Community discussions

MikroTik App
 
JSzmanda
just joined
Topic Author
Posts: 3
Joined: Sat May 06, 2017 1:21 pm

L2TP server

Sat May 06, 2017 2:04 pm

Hello,

I'm looking for best tutorial for l2tp with ipsec.
I've configured but when I connect to vpn I can't get Internet connect - it's not working.

How can I fix that?

I'm just starting MT road :)

Thank you
 
User avatar
Steveocee
Forum Guru
Forum Guru
Posts: 1120
Joined: Tue Jul 21, 2015 10:09 pm
Location: UK
Contact:

Re: L2TP server

Sat May 06, 2017 5:03 pm

Do you have a NAT masquerade rule for your VPN traffic?
 
JSzmanda
just joined
Topic Author
Posts: 3
Joined: Sat May 06, 2017 1:21 pm

Re: L2TP server

Sat May 06, 2017 5:31 pm

Do you have a NAT masquerade rule for your VPN traffic?
I don;t know how to do this in this moment...

http://imgur.com/a/BjV0h
 
zoltarex
just joined
Posts: 3
Joined: Fri Oct 11, 2013 5:42 pm
Location: Cracow, Poland

Re: L2TP server

Sat May 06, 2017 6:47 pm

You must update your NAT rules.

For example, try this:
/ip firewall nat add chain=srcnat action=masquerade out-interface=Public
Wiki: https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/NAT
 
JSzmanda
just joined
Topic Author
Posts: 3
Joined: Sat May 06, 2017 1:21 pm

Re: L2TP server

Sat May 06, 2017 10:31 pm

You must update your NAT rules.

For example, try this:
/ip firewall nat add chain=srcnat action=masquerade out-interface=Public
Wiki: https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/NAT
You are the one! It's working like a charm
Many thanks.

Another question - how can I allow or block browsing web with public IP VPN?
Eg. user1 can browse with public IP, user2 can not.
 
Revelation
Member
Member
Posts: 336
Joined: Fri Dec 25, 2015 5:59 am

Re: L2TP server

Sat May 06, 2017 10:44 pm

You must update your NAT rules.

For example, try this:
/ip firewall nat add chain=srcnat action=masquerade out-interface=Public
Wiki: https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/NAT
You are the one! It's working like a charm
Many thanks.

Another question - how can I allow or block browsing web with public IP VPN?
Eg. user1 can browse with public IP, user2 can not.
What I did is instead of assigning a "pool" to a user for my VPN service was to specify a single IP address. That way when they connect via VPN they get the same "Remote IP Address" every time and I can restrict them from accessing NAT or other devices as I choose. Also, by default, I have no NAT enabled for VPN users and selectively add them as needed. In other words I have several NAT statements that have a single IP address permitted.

Who is online

Users browsing this forum: No registered users and 68 guests