Community discussions

MikroTik App
 
johnt107
just joined
Topic Author
Posts: 22
Joined: Sat Jun 20, 2020 3:28 pm

VPN Access to NAS problem

Sat Nov 06, 2021 10:42 am

I have set up a L2TP server on the Mikrotik so I can remote in and attach to my LAN. I have also set an outgoing VPN interface in the Mikrotik.

When I attach to the incoming VPN I can ping all devices on the LAN except for the NAS when the NAS traffic is being directed to an outgoing VPN. I have set the Mikrotik to ensure my local NAS uses the outgoing VPN interface for all comms. I've used Mangle and NAT rules to achieve this.

I have a problem though that when I attach to the LAN via the incoming L2TP VPN server (set up in the Mikrotik) I can't use the NAS. I can't ping it nor use any of the mobile apps to view and retrieve files. When I disable the Mangle rule directing the NAS to the outgoing VPN I can see the NAS.

What rules can I put in place to allow ping and certain ports on the NAS to be visible when I come in through the L2TP VPN?
 
spynappels
Member Candidate
Member Candidate
Posts: 106
Joined: Mon Oct 25, 2021 12:32 pm
Location: Northern Ireland
Contact:

Re: VPN Access to NAS problem

Sat Nov 06, 2021 11:01 am

It sounds like your srcnat for the NAS/VPN is messing with the routing table.

I'm afraid I do not understand your layout with regards to the NAS, are you redirecting all traffic out of the NAS to go out through a separate VPN? Or through the same VPN as you're coming in on?

Could you maybe provide a diagram that illustrates it a little clearer, and also show your Mikrotik config:
/export hide-sensitive file=my-config-file
 
johnt107
just joined
Topic Author
Posts: 22
Joined: Sat Jun 20, 2020 3:28 pm

Re: VPN Access to NAS problem

Sat Nov 06, 2021 12:01 pm

They are two separate VPNs. The outgoing one is a PPTP connection (security not important). The incoming one for me to connect to the network is L2TP/IPSEC.

Here is the config.
deleted
 
johnt107
just joined
Topic Author
Posts: 22
Joined: Sat Jun 20, 2020 3:28 pm

Re: VPN Access to NAS problem

Mon Nov 15, 2021 9:55 pm

Solution: Add exclusion for lan addresses in Mangle rule.

Why? Don't know. I thought a PC coming in through a VPN would be treated exactly like a PC physically on the LAN. There must be some differences.

Who is online

Users browsing this forum: lostb1t and 64 guests