Community discussions

MikroTik App
 
andyfirebug
just joined
Topic Author
Posts: 2
Joined: Thu Jul 06, 2017 9:25 pm

How to block PPTP/LT2P VPN user from accessing internet

Thu Jul 06, 2017 9:41 pm

Hi everyone,
What would be a good (and preferably easy) way of stopping a pptp/lt2p vpn client who is connected to the router from being able to access the routers internet connection?
I want them to have access to the local lan only.
Currently the vpn client gets an IP in a different range from the local lan.
I am running routeros 6.11 on a RB750.

Thanx in advance.
 
effndc
newbie
Posts: 44
Joined: Wed Jan 11, 2017 1:25 am

Re: How to block PPTP/LT2P VPN user from accessing internet

Fri Jul 07, 2017 1:17 am

Either through firewall or NAT rule changes, you could configure that subnet with explicit allow destination list and then have a deny all to block access to anything not in the approved destination list...or you could look at your NAT policy and have it actually specify the allowed source subnets for masquerade access to the Internet.
 
andyfirebug
just joined
Topic Author
Posts: 2
Joined: Thu Jul 06, 2017 9:25 pm

Re: How to block PPTP/LT2P VPN user from accessing internet

Fri Jul 07, 2017 6:18 am

Ok, either options sounds good, could you detail how to do the config for either?
Thanx much.
 
effndc
newbie
Posts: 44
Joined: Wed Jan 11, 2017 1:25 am

Re: How to block PPTP/LT2P VPN user from accessing internet

Mon Jul 10, 2017 9:47 pm

Easiest option is to edit the existing masquerade tool under Firewall --> NAT. Edit it to add a source IP address subnet of your network that you want to have access to the internet, so if you are using 192.168.1.0/24 you would put that into the Src Address field. This will only allow that address to have NAT to the Internet, by default any address has access. If you have other subnets behind your router (e.g. using VLANs) you could look at using a address lists to include all network segments you want to give Internet access to.

Without seeing your configuration it is hard to be specific.

Who is online

Users browsing this forum: No registered users and 16 guests