Community discussions

MikroTik App
 
corp9592
just joined
Topic Author
Posts: 12
Joined: Sun May 05, 2019 10:14 pm

L2TP Client apparently incompatible with VPN server?

Wed Oct 16, 2019 12:12 am

Hello,
I have an OpenVPN server which is working wonderful. I can connect from the outside to my home network getting a 10.0.0.0/24 IP address and accessing the internet via my home IP.
Additionally I have an L2TP Client connecting to an Ivacy.com VPN provider, which is also working ok, because I can see my public IP switching from my ISP to the VPN provider.

The setup is simple, I have a wireless connection as a WAN interface. It has a static route entry with distance 2.
When the L2TP client connects, it creates a dynamic route entry with distance 1, so all the traffic is routed through it.

But, here comes the issue:
When I have the L2TP client active, I can no longer connect to my home network using the OpenVPN server. It may sound silly but I am facing this issue.
*I can even see a packet incoming to port 1194 in the firewall table, but nothing happens.* Is like the connection never gets to the OpenVPN server.
I tried setting up an L2TP server and it also fails (on the other hand, without the L2TP Client, it works OK).

I ask you. Could you please give me a hint to something to look for?
Maybe my firewall NAS is missing something?
Maybe the route table is not OK?

If you need some more information I will gladly give it to you.

Many thanks.
 
Van9018
Long time Member
Long time Member
Posts: 558
Joined: Mon Jun 16, 2014 6:26 pm
Location: Canada - Abbotsford

Re: L2TP Client apparently incompatible with VPN server?

Wed Oct 23, 2019 9:57 am

I'm not sure I understand your scenario...

Your not at home with your laptop. You want your internet traffic to first go home via OpenVPN, and then out the LT2P client through ivacy.com. Is that right?

I would think it's a route problem. When the L2TP connection is active and has a lower route distance than that of the OpenVPN connection, the OpenVPN packets will be first routed through the L2TP connection and to your laptop. The problem is your OpenVPN connection is with your home IP but the replies are from Ivacy.com's IP. Your laptop will drop them. Or rather the router/NAT you're behind will drop them.

You can use Tools > Torch inside Winbox to see where your outbound UDP 1194 packets are going. They need to leave your WAN interface and go back to your laptop and NOT through the L2TP connection.

You'd need to use a mangle rule I think to give outbound UDP packets on port 1194 a routing-mark. Then create another route that applies to packets with that routing-mark and route the packets out the WAN interface instead of out the L2TP interface.
 
corp9592
just joined
Topic Author
Posts: 12
Joined: Sun May 05, 2019 10:14 pm

Re: L2TP Client apparently incompatible with VPN server?

Wed Oct 23, 2019 11:23 am

Thank you for your response.
I got some help form Reddit as well, and my final decision was to enroll with another VPN provider that had a Mikrotik guide to use IKEv2. Now I got all the network addressed.
It was indeed a routing problem that, before switching VPN provider I got resolved by some firewall/mangle rules, just as you mentioned.
Regards.

Who is online

Users browsing this forum: GoogleOther [Bot] and 178 guests