Page 1 of 1

L2TP/IPSEC client behind NAT fw to ROS3..

Posted: Thu Jul 19, 2007 2:32 pm
by amode
Hi,

we have a very-typical configuration for "home" workers:

Home-Laptop (using private IP) -> Home-Router doing NAT -> Office Mikrotik having static public IP.

Now, the home users should be able to connect to the office by using L2TP/IPSEC (using windows xp), but I was not able to setup this configuration using ROS3beta10.

Can someone please post the required config for the Mikrotik side?

Thanks for any help here.
Achim

PS: We're using ROS3beta10, beacaue I think we need this new feature "NAT traversal" in the IPSec Peer settings, right?

Re: L2TP/IPSEC client behind NAT fw to ROS3..

Posted: Fri Jul 20, 2007 10:53 am
by amode
Hm, so no answer here after one day means that this "feature" is not so easy to setup as it sounds?
Or it doesn't work at all?
I was thinking that this scenario is quite common out there, but is not...(?)

Achim

Re: L2TP/IPSEC client behind NAT fw to ROS3..

Posted: Fri Jul 20, 2007 7:40 pm
by changeip
I have never gotten L2TP IPSec to work between windows and routeros. I believe it has to do with the certificates, ipsec configuration (not static ip = wont work most likely), ipsec policies, etc. You can use PPTP with no problems.

Re: L2TP/IPSEC client behind NAT fw to ROS3..

Posted: Fri Jul 20, 2007 7:59 pm
by amode
Thanks a lot for the reply.

@Mikrotik: So, native Linux l2tp/ipsec works with windows clients. Why does the linux based ROS not work in this context?