Community discussions

MikroTik App
 
Zapnologica
Long time Member
Long time Member
Topic Author
Posts: 594
Joined: Fri Sep 25, 2009 8:15 pm
Location: South frica

VPN ?

Tue Jan 18, 2011 8:46 pm

Good day,

I am not entirely sure what i want to do is called so thats why i am askign here, i have googled and vpn, ppptp pppoe and all sorts of different protocols pop up.


I have a Mikrotik Router with a fast internet ADSL internet connection at my offices.

Now what i want to do is get my self a LOCAL only adsl account for my house and then make my mikrotik router at home connect to the router at work through the internet and then it must be as if i was sitting at work, and when i go on the internet it must go through the works adsl account?


Can i do this?
What is it called?
What do i need?

Thanks
 
Iron
just joined
Posts: 5
Joined: Wed Jan 19, 2011 11:24 am

Re: VPN ?

Thu Jan 20, 2011 11:19 am

Hi! Yes you can do it. :)

You can use pptp for your vpn needs.

At the office on mikrotik enable pptp server and create a user.
At home you can use your windows or linux machine as pptp clinet that will connect's to the office pptp server.
here is exmaple http://wiki.mikrotik.com/wiki/Manual:In ... n_Examples
 
Zapnologica
Long time Member
Long time Member
Topic Author
Posts: 594
Joined: Fri Sep 25, 2009 8:15 pm
Location: South frica

Re: VPN ?

Fri Jan 21, 2011 8:28 pm

I followed that setup and i used my windows 7 laptop to try connect and i keep getting error 800.
You do not have the required permissions to view the files attached to this post.
 
Feklar
Forum Guru
Forum Guru
Posts: 1724
Joined: Tue Dec 01, 2009 11:46 pm

Re: VPN ?

Fri Jan 21, 2011 9:29 pm

MikroTiks do not like IPSec/L2TP when you are behind NAT. If you were on a public IP for your Win7 machine, it would probably work. They do not handle the NAT traversal properly I believe, but there have been some change logs in 5.0rc about that, so maybe it has been fixed there.

If you want your MikroTik router at home to connect to your work router over a VPN instead of your Win7 machine then that is possible. You will basically need to choose a VPN protocol that both your office router and the MikroTik supports, and then follow their documentation and the MikroTik one for setting up the appropriate tunnel.
 
Zapnologica
Long time Member
Long time Member
Topic Author
Posts: 594
Joined: Fri Sep 25, 2009 8:15 pm
Location: South frica

Re: VPN ?

Fri Jan 21, 2011 9:45 pm

i used pptp , i think windows just tried all of them. Cause i saw pptp popup,

So u say i must try from router to router.

They both mikrotik routers, so it should be fine.
 
Feklar
Forum Guru
Forum Guru
Posts: 1724
Joined: Tue Dec 01, 2009 11:46 pm

Re: VPN ?

Fri Jan 21, 2011 10:01 pm

That's what your original post was asking for. It's possible to do it from Win7 if you just want to be attached to the VPN when you choose and to have it off and use your local connection when you don't. Having it router to router is a slightly more permanent setup.

Without knowing your local settings on Win7 and what settings you chose for the PPTP tunnel at the other end I can't be much more help.
 
Zapnologica
Long time Member
Long time Member
Topic Author
Posts: 594
Joined: Fri Sep 25, 2009 8:15 pm
Location: South frica

Re: VPN ?

Sat Jan 22, 2011 11:05 am

Howist,

Ok the router to router pptp link worked.

I am just having trouble with the routes.

On my router at home. I have a route with distance=1 that allows for the internet to work? (the pptp goes through here)

Now how do i route my computers traffic through the pptp route? cause i cant have two route with distance=1 ?

It chooses one, So either it choses the pptp and then the internet link dies (and intern the pptp link) or it just uses the internet.

How do i sort this one out?
 
Feklar
Forum Guru
Forum Guru
Posts: 1724
Joined: Tue Dec 01, 2009 11:46 pm

Re: VPN ?

Mon Jan 24, 2011 5:47 pm

You're going to have to answer what your specific goals are in this case.

1.) Do you just want access to the office subnets at your home, and vice versa?
2.) Do you only want specific computers to have to send all traffic out of the PPTP link?

For number 1, you need to set up more specific routes for the remote subnets so the router knows to send that traffic out of the right link. The best way to do it is define a more specific route with the dst-address set to the remote subnets, and the gateway as the PPTP link. If you want the office to have access to your local subnet as well, then you need to set up a similar route on their end as well.

For number 2, you use the firewall mangle to mark connections coming from specific IP addresses, and then mark for routing based off of the connection mark. Then use that routing mark in a route to send that traffic over the PPTP tunnel. Like number 1, if you want the office to have access to your local subnet, then they will need a similar route back over the PPTP link as well.

Who is online

Users browsing this forum: dioeyandika, Google [Bot], GoogleOther [Bot], yonutm and 42 guests