VPN using CHR (VPN clients can't see an MKT connected as VPN client)

vpn design.jpg
Hi there,

I’m trying to configure a VPN solution using CHR, I can’t use a regular procedure to create Point-to-Point because IPs publics are not available using the ISP providers where I live.

I put a CHR in a cloud with Public IP using PPTP, server and a couple of VPN clients with Android. I can do ping between these two devices but when I added a MKT hAP2 as a third VPN client nobody can’t see the MKT and the MKT can’t see the devices, I don’t understand if I need routing or I should enable some rule in the firewalls or I’m using VPN server inappropriate. I attached the idea design.

Please help..!!
vpn design.jpg

You have similar problem with me in http://forum.mikrotik.com/t/aws-chr-as-l2tp-ipsec-vpn-site-to-site-not-working/147984/1
I’m using L2TP/IPSec and CHR on AWS

I encountered your problem before can’t see can’t ping some of devices
I believe this is routing problem either in cloud CHR or hAP