Community discussions

MikroTik App
 
eghtedari2000
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 85
Joined: Tue Aug 11, 2009 10:11 am

can mikrotik in L7 filter work on VPN services ( PPTP, L2TP)

Wed Nov 24, 2010 7:15 pm

hi

can any body help me about that, i want to have L7 filter on vpn packets, L2TP and PPTP.

if any body can help, please give its file.

thanks
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: can mikrotik in L7 filter work on VPN services ( PPTP, L

Wed Nov 24, 2010 7:40 pm

Not on encrypted packets, no. If the router is terminating the connection, however, you can inspect the packets before encryption or after decryption. That happens when the traffic comes out of a tunnel interface or goes into a tunnel interface. Refer to the packet flow diagram to see what facilities are available.

http://wiki.mikrotik.com/wiki/Manual:Packet_Flow
 
eghtedari2000
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 85
Joined: Tue Aug 11, 2009 10:11 am

Re: can mikrotik in L7 filter work on VPN services ( PPTP, L

Thu Nov 25, 2010 12:36 am

hi

i mean that my router is pppoe server and i want to control my users bandwidth that take from vpn servers on internet, does it encrypted or not.

and if it is encrypted you said that it is impossible, so how can i control that

thanks
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: can mikrotik in L7 filter work on VPN services ( PPTP, L

Thu Nov 25, 2010 12:53 am

If encrypted packets are passing through your router you cannot look inside them. That's the whole point of VPNs and encryption.
 
eghtedari2000
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 85
Joined: Tue Aug 11, 2009 10:11 am

Re: can mikrotik in L7 filter work on VPN services ( PPTP, L

Thu Nov 25, 2010 7:08 am

hi

so you said that i cant find packets for although it uses standard vpns that uses statndard protocol, such as ipsec and,...

how can i solve my problem, is there another way?

thanks
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: can mikrotik in L7 filter work on VPN services ( PPTP, L

Thu Nov 25, 2010 7:24 am

The whole purpose of an encrypted VPN is to hide the data inside the packet from anyone that is looking. If there was a way to look inside the packets, do you think anyone would use that VPN method?
 
eghtedari2000
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 85
Joined: Tue Aug 11, 2009 10:11 am

Re: can mikrotik in L7 filter work on VPN services ( PPTP, L

Thu Nov 25, 2010 4:33 pm

hi

i dont want to look to content of encrypted data in packet, i need that router from kind of encryptuion or other way know that it is vpn packet to manage bandwidth for that.

thanks
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: can mikrotik in L7 filter work on VPN services ( PPTP, L

Thu Nov 25, 2010 5:53 pm

Oh. Then you don't need L7 at all. VPN packets use commonly known ports and protocols. Just Google them. The IPSec suite, for example, includes IP protocols 50 (ESP) and 51 (AH) as well as UDP/500 (ISAKMP) and UDP/4500 (NAT-T).
 
eghtedari2000
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 85
Joined: Tue Aug 11, 2009 10:11 am

Re: can mikrotik in L7 filter work on VPN services ( PPTP, L

Thu Nov 25, 2010 5:58 pm

hi

thanks alot for your attention

now i use quee tree for my QOS.

i wanted to have axact information about that.

can you say me how can i limit bandwidth on port and also i dont want to do this limit for all of my users

i want to do that for some of my ip address classes.

please say me about all of vpn ports and openvpn and in where i can limit that for some of my ip addresses

thanks
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: can mikrotik in L7 filter work on VPN services ( PPTP, L

Thu Nov 25, 2010 6:01 pm

Just use Google to find out the ports. That information is easily available for you there.

Here is a link showing QoS per customer and per port: http://mum.mikrotik.com/presentations/C ... _Megis.pdf. Just adjust it for your protocols.