Community discussions

MikroTik App
 
tanyo
just joined
Topic Author
Posts: 2
Joined: Wed Jun 06, 2018 11:30 am

Which mikrotik router for OpenVPN

Wed Jun 06, 2018 11:44 am

Hello ,

I'm looking for mikrotik router to replace my current Cisco VPN router. It should be able to provide (OpenVP) site-to-site for about 30 clients and about 5-6 mobile VPN client ( 100M/100M traffic).

Hadware acceleration would be in advance. Are CCR1009-7G or CCR1016-12G good enough ?

Thank you ,
Tanyo
 
sindy
Forum Guru
Forum Guru
Posts: 10206
Joined: Mon Dec 04, 2017 9:19 pm

Re: Which mikrotik router for OpenVPN

Wed Jun 06, 2018 1:06 pm

To date none of the Mikrotik routers supports hardware encryption for OpenVPN, those which do have CPUs with hardware encryption can currently only use it for IPsec.

In addition to that, RouterOS only supports TCP transport for OpenVPN, so the network between the clients and the server must have enough capacity and quality not to drop packets. As soon as packets get dropped and retransmissions become necessary, the connections over any VPN using TCP transport become very bad. So if you prefer Mikrotik, use IPsec (and benefit from the hardware acceleration by choosing a model like hAP ac² or hEX S); if you prefer OpenVPN, don't use Mikrotik.
 
wpeople
Member
Member
Posts: 380
Joined: Sat May 26, 2007 6:36 pm

Re: Which mikrotik router for OpenVPN

Wed Jun 06, 2018 3:29 pm

currently (in ROS 6) no HW acceleration.
if you want to push 100/100mbps via OpenVPN i recommend 1100AHx4 what has a quad core 1400MHz CPU (what also can be overclocked with 20% - no problem if you have proper cooling of rack).

more MHz is better than more cores in this, so 1100AHx4 would be better if you have few clients doing more speed.
CCR1009 (active cooling) may would be better with more clients, less speed per client.
 
R1CH
Forum Guru
Forum Guru
Posts: 1101
Joined: Sun Oct 01, 2006 11:44 pm

Re: Which mikrotik router for OpenVPN

Wed Jun 06, 2018 7:25 pm

I would strongly advise against OpenVPN on Mikrotik for the above reasons. Performance is very poor with TCP-in-TCP, see http://sites.inka.de/bigred/devel/tcp-tcp.html for explanations.
 
Van9018
Long time Member
Long time Member
Posts: 558
Joined: Mon Jun 16, 2014 6:26 pm
Location: Canada - Abbotsford

Re: Which mikrotik router for OpenVPN

Wed Jun 06, 2018 10:59 pm

Since 2010, Mikrotik is no longer developing their OpenVPN implementation. Expect the limitations to be permanent. Use IPSec, or GRE/IPSec if you want an interface to work with (I think Cisco supports GRE/IPSec?)
 
wpeople
Member
Member
Posts: 380
Joined: Sat May 26, 2007 6:36 pm

Re: Which mikrotik router for OpenVPN

Thu Jun 07, 2018 12:10 am

I would strongly advise against OpenVPN on Mikrotik for the above reasons. Performance is very poor with TCP-in-TCP, see http://sites.inka.de/bigred/devel/tcp-tcp.html for explanations.
I easily can pass ~120mbps TCP traffic, what would answer _this_ question.
 
User avatar
juliokato
Member Candidate
Member Candidate
Posts: 228
Joined: Mon Oct 26, 2015 4:27 pm
Location: Brazil

Re: Which mikrotik router for OpenVPN

Thu Jun 07, 2018 12:35 am

Don´t use Mikrotik for substitute the Cisco VPN.

Good luck if you want to use Mikrotik with IPSec Hardware Accelerate for VPN site-to-site.
Choose the best hardware and multiple for 4.
configure only the basic manuals, do not try to reinvent, nor try to use dynamic routing.
 
tanyo
just joined
Topic Author
Posts: 2
Joined: Wed Jun 06, 2018 11:30 am

Re: Which mikrotik router for OpenVPN

Thu Jun 14, 2018 4:24 pm

So, no way to substitute my current site-to-site Cisco EZVPN with Mikrotik VPN solution ?
 
sindy
Forum Guru
Forum Guru
Posts: 10206
Joined: Mon Dec 04, 2017 9:19 pm

Re: Which mikrotik router for OpenVPN

Thu Jun 14, 2018 5:17 pm

There is, but OpenVPN is not the best choice. IPsec with or without a GRE tunnel is the best setup in Mikrotik context.

Who is online

Users browsing this forum: akakua, bdivrik and 186 guests