Saw some examples:
- https://wiki.mikrotik.com/wiki/Manual:Interface/L2TP
- https://youtu.be/vPxGIz0_Pnw
- viewtopic.php?f=13&t=124618&hilit=l2tp+vpn
- viewtopic.php?f=9&t=123532&p=607963&hil ... pn#p607963
But with all implementations I saw, I don't see them as complete configurations
- shouldn't I need some kind of nat?
- definitively I need firewall rules I also noticed I have some default ipsec rules. do they relate?
Code: Select all
/ip firewall filter
add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
So I ended with this
Code: Select all
/ip pool
add name=dhcp ranges=10.10.10.200-10.10.10.250 # local pool
add name=vpn-pool ranges=10.10.10.251-10.10.10.254 # vpn pool
/ppp profile
add change-tcp-mss=yes local-address=10.10.10.1 name=vpn-profile only-one=yes remote-address=vpn-pool use-encryption=yes
/ppp secret
add name=user password=userpw profile=vpn-profile service=l2tp
/interface l2tp-server server
set authentication=mschap2 default-profile=vpn-profile ipsec-secret=my_secret one-session-per-host=yes use-ipsec=yes
again any insight is welcome