https://wiki.mikrotik.com/wiki/Manual:I ... sec_tunnel
Mikrotik A - 10.91.22.56/24
Mikrotik B - 10.101.0.251/24
Traffic goes fine, both routers can see each other and different hosts in remote subnets. Basic routing/nat applied:
Code: Select all
0 chain=srcnat action=accept src-address=10.91.22.0/24
dst-address=10.101.0.0/24 log=no log-prefix=""
1 chain=srcnat action=masquerade log=no log-prefix=""
After this I fired up l2tp server on Mikrotik A and applied subnet 10.99.99.2-254 for l2tp clients.
I tried client connection from Ubuntu using NM and L2tp profile there. I added necessary login data and it worked like a charm with default options which is routing whole traffic thru vpn.
I don't want all traffic to go thru vpn, so I check "Use this connection only for resources on its network" and this is desired client scenario but in this case I can't reach any of the subnet's.
If I manually add routes and mikrotik as GW on client side all works again as expected I can reach both subnet's. I need help on following:
1. In case client uses to ignore all traffic going thru tunnel how can I add routes once connection is established except manually?
Can this part be somehow delivered once client connection is established or on mikrotik side using mangle rules for traffic coming from vpn pool 10.99.99.0.0?
2. I choose l2tp server since it's compatible with all major clients WIndows, Linux, OSX, Android maybe I just choose some other option for clients in my case.
Important is that the clients can reach both subnet's once connected using l2tp or any other protocol and avoid routing whole traffic and adding static routes on client.
I want mikrotik to route also vpn clients towards both subnets. Some examples for my case much appreciated.
3. What do I need to add, so hosts behind each subnet can communicate between each other? For now communication works from both Mikrotik's, they can reach both subnet's and hosts behind them but hosts different from Mikrotik can't communicate between each other. I tried adding static route and mikrotik as GW but no luck