Community discussions

MikroTik App
 
drbunsen
newbie
Topic Author
Posts: 40
Joined: Fri Apr 29, 2016 7:24 pm

L2TP client change destination port away from UDP 1701

Fri Apr 29, 2016 7:39 pm

Hi,
I'm trying to configure L2TP as a client, but it needs to connect to a server which runs its service on a different port than 1701.
Is there any way to change the destination UDP port away from the standard 1701?
Thanks in advance.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10239
Joined: Mon Jun 08, 2015 12:09 pm

Re: L2TP client change destination port away from UDP 1701

Tue May 03, 2016 2:37 pm

Did you try :port after the address? Maybe it works.
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: L2TP client change destination port away from UDP 1701

Tue May 03, 2016 4:09 pm

Not possible directly.
 
drbunsen
newbie
Topic Author
Posts: 40
Joined: Fri Apr 29, 2016 7:24 pm

Re: L2TP client change destination port away from UDP 1701

Tue May 03, 2016 8:28 pm

Yes, I've tried :port, but it's not being accepted as entry.

@mrz: Does "not directly" mean not at all or maybe possible with some sort of trick?
 
pe1chl
Forum Guru
Forum Guru
Posts: 10239
Joined: Mon Jun 08, 2015 12:09 pm

Re: L2TP client change destination port away from UDP 1701

Tue May 03, 2016 8:50 pm

Of course you can try dstnat...
 
drbunsen
newbie
Topic Author
Posts: 40
Joined: Fri Apr 29, 2016 7:24 pm

Re: L2TP client change destination port away from UDP 1701

Tue May 03, 2016 9:20 pm

Not sure if I'm doing it right, just tried with:
/ip firewall nat
add action=dst-nat chain=dstnat dst-address=1.1.1.1 dst-port=1701 \
    protocol=udp to-addresses=1.1.1.1 to-ports=10000
However, I still see packets leaving with 1701 as destination and the counters for this rule are not increasing.
To be honest I would not even expect this to work, why should the box send it's own traffic through this chain?
Thanks for this idea though.
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: L2TP client change destination port away from UDP 1701

Wed May 11, 2016 5:12 pm

DST nat wont work because it is processed in prerouting. Locally originated packets do not get into prerouting chain.

You can change port if you add another device between server and client adn run DST NAT there.
 
drbunsen
newbie
Topic Author
Posts: 40
Joined: Fri Apr 29, 2016 7:24 pm

Re: L2TP client change destination port away from UDP 1701

Thu May 12, 2016 3:31 am

OK, so it's not possible with a device on the border of the network :(
Would you please consider to add a variable destination port for L2TP in a future routeros version?
 
jo2jo
Forum Guru
Forum Guru
Posts: 1003
Joined: Fri May 26, 2006 1:25 am

Re: L2TP client change destination port away from UDP 1701

Sat Jan 28, 2017 10:51 pm

is this feature still not added as of 6.38.1? why can we not change the port L2TP uses?

I under stand we can add another MT but thats another point of failure and another device to have to manage (for just one simple feature request).

tks

Who is online

Users browsing this forum: gabeluci, tdw and 53 guests