@MikroTik] > interface bridge port print
Flags: X - disabled, I - inactive, D - dynamic
# INTERFACE BRIDGE PRIORITY PATH-COST HORIZON
0 ether1-master-local bridge_local 0x80 10 none
1 D (unknown) bridge_local 0x80 10 none
[admin@MikroTik] > ip address print
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK INTERFACE
0 ;;; lan
192.168.120.203/24 192.168.120.0 bridge_local
1 ;;; internet
xx.xx.xx.xx/30 xx.xx.xx.xx ether2-slave-local
...