Community discussions

MikroTik App
 
cicserver
Member
Member
Topic Author
Posts: 303
Joined: Sun Jul 24, 2011 12:04 pm

Site 2 Site VPN with same Subnet at Both Ends

Wed Nov 05, 2014 8:59 am

Hello Everyone,

I am trying to configure a Site to Site branch connectivity using Mikrotik RB at both end. But the problem is that both sites have same subnet running at each other. e.g: SITE A users have 192.168.10.0/24 and SITE B also have same series. I cannot modify the IP addresses series at both sides.

How to define routes while having same subnet at both end?
 
noib
Member Candidate
Member Candidate
Posts: 291
Joined: Fri Jan 25, 2013 6:04 pm
Location: France
Contact:

Re: Site 2 Site VPN with same Subnet at Both Ends

Wed Nov 05, 2014 12:52 pm

If you really want the same subnet, create a L2TP or PPTP connection, put a EOIP tunnel on it and bridge all (LAN bridged with EOIP on both sides). But i'm not sure it's a clean solution, your link will be polluted with broadcast traffic.
 
jarda
Forum Guru
Forum Guru
Posts: 7756
Joined: Mon Oct 22, 2012 4:46 pm

Re: Site 2 Site VPN with same Subnet at Both Ends

Wed Nov 05, 2014 6:41 pm

... and what to do with address collisions and DHCP collisions? Bridging is not the good way in this case. If the computers from both networks should be able to talk together you need to renumber one network.
 
andriys
Forum Guru
Forum Guru
Posts: 1527
Joined: Thu Nov 24, 2011 1:59 pm
Location: Kharkiv, Ukraine

Re: Site 2 Site VPN with same Subnet at Both Ends

Wed Nov 05, 2014 6:49 pm

If you need to provide access from one network to just a limited number of services in another network (which is often the case) then introduce some new network just for that case, then map (destination NAT) some addresses from this new network to the real IPs of your services.
 
jarda
Forum Guru
Forum Guru
Posts: 7756
Joined: Mon Oct 22, 2012 4:46 pm

Re: Site 2 Site VPN with same Subnet at Both Ends

Wed Nov 05, 2014 9:40 pm

Both sides nat with masquerade is really very limiting. You should describe what are you expecting from this connection.
 
SystemErrorMessage
Member
Member
Posts: 383
Joined: Sat Dec 22, 2012 9:04 pm

Re: Site 2 Site VPN with same Subnet at Both Ends

Wed Nov 05, 2014 9:54 pm

It might be simpler to configure dhcp address pool for half of 254 addresses and other site for the other half.

Create a VPN connection between the 2 mikrotiks. No need to put any sort of DHCP between them or IP but add the connection to the bridge with the switch/ports. Make sure both mikrotiks have different IP addresses. You can add the same IP address to multiple places in routerOS within the same machine. So the VPN interface on the router, the bridge and ports can all have the same IP assigned to them.

Who is online

Users browsing this forum: lubara and 155 guests