VPN to connect home network to cottage

Good morning everyone,

I’m looking at getting some help in the design and setup of extending my home network to my cottage so that I have access to all my services from both locations. I will post my current setup when I get back home but I wanted to first know what device I should get for the cottage location.

I currently have a RB4011iGS+5HacQ2HnD-IN with wifi (my kids call it the little alien). I also have a Cap AC (2.4&5GHz) to extend my WiFi around the house. I will probably need some Cap AC for the cottage as well, but that can be done once I have the initial connection.

At the cottage, I have had my Starlink working flawlessly and using only that. But now I would like to be able to start working from the cottage, have access to my home network (NAS, home server, Plex server, home automation server extension) to make it feel like I’m still at home. I continue to want WiFi in the cottage, be able to use my streaming services, add the cottage printer to the network.

So my first question is: What would be the recommended device to enable this connectivity? Should I just buy another 4011? Or is there something else that would work better?

Once I know the device, I’m hoping that is half the battle. My home network has a couple vlans, for the home automation stuff, the server stuff, and an admin one.

Thank you in advance for all the help. I’ll post my config either later today or tonight.

Cheers,

Question 1:
What kind of Speed’s are available via Starlink in your location ?
Something like ~ 70 Mbps (Download) and ~ 20 Mbps (Upload) ?

Question 2:
What kind of Speed’s are available at Home ?

Question 3:
Do you have a Public IP at Home?

  1. I am getting on averate 125 Mbps download and 20 Mbps upload
  2. I have 500/500 FTTH service
  3. If you mean do I have a static IP the answer would be no, but I do have my RB4011 which has DDNS enabled so I have at least that DNS that is reachable from anywhere.

I’ve attached my current home network config. @anav was nice enough to help me get this working. I’m sure there are still some things in there that should be cleaned out from me testing and tinkering here and there. TBH, I don’t even know if my minecraft port forward works. haha. I haven’t used it outside my network in a long time.

Thanks for the help!
10Oct21RB4011.rsc (11.2 KB)

  1. Router-Config
    Just in case your “Virgin Mobile” ist still active,
    You may want to remove some User-Information
    under → service-name=“Virgin Mobile PPPoE” user=…

  2. Hardware for Cottage
    If money isn’t a issue, another RB4011 isn’t a bad choice
    It as a lot of features , like WLAN, 10 Ether-Ports, etc…
    Performace of the Router can provide good IPsec-Tunnel with your ISP-Speeds.

If money or space is an issue, a cAP ac can be used.
It still as WLAN for the Cottage and 2 Ether-Port (1x for Starlink and 1x for PC or printer)
IPsec throughput isn’t bad, but will be the limiting factor (bottleneck) of the system.

Small addition to my last Post…
I assumed a “small” Cottage, but if you are already planning on multiple AP’s
then I need to think bigger :smiley:

Alternatively to the RB4011…
You could use the very powerfull RB5009UG+S+IN
in conjunction with one or more AP’s like the cAP ac.

Yep, missed that Virgin part. It’s an old cancelled service, not a huge issue.

I was figuring it would be best to just get another 4011. It will help with the expansion in the cottage (not so small, probably more like a retirement home). I do think that the 5009 is a bit overkill for what I need. Had to look it up, what a nice piece of kit!

What would the next steps be in getting this setup?

Ordered the RB4011 (wifi version). I’ll pick it up tomorrow and be able to install it on the weekend. :slight_smile:

Then I can work on learning how to extend my current network out to the cottage.

I figure there will be 2 types of devices at the ‘cottage:’ Home_Devices and IoT. So I will need to figure out how to extend both VLAN15 and VLAN50 out to the cottage.

Thanks for the help so far! I really appreciate it.

A little “Food for Thought” until your new RB4011 arrives,

RouterOS supports many VPN and Tunneling Solutions.
But which one is the right one ? :smiley:

The Main Question right now is,
Do you want or need Layer2 connectivity between your Main-Network and the Cottage?

Wireguard is the right solution, WHEN its out of beta, so you really mean in the interim ?? :wink:

Yes, of course !!!
I hope we will get a Stable Ver.7 as a early Christmas present from Mikrotik :smiley:

@hahnhell
The export is really Sympatic oh…
you forgot to Hide Something while Export…

Yep, we mentioned that above. I went ahead and removed the PPPoE info from my defunct Virgin Mobile services. They've been deactivated for some time now. I went back to B[H]ell Fibe, got a plan for less money and upped my speed by 5x (and now it's symmetric).

Wireguard huh? That looks neat. I'll have to think about what I want to do exactly with the VPN. I honestly think right now it's just going to be an extension of my VLAN50 and VLAN15. I want to be able to access my Plex server as a local device on my googletv, will probably add a network printer at the cottage. That is probably it for now, until I start doing some work-from-home at the cottage, then my needs will change somewhat.

Good to see you @anav!

Sympatico HSE is Virgin?

Not sure where you’re finding anything about Sympatico in that file :frowning: I haven’t used/heard of that service since the 90’s when I was living at my parents. I would have removed any public facing IPs if there were any in there… the only other item I see with a 76 in there is one of the MAC for the wireless interface.
Are we looking at the same file?

[removed for not provide hint…]

Ah you’re right! Man there is a lot of simple things I keep forgetting about with this. Not that anything is accessible through that outside facing address.

Thanks for the insight. I’ll do the changes above.

And sympatico is Bell.. and Virgin is a sub of Bell, so yeah it probably was similar before when I was with Virgin.

Thanks for the lesson! I don’t look for these things anymore. Maybe I should take some refresher courses.

No Problem, as a Thank you just send us a nice bowl of Poutine !

hahaha I hope rextended didnt also take your virginity at the same time…