Community discussions

MikroTik App
 
User avatar
LinuxLarry
just joined
Topic Author
Posts: 20
Joined: Fri Aug 10, 2018 9:31 pm
Location: Earth

Is RouterOS Blocking VPN? (Noob In need)

Tue Sep 25, 2018 2:07 am

Howdy,

The googles is filled with all sorts of router to router configurations and other stuff. I can not seem to find a solid answer to my problem. The scenario is as follows

Company vpn hosted on a windows 2012 server. L2TP with PSK (I know I know). My goal is to connect to their vpn server. I am using linux and nothing I do appears to work. The basics appear to be a protocol problem possibly. I broke down and grabbed a windows box to use. My logic is that since I've tried everything I could think of maybe its a router configuration problem. Only way for me to rule this out was to try on a native windows system.

It failed too. So I am thinking maybe some stuff I am missing is in the router. Do I need to set up anything in the ipsec area of the router if I am not actually using the router to connect to the client. I would like to just connect my Linux pc to my company hosted vpn server. Again I am not looking to connect my router as the client or connect directly to another router that is service.

Please any advice ?
 
mducharme
Trainer
Trainer
Posts: 1777
Joined: Tue Jul 19, 2016 6:45 pm
Location: Vancouver, BC, Canada

Re: Is RouterOS Blocking VPN? (Noob In need)

Tue Sep 25, 2018 2:13 am

Do I need to set up anything in the ipsec area of the router if I am not actually using the router to connect to the client. I would like to just connect my Linux pc to my company hosted vpn server. Again I am not looking to connect my router as the client or connect directly to another router that is service.
No. The router with its default configuration will allow computers behind it to connect up to L2TP/ipsec VPNs. I do this all the time.

Chances are that the VPN that you are trying to connect to is not configured properly for allowing L2TP/IPsec NAT traversal, which means that only a host that is directly receiving a public IP address would be able to connect to the VPN.
 
User avatar
LinuxLarry
just joined
Topic Author
Posts: 20
Joined: Fri Aug 10, 2018 9:31 pm
Location: Earth

Re: Is RouterOS Blocking VPN? (Noob In need)

Tue Sep 25, 2018 2:25 am

Do I need to set up anything in the ipsec area of the router if I am not actually using the router to connect to the client. I would like to just connect my Linux pc to my company hosted vpn server. Again I am not looking to connect my router as the client or connect directly to another router that is service.
No. The router with its default configuration will allow computers behind it to connect up to L2TP/ipsec VPNs. I do this all the time.

Chances are that the VPN that you are trying to connect to is not configured properly for allowing L2TP/IPsec NAT traversal, which means that only a host that is directly receiving a public IP address would be able to connect to the VPN.
Thank you for the response. I am not running a default configuration however, I do have the allow established and related configured in the filter section of the firewall. Might there be more required in order to get this working or at least eliminate the config/router from the problem?
 
mducharme
Trainer
Trainer
Posts: 1777
Joined: Tue Jul 19, 2016 6:45 pm
Location: Vancouver, BC, Canada

Re: Is RouterOS Blocking VPN? (Noob In need)

Tue Sep 25, 2018 2:28 am

Thank you for the response. I am not running a default configuration however, I do have the allow established and related configured in the filter section of the firewall. Might there be more required in order to get this working or at least eliminate the config/router from the problem?
No, not really. The only rule needed to allow you connect to L2TP is the same one that would allow you to browse the web, and I'm sure you would notice if you could not browse the web through your router. Try connecting your computer directly to a public IP, if it works, chances are that the corporate L2TP/IPsec VPN is not set up for NAT traversal.

Who is online

Users browsing this forum: Amazon [Bot], vshaev60 and 122 guests