Community discussions

MikroTik App
 
romheraldi
just joined
Topic Author
Posts: 3
Joined: Mon Jun 04, 2018 7:31 am
Location: Indonesia
Contact:

Cannot Access VPN from Outside

Mon Jun 04, 2018 9:55 am

Hi.

I have a problem using VPN network from my HQ. so here's my network configuration for my HQ office :
Mikrotik Topologi.jpg


i don't have any IP Public Static for this network. so i use IP >> Cloud features.

my current configuration is :

IP >> Address:
  • Ether 2 : 192.168.2.3 (to Router Modem)
  • Ether 4 : 192.168.1.1 (for Local Network)
IP >> DNS:
  • Servers : 8.8.8.8 , 8.8.4.4, 192.168.2.1
  • Allow Remote Request = Yes
IP >> Firewall:
  • NAT : Action = Masqurade , chain = srcnat
IP >> Cloud:
  • Enabled = yes
i try to access my mikrotik from winbox (With another network) using my DNS Name (xxxxxxxxxxxx.sn.mynetname.net) but it's cannot.

can someone help me for this problem ?
You do not have the required permissions to view the files attached to this post.
 
User avatar
JohnTRIVOLTA
Member
Member
Posts: 405
Joined: Sun Dec 25, 2016 2:05 pm
Location: BG/Sofia

Re: Cannot Access VPN from Outside

Mon Jun 04, 2018 11:54 am

Cloud features are used when you have a dynamic public address, not a private one . If you do not have a public address, you can not access your router.
Last edited by JohnTRIVOLTA on Mon Jun 04, 2018 12:35 pm, edited 1 time in total.
 
HairyOne
just joined
Posts: 12
Joined: Thu May 10, 2018 5:39 pm

Re: Cannot Access VPN from Outside

Mon Jun 04, 2018 12:11 pm

Hi!
Either you've got a too many of things wrong or did not specify them in the description, I kindly suggest to read basic installation manual.
For starters:
1) what are NAT rules for HQ router modem?
2) Did you add anything else to SRC NAT in HQ mikrotik?
3) What kind of VPN is being used?

P.s. I also strongly suggest to abandon configuration of double NAT (when you have ISP router\modem NATting) for anything that is related to VPNs. Get a static IP address and ask ISP to configure modem as bridge.

P.p.s. DynDNS will give you private IP, which is useless, but not relevant, since you would be using private IPs anyhow when VPN is set up correctly.
 
romheraldi
just joined
Topic Author
Posts: 3
Joined: Mon Jun 04, 2018 7:31 am
Location: Indonesia
Contact:

Re: Cannot Access VPN from Outside

Tue Jun 05, 2018 4:14 am

Cloud features are used when you have a dynamic public address, not a private one . If you do not have a public address, you can not access your router.
so, am i have a wrong configuration ?
 
User avatar
sindy
Forum Guru
Forum Guru
Posts: 11408
Joined: Mon Dec 04, 2017 9:19 pm

Re: Cannot Access VPN from Outside

Tue Jun 05, 2018 8:41 am

You need at least one public address in the whole system towards which the other devices can establish connections. If the router/modem in the HQ has a public address and you have administrative access to it, you can configure port forwarding on it so that it would deliver the incoming requests to the Mikrotik.

If none of the HQ or the BOs has a public addresses, you'll have to run a virtual Mkrotik or some other device supporting the VPN protocol you've chosen somewhere in a server hosting where you can get a public IP address, and make all your 'Tiks including the one at the HQ site VPN clients of that virtual router (sure you may place a physical 'Tik there if your hosting provider's service offer allows that).

The Mikrotik's cloud service always registers the public address nearest to your Mikrotik in the DNS system, but if the address is not assigned to one of those devices in the chain to which you have administrative access, you cannot set port forwarding on that device.