Community discussions

MikroTik App
 
emadtaha2010
just joined
Topic Author
Posts: 1
Joined: Sat Sep 19, 2015 12:57 pm

VPN Site to site

Sat Sep 19, 2015 1:10 pm

Please i have 2 routerboad 450 i need to make VPN site to site between each other

Please help
 
Van9018
Long time Member
Long time Member
Posts: 558
Joined: Mon Jun 16, 2014 6:26 pm
Location: Canada - Abbotsford

Re: VPN Site to site

Tue Sep 22, 2015 3:19 am

IPSec is a good place to start
http://wiki.mikrotik.com/wiki/Manual:IP/IPsec
That's a lengthy read, but IPSec is probably the best bet.

Some ISPs that issue modems with a router built in may disallow IPSec.
 
zizobaddy
Member Candidate
Member Candidate
Posts: 115
Joined: Mon Sep 13, 2010 10:13 am
Location: Osogbo
Contact:

Re: VPN Site to site

Tue Sep 22, 2015 3:31 am

you can use pptp os l2tp with IPSEC

Set IP on the VPN sever router E.g local=192.168.1.1 remote=192.168.1.2

it will work

PPTPconnction without IPSEC too will work just that less secured
 
descartes
just joined
Posts: 21
Joined: Sun Sep 20, 2015 3:04 pm

Re: VPN Site to site

Tue Sep 22, 2015 5:27 pm

 
Van9018
Long time Member
Long time Member
Posts: 558
Joined: Mon Jun 16, 2014 6:26 pm
Location: Canada - Abbotsford

Re: VPN Site to site

Wed Sep 23, 2015 2:35 am

Stick with plain IPSec in tunnel mode for site-to-site, supposed to be better performing. I use pre-shared keys instead of certificates because it's quicker to setup.
 
andriys
Forum Guru
Forum Guru
Posts: 1545
Joined: Thu Nov 24, 2011 1:59 pm
Location: Kharkiv, Ukraine

Re: VPN Site to site

Wed Sep 23, 2015 9:34 am

+1 - plain old IPsec in tunnel mode is the best for S2S- flexible, secure and performing. The only "disadvantage" is it requires some learning. And pre-shared key auth method should be just fine for S2S.
 
User avatar
cdiedrich
Forum Veteran
Forum Veteran
Posts: 997
Joined: Thu Feb 13, 2014 2:03 pm
Location: Basel, Switzerland // Bremen, Germany
Contact:

Re: VPN Site to site

Wed Sep 23, 2015 5:01 pm

I second the IPsec recommendations.
But: which bandwidth do you expect to be encrypted? If it's just some few MBit < 5, the 450 will for sure be able to handle this. If you're talking about more, better consider either different hardware (850, 1100, CCR series) or a non-IPsec approach.

-Chris
 
andriys
Forum Guru
Forum Guru
Posts: 1545
Joined: Thu Nov 24, 2011 1:59 pm
Location: Kharkiv, Ukraine

Re: VPN Site to site

Thu Sep 24, 2015 1:29 pm

consider either different hardware (850, 1100, CCR series) or a non-IPsec approach.
I'd argue the non-IPsec approach is worth considering, unless you don't care about encryption at all.
 
jarda
Forum Guru
Forum Guru
Posts: 7756
Joined: Mon Oct 22, 2012 4:46 pm

Thu Sep 24, 2015 11:29 pm

Or think about 1100ahx2 with hw ipsec acceleration.