Community discussions

MikroTik App

Search found 11 matches

by mikroguf
Fri Apr 08, 2011 7:47 am
Forum: General
Topic: dst-nat on bridge with connection tracking
Replies: 0
Views: 887

dst-nat on bridge with connection tracking

Hi all, I have a simple bridge with 3 interfaces and I'd like to make some bridge dst-nat decisions (ie re-write the destination MAC) based on the attributes of the IP connection (not packet). However, bridges do not track IP connections, rather this function is performed by the IP firewall. I can a...
by mikroguf
Tue Mar 22, 2011 3:17 am
Forum: General
Topic: L2TP/IPsec confiruration disables all connectivity
Replies: 11
Views: 4996

Re: L2TP/IPsec confiruration disables all connectivity

Most client software will attempt to switch to NAT-T if it detects NAT in the path. So that means if you are using NAT, you need to configure your IPSec peer to use NAT-T. Be aware though that not all clients are currently working with NAT-T. Windows XP, for instance, will not successfully establish...
by mikroguf
Mon Mar 21, 2011 1:27 am
Forum: General
Topic: Problem with MLPPP over PPPoE
Replies: 3
Views: 1417

Re: Problem with MLPPP over PPPoE

Hi all,

Is there nobody out there who can confirm a working MPPP setup over two links using PPPoE with MT as the client?

Thanks!
by mikroguf
Mon Mar 21, 2011 12:13 am
Forum: General
Topic: IPSec/L2TP between Win Mobile & MikroTik: Is it possible?
Replies: 8
Views: 7950

Re: IPSec/L2TP between Win Mobile & MikroTik: Is it possible

Do you have any specifics for the Linux patch? I'd love to research a bit more into exactly how Linux resolved this...
by mikroguf
Fri Mar 18, 2011 1:05 am
Forum: General
Topic: Anyone have success with IPSEC and NAT-T on 5.0r8
Replies: 1
Views: 1574

Re: Anyone have success with IPSEC and NAT-T on 5.0r8

We have NAT-T working fine for L2TP/IPSec and generate-policy=yes with MAC OS from RC2 upwards. XP and Win7/Vista are another matter.

If you can be more specific about your config and error messages, maybe I can help.
by mikroguf
Fri Mar 18, 2011 12:46 am
Forum: General
Topic: IPSec/L2TP between Win Mobile & MikroTik: Is it possible?
Replies: 8
Views: 7950

Re: IPSec/L2TP between Win Mobile & MikroTik: Is it possible

Yes I concur that the issue is with the client sending FQDN instead of IP address as part of the IPSec setup. We have seen this in XP when it is behind NAT, though curiously XP does send its IP address as long as it does not detect NAT. I have asked MT to provide a fix for this on their side, as the...
by mikroguf
Fri Mar 18, 2011 12:31 am
Forum: General
Topic: L2TP/IPsec confiruration disables all connectivity
Replies: 11
Views: 4996

Re: L2TP/IPsec confiruration disables all connectivity

If you are attempting to allow an L2TP/IPSec Client on any address to create a tunnel to your server, which is addressable on 192.168.1.80, then you have got yourself in a muddle. I recommend that you re-read the material, but also note that the link to which you refers talks about setting up a tunn...
by mikroguf
Fri Mar 11, 2011 8:39 am
Forum: General
Topic: Problem with MLPPP over PPPoE
Replies: 3
Views: 1417

Re: Problem with MLPPP over PPPoE

Hi,
A MLPPP setup just like this is on my to-do list. Cander1's post has made me nervous. Has any one got MLPPP going on multilinks ok? With which LAC / LNS? I was going to use Cisco.
Thanks!
by mikroguf
Sun Mar 06, 2011 11:53 pm
Forum: General
Topic: NAT-T & IPSec Issues still exist
Replies: 25
Views: 16078

Re: NAT-T & IPSec Issues still exist

Hi Mikrotik, I see RC11 is out and more work has been done on IPSec. However, no news about these final issues with ids for Vista/7 and XP behind NAT-T. I'd be really grateful for just a clue as to whether anyone will look at it, so we can decide whether to stop waiting and go looking for another so...
by mikroguf
Thu Feb 03, 2011 1:40 am
Forum: General
Topic: Feature request for 5.0 final.
Replies: 40
Views: 11007

Re: Feature request for 5.0 final.

Unfortunately, 5.0rc2 didn't completely solve all IPSec-behind-NAT issues. See http://forum.mikrotik.com/viewtopic.php?f=1&t=47207
by mikroguf
Mon Dec 06, 2010 5:58 am
Forum: General
Topic: NAT-T & IPSec Issues still exist
Replies: 25
Views: 16078

NAT-T & IPSec Issues still exist

Hi all, First post - but I've been lurking for a while! We have been doing extensive testing with remote users establishing L2TP/IPSec tunnels to an RB450G, now running V5.0 RC3. We're using the built in L2TP/IPSec capability of a few different clients, namely WindowsXP, Windows Vista/7 and Mac. We ...