Community discussions

MikroTik App
 
matthei
just joined
Topic Author
Posts: 12
Joined: Sun May 23, 2021 6:04 pm

L2TP server to use same pool as LAN

Thu May 27, 2021 12:40 am

Hey all, as I was setting up a L2TP server, initially I've configured to use the same ip pool as the LAN. That didn't work well (couldn't connect to machines in the LAN), and on some site with instructions i've read that it has to be on a different subnet - no problem, i've just added another Pool, configured L2TP server to use that pool, works ok.

However, is it possible to have L2TP clients to be assigned IPs from the same pool as LAN computers. Perhaps even using a static IP for a given username?

(L2TP is just temporary so I saved time making certificates. I intend to set up OVPN in the future.)
 
tdw
Forum Guru
Forum Guru
Posts: 1845
Joined: Sat May 05, 2018 11:55 am

Re: L2TP server to use same pool as LAN

Thu May 27, 2021 1:35 am

When you share addresses between a local subnet and remote devices connected by an IP VPN (so L2TP, OVPN tun, SSTP or PPTP) the local devices will use ARP and this is unsuccessful for the remote devices. Use proxy-arp on the interface, or parent bridge if used, for the local subnet.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19322
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: L2TP server to use same pool as LAN

Thu May 27, 2021 2:35 am

When I created a vpn tunnel using IKEv2, I had to create a faux subnet. So it was not a full dhcp subnet but just a pool of a few IPs if i recall (was a while ago).
But just to state I couldnt directly join a subnet but I think If I had wanted to go from VPN subnet to LAN subnet I would have to ensure it was allowed in the forward chain.
I simply used it to gain access to the router for admin purposes through the MIkrotik smart phone APP.
 
matthei
just joined
Topic Author
Posts: 12
Joined: Sun May 23, 2021 6:04 pm

Re: L2TP server to use same pool as LAN

Thu May 27, 2021 9:28 pm

Thanks, arp-proxy worked. I configured my bridge_vlan5 to have arp mode as "arp-proxy", then changed my PPP Profile (Pool, local ip, gateway) to the same IPs used by the LAN, and it seems to work all ok.
 
joegoldman
Forum Veteran
Forum Veteran
Posts: 767
Joined: Mon May 27, 2013 2:05 am

Re: L2TP server to use same pool as LAN

Fri May 28, 2021 2:04 am

What people tend to forget - VPN interfaces are L3 interfaces not L2 - dialing in is not the same as plugging into the local network, the L2 protocols are largely lost.

Things like proxy-arp help, so the router is doing the work for you, but beyond using tech like vpls or eoip, you have to consider VPN's another 'network' and adjust accordingly.
 
Cablenut9
Long time Member
Long time Member
Posts: 542
Joined: Fri Jan 08, 2021 5:30 am

Re: L2TP server to use same pool as LAN

Fri May 28, 2021 2:55 am

Actually, you could use L2TP BCP to get a DHCP address, but only things like routers support it.

Who is online

Users browsing this forum: derolf, Google [Bot] and 39 guests