I have a Hap Mini configured as a simple switch (so eth1 connected to ISP router with eth2 and eth3 connected to other devices) and wireless AP with routing and DHCP handled by ISP router. I've also set up a L2TP VPN Client which connects successfully. As a starting point, i'm now trying to get all traffic that goes through the Hap Mini (i.e. eth2, eth3 and wireless) to go through the VPN tunnel. I tried to adapt the tutorial here (https://www.youtube.com/watch?v=gXBXTWy62X8) for the case of not using a connection mark or routing mark and only a single VPN tunnel as opposed to a list as i assumed that since i want to send all traffic through the VPN, connection and routing mark aren't needed but the traffic doesn't seem to go over the tunnel. Below is the configuration without a connection mark and routing mark:
Code: Select all
# aug/24/2021 00:00:16 by RouterOS 6.42.7
# software id = BKEZ-U2KK
#
# model = RB931-2nD
# serial number = ZZZZZZZZZZ
/interface bridge
add fast-forward=no name=bridge1
/interface l2tp-client
add connect-to=XXX.XXX.XXX.XXX disabled=no name=l2tp-out1 password=XXXXXX user=XXXXXXX
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
add authentication-types=wpa-psk,wpa2-psk eap-methods="" management-protection=allowed mode=dynamic-keys name=profile1 \
supplicant-identity="" wpa-pre-shared-key=XXXXXXXXXXX wpa2-pre-shared-key=XXXXXXXXXXXXX
/interface wireless
set [ find default-name=wlan1 ] disabled=no frequency=2447 mode=ap-bridge security-profile=profile1 ssid=MikroTikvpn
/interface bridge port
add bridge=bridge1 interface=ether1
add bridge=bridge1 interface=ether2
add bridge=bridge1 interface=ether3
add bridge=bridge1 interface=wlan1
/ip dhcp-client
add dhcp-options=hostname,clientid disabled=no interface=bridge1
/ip firewall nat
add action=masquerade chain=srcnat out-interface=l2tp-out1
/ip route
add distance=1 gateway=l2tp-out1
/system routerboard settings
set silent-boot=no
When that didn't work i also tried with what seemed to be default connection and routing marks but again no luck! Below is the configuration with connection/routing mark:
Code: Select all
# aug/23/2021 23:57:17 by RouterOS 6.42.7
# software id = BKEZ-U2KK
#
# model = RB931-2nD
# serial number = ZZZZZZZZZZ
/interface bridge
add fast-forward=no name=bridge1
/interface l2tp-client
add connect-to=XXX.XXX.XXX.XXX disabled=no name=l2tp-out1 password=XXXXXX user=XXXXXXX
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
add authentication-types=wpa-psk,wpa2-psk eap-methods="" management-protection=allowed mode=dynamic-keys name=profile1 \
supplicant-identity="" wpa-pre-shared-key=XXXXXXXXXXX wpa2-pre-shared-key=XXXXXXXXXXXXX
/interface wireless
set [ find default-name=wlan1 ] disabled=no frequency=2447 mode=ap-bridge security-profile=profile1 ssid=MikroTikvpn
/interface bridge port
add bridge=bridge1 interface=ether1
add bridge=bridge1 interface=ether2
add bridge=bridge1 interface=ether3
add bridge=bridge1 interface=wlan1
/ip dhcp-client
add dhcp-options=hostname,clientid disabled=no interface=bridge1
/ip firewall nat
add action=masquerade chain=srcnat connection-mark=no-mark out-interface=l2tp-out1 routing-mark=main
/ip route
add distance=1 gateway=l2tp-out1
/system routerboard settings
set silent-boot=no
Can anyone please help with what the issue might be? Is it the firewall NAT and routes? or maybe something else?
Thanks!