Community discussions

 
Grocher
just joined
Topic Author
Posts: 2
Joined: Wed Feb 22, 2017 2:11 pm

PPTP vpn to Windows server inside my network

Mon Mar 13, 2017 8:15 pm

So i finally have some basics down and got my first firewall setup and doing what i wanted it to do except for setting up a PPTP vpn to a Windows Server essentials 2012 R2 machine behind the Firewall.
So my setup looks something like this, i have a Huawei 4G router providing me with internet access connected to ether 1 on my RB750r2, ether 2-4 are bridged for LAN.

so my 4g router has a IP of x.x.0.1, my wan port on my rb750 has the ip x.x.0.25, on the LAN side my router ip is x.x.1.1 and my server has the IP of x.x.20. what i have done thus far is forward the ports from my 4g router to my rb750, this part works as i have a firewall rule in the input chain that allows packets to the router and i can see the packet count go up every time i try to initiate the connection
any and all help would be appreciated.
 
User avatar
matiaszon
Member
Member
Posts: 305
Joined: Mon Jul 09, 2012 9:26 am

Re: PPTP vpn to Windows server inside my network

Mon Mar 13, 2017 10:51 pm

Just to make sure - you want MikroTik to work as PPTP server and you remote machine as a client, right? If so, I understand that your ISP gives you public IP or your server and client are in the same local network. It's hard to understand from your hidden IP addresses.
 
sebus
newbie
Posts: 38
Joined: Sun Mar 12, 2017 6:29 pm

Re: PPTP vpn to Windows server inside my network

Mon Mar 13, 2017 10:55 pm

Most likely he wants to setup PPTP VPN ON internal Windows Server, so only NAT should be required (with correct FW rules)

Which ports to unblock for VPN traffic to pass-through?
 
User avatar
matiaszon
Member
Member
Posts: 305
Joined: Mon Jul 09, 2012 9:26 am

Re: PPTP vpn to Windows server inside my network

Mon Mar 13, 2017 11:07 pm

OK, I get it now. So need to put it in console:
/ip firewall nat add chain=dstnat protocol=tcp port=1723 in-interface=ether1 action=dst-nat to-addresses=x.x.0.20 to-ports=1723
 
janus20
Member Candidate
Member Candidate
Posts: 111
Joined: Thu Nov 03, 2016 10:31 am
Location: Pitesti, Romania

Re: PPTP vpn to Windows server inside my network

Tue Mar 14, 2017 9:43 am

Hi,
OK, I get it now. So need to put it in console:
/ip firewall nat add chain=dstnat protocol=tcp port=1723 in-interface=ether1 action=dst-nat to-addresses=x.x.0.20 to-ports=1723
... and depending on his firewall filter rule might add this as well:
/ip firewall filter
add action=accept chain=input comment="Accept PPTP connection to be forwarded" dst-port=1723 in-interface=\
    ether1 log=yes log-prefix=pptp-passthrough protocol=tcp
kind regards,
 
sebus
newbie
Posts: 38
Joined: Sun Mar 12, 2017 6:29 pm

Re: PPTP vpn to Windows server inside my network

Tue Mar 14, 2017 9:29 pm

Or use the magic rule
/ip firewall filter
add action=accept chain=forward connection-nat-state=dstnat
 
janyao
just joined
Posts: 7
Joined: Thu Mar 16, 2017 1:36 pm

Re: PPTP vpn to Windows server inside my network

Thu Mar 16, 2017 1:43 pm

facing same prblem.
 
User avatar
docmarius
Forum Guru
Forum Guru
Posts: 1219
Joined: Sat Nov 06, 2010 12:04 pm
Location: Timisoara, Romania
Contact:

Re: PPTP vpn to Windows server inside my network

Thu Mar 16, 2017 9:27 pm

Don't forget to forward ip protocol 47, too... 1723 is only the control port, the actual data transport happens over GRE.
Helpers may not work properly over NAT, so manual forwarding may be needed.
Torturing CCR1009-7G-1C-1S+, RB450G, RB750GL, RB951G-2HnD, RB960PGS, RB260GSP, OmniTIK 5HnD and NetMetal 922UAGS-5HPacD + R11e-5HnD in my home network.
 
Van9018
Long time Member
Long time Member
Posts: 515
Joined: Mon Jun 16, 2014 6:26 pm
Location: Canada - Abbotsford

Re: PPTP vpn to Windows server inside my network

Thu Mar 16, 2017 11:20 pm

To forward PPTP into a Windows PPTP Server:

- Forward TCP port 1723 (dst-nat chain) to server IP
- Forward GRE packets to server IP. GRE is an IP Protocol, alternative to TCP.
- Input Filters have no effect on packets forwarding through your router. Adding the input filter rule in the firewall is only required if your Mikrotik is the PPTP server.
 
janyao
just joined
Posts: 7
Joined: Thu Mar 16, 2017 1:36 pm

Re: PPTP vpn to Windows server inside my network

Fri Mar 24, 2017 9:24 am

I think the source is a solution of your problem.
https://support.microsoft.com/en-us/hel ... erver-2003
 
edwsin
just joined
Posts: 1
Joined: Fri Feb 23, 2018 11:51 am

Re: PPTP vpn to Windows server inside my network

Fri Feb 23, 2018 12:01 pm

Hi,
I have 1 question regardless it is about pptp server connection between mikrotik and windows server 2012 R2, so here is my question:

I have a mikrotik RB1100AHx2 and setup PPTP server to connect to our site using RB1100AHx2 (VPN) this is working like a charm.
And i also have windows server 2012 R2 (connect LAN Switch same with Mikrotik) installed and configured role Remote Access to use VPN server on my windows server 2012 R2, so i would like to set some employees connect to Windows Server VPN not to Mikrotik VPN using the same ip public address.
Is this possible to do it..?

Best Regards,
Edwsin

Who is online

Users browsing this forum: No registered users and 33 guests