Community discussions

MikroTik App
 
tenhi
just joined
Topic Author
Posts: 1
Joined: Mon Aug 22, 2022 11:10 pm

Client VPN

Mon Aug 22, 2022 11:13 pm

Hi Folks,

I am using RouterOS v 7 and just wanted to ask how to handle it better( routing
or mangling or what ) cause it's not fully transparent and clear for me. Here
maybe my bad, but I haven't got usefull in google and on old/new wiki of
Mikrotik. I tried to follow the instructions, but nothing works.

Here is what I have at the moment:

Mikrotik router with just an internet on ether1.

Ether2 is connected with Linux machine.
On a router it's 192.168.2.1/30
On machine it's 192.168.2.2/30
They could ping each other, no problem. Internet is working fine if I just do
simple masquerade via ether1. It's okay.

Now I also have OpenVPN connection from Mikrotik to another server in the
internet with config:

Mikrotik 192.168.3.1/30
VPS 192.168.3.2/30

---
30 here just to make it simple.

Could you please advice how it's better to configure the Linux machine using
ONLY vpn connection?

Mark Routing/Mark connection? Routing rules? What exactly to use and how make it
properly?

Thank in advance.
 
AidanAus
Member Candidate
Member Candidate
Posts: 177
Joined: Wed May 08, 2019 7:35 am
Location: Australia
Contact:

Re: Client VPN

Wed Sep 07, 2022 9:30 am

unless you are using a 3rd party vpn client (like open vpn for example) that allow you some additional or limited configuration access the vpn behaviour is not really going to be much different. the main differences is that on a client device the vpn can take over the 0.0.0.0 route and the client gets the VPN address that is known on the other side so it makes set up for the inexperienced a little easier.
The main benefits of installing the vpn on the Mikrotik instead is that you are 1 able to share this vpn connection with more than 1 client and 2 you are able to control what traffic you would like to go though the vpn tunnel a lot easier, for example for most connections you could set it to go out to the normal isp but for netflix you could have it go just through the vpn to allow you access to other shows etc.


Again I dont think there is a 'better' option over all but depending on what you want to achieve one would be better than the other, this segways me into: are you able to let us know what you would like to achive or what you would like the end behaviour to be? Also it might be useful to get an export from you at the same time just in case its needed :) make sure you remove all sensitive information like your public ip address, passwords etc before posting :)

Who is online

Users browsing this forum: No registered users and 54 guests