Community discussions

MikroTik App
 
mertinator
just joined
Topic Author
Posts: 7
Joined: Wed Sep 23, 2020 4:25 pm
Location: Germany

DNS NAT Problem with VPN between 2 mikrotik router subnets and pihole  [SOLVED]

Fri Dec 03, 2021 1:57 am

Hi together,

i have read this forum for weeks and i dont find the right solution for my problem so i decided to post my configuration hoping that someone has a solution in mind.
I have 2 locations both with mikrotik equipment for the network.
one locations has a static ip address with a HEX 192.168.0.1 and holds my NAS and all the other server stuff including a pihole for DNS all in one single subnet 192.168.0.0/24.
The other location has a dynamic ip address with a cable modem in bridge mode and a HAP AC2 192.168.80.1 behind it also with one single subnet 192.168.80.0/24.

I have a working l2tp connection with ipsec between both subnets and i was also able to define routes between both subnets.
I was also able to setup a pihole on the HEX subnet 192.168.0.0 as a DNS Server 192.168.0.2.
That pihole is working fine and showing me every single client on that subnet 192.168.0.0.
My problem is, that every single client from the "remote" subnet 192.168.80.0 that comes over vpn is shown as the HEX IP 192.168.0.1
In my opinion its something about a NAT Problem or after i read a lot in this forum something that is called Hairpin NAT.
My target is that the pihole dns server sees the incoming request from the remote subnet clients from 192.168.80.0 as single clients.
But without Help i dont know what exactly i have to do to get it Working...
Hope that this painting of my Networks helps. I inserted the routes, firewall and nat rules.
network.jpg
You do not have the required permissions to view the files attached to this post.
 
mertinator
just joined
Topic Author
Posts: 7
Joined: Wed Sep 23, 2020 4:25 pm
Location: Germany

Re: DNS NAT Problem with VPN between 2 mikrotik router subnets and pihole

Thu Dec 09, 2021 2:31 am

when i get it right i need another srcnat-masq nate rule on one side but i dont get it to work...pls help
 
Sob
Forum Guru
Forum Guru
Posts: 9119
Joined: Mon Apr 20, 2009 9:11 pm

Re: DNS NAT Problem with VPN between 2 mikrotik router subnets and pihole

Thu Dec 09, 2021 2:45 am

It's usually better to post configuration exports in text form, because screenshots don't show everything.

But if all 192.168.80.x clients show as 192.168.0.2 in HEX's LAN, it must be work of the only srcnat rule you have on HEX (#2). From screenshot it looks like there is no condition and it affects any connection through router, in any direction. But you really need it only for connections to internet, so the solution should be to add out-interface-list=WAN to it.
 
Sob
Forum Guru
Forum Guru
Posts: 9119
Joined: Mon Apr 20, 2009 9:11 pm

Re: DNS NAT Problem with VPN between 2 mikrotik router subnets and pihole

Thu Dec 09, 2021 2:50 am

Also your firewall looks pretty useless, it seems that you allow almost everything.
 
mertinator
just joined
Topic Author
Posts: 7
Joined: Wed Sep 23, 2020 4:25 pm
Location: Germany

Re: DNS NAT Problem with VPN between 2 mikrotik router subnets and pihole

Fri Dec 10, 2021 12:13 am

Thx a lot, that was the point. with the srcnat rule only on wan everything is working like a charm. and thx for the hint regarding the firewall, y that comes next, i disabled nearly everything to get the nat working. THX

Who is online

Users browsing this forum: neskiask and 100 guests