While i'm able to ping directly between the Linux<->Mikrotik, i get timeouts when i ping smth behind those boxes.
Linux OVPN Server Config:
Code: Select all
mode server
proto tcp
local _IPADDR_
dev-type tun
dev tun1
topology subnet
server 192.168.224.0 255.255.252.0
txqueuelen 250
keepalive 300 900
persist-tun
persist-key
cipher AES-128-CBC
ncp-ciphers AES-128-GCM
duplicate-cn
verb 3
log-append /var/log/openvpn.log
log logs/log1.log
status logs/status1.log 30
client-config-dir ccd
client-connect /etc/openvpn/client-connect.sh
script-security 2
ca ca.crt
cert cert.crt
key cert.key
dh dh2048.pem
Code: Select all
/interface ovpn-client
add certificate=client1.crt_0 cipher=aes128 connect-to=_IPADDR_ mac-address=_MACADDR_ name=name password=none user=none
Code: Select all
/interface> ovpn-client print
Flags: X - disabled, R - running
0 R name="name" mac-address=_MACADDR_ max-mtu=1500 connect-to=_IPADDR_ port=1194 mode=ip user="none" password="none" profile=default certificate=client1.crt_0 auth=sha1 cipher=aes128 add-default-route=no
Code: Select all
/interface> /ping 192.168.224.1
SEQ HOST SIZE TTL TIME STATUS
0 192.168.224.1 56 64 170ms
1 192.168.224.1 56 64 170ms
2 192.168.224.1 56 64 170ms
3 192.168.224.1 56 64 170ms
4 192.168.224.1 56 64 171ms
Code: Select all
root@fr:/etc/openvpn# ping 192.168.224.3
PING 192.168.224.3 (192.168.224.3) 56(84) bytes of data.
64 bytes from 192.168.224.3: icmp_seq=1 ttl=64 time=170 ms
64 bytes from 192.168.224.3: icmp_seq=2 ttl=64 time=170 ms
64 bytes from 192.168.224.3: icmp_seq=3 ttl=64 time=170 ms
i define a loopback on mikrotik:
Code: Select all
/interface> /interface print where name=loopback
Flags: D - dynamic, X - disabled, R - running, S - slave
# NAME TYPE ACTUAL-MTU L2MTU MAX-L2MTU MAC-ADDRESS
0 R loopback bridge 1500 65535 00:00:00:00:00:00
Code: Select all
/interface> /ip address print where interface=loopback
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK INTERFACE
0 172.30.0.1/30 172.30.0.0 loopback
Code: Select all
root@fr:~# route add -net 172.30.0.0/30 192.168.224.2
root@fr:~# netstat -rn
Kernel IP routing table
Destination Gateway Genmask Flags MSS Window irtt Iface
0.0.0.0 50.116.3.1 0.0.0.0 UG 0 0 0 eth0
_IPADDR_NET_ 0.0.0.0 255.255.255.0 U 0 0 0 eth0
172.30.0.0 192.168.224.2 255.255.255.252 UG 0 0 0 tun1
192.168.224.0 0.0.0.0 255.255.252.0 U 0 0 0 tun1
Code: Select all
root@fr:~# ping 172.30.0.1
PING 172.30.0.1 (172.30.0.1) 56(84) bytes of data.
^C
If i create loopback on Linux box and add static route to Mikrotik - i can ping it from Mikrotik.
Seems to me like some basic detail I'm missing here. Can anyone please advise me the right path here?
Appreciate beforehand your support!