Page 1 of 1

Why openvpn server on routeros?

Posted: Tue Nov 09, 2021 1:14 pm
by jdMobiusIT
What are the usage scenarios?
Was the OpenVPN server only implemented to be able to advertise with it?
Who really uses OpenVPN servers on routeros and for what?
I never considered using it because it doesn't support UDP.
Now I realize that you can't push routes.

At the moment I use PFSense boxes for my customers and only because of OpenVPN, would like to sell Mikrotik.
What is the probability that all standard functions will be implemented in the foreseeable future?

Now I have exactly the same purpose in my office as my customers. I would like to set up SIP phones with OpenVPN for my employees, but I can't do it with Mikrotik because I can't push routes.

I think the feature should be completely removed to avoid a lot of disappointment.

Re: Why openvpn server on routeros?

Posted: Tue Nov 09, 2021 3:27 pm
by nettnuts
No, OpenVPN works okay for me. Using TCP gives some speed penalty, not so important for my use case.
Missing support for route pushing can be easily bypassed in the user policies.

OpenVPN server will be improved with RouterOS V7.1, which is, however, not ready yet.
Wireguard support is added there, too.

Re: Why openvpn server on routeros?

Posted: Tue Nov 09, 2021 4:06 pm
by Znevna
Exactly what I wrote here: viewtopic.php?p=890059#p890059

Re: Why openvpn server on routeros?

Posted: Tue Nov 09, 2021 4:34 pm
by nettnuts
Not really, I'm glad that ROS supports OpenVPN, because this way the VPN endpoint is where my firewall is.

However, to get more features for the same price would always be nice, but it works for me as it is without any problems.
And improvement will come, not so bad.

Re: Why openvpn server on routeros?

Posted: Tue Nov 09, 2021 4:39 pm
by Znevna
Any particular reason you're insisting on OpenVPN ?
Considering it lacks hardware acceleration among other things.

Re: Why openvpn server on routeros?

Posted: Tue Nov 09, 2021 4:53 pm
by nettnuts
Yes, I have to keep existing tunnels for legacy reasons. If speed is an issue and I would be free to choose, some other VPN types already exist in ROS.

Re: Why openvpn server on routeros?

Posted: Tue Nov 09, 2021 5:14 pm
by Znevna
Legacy tunnels can be migrated to something else. I've migrated from OpenWrt/OpenVPN to RouterOS/IKEv2 without issues, they ran in parallel until migration was complete.
You just have to take the time to do it. You'll have to at some point anyway.

Re: Why openvpn server on routeros?

Posted: Tue Nov 09, 2021 8:15 pm
by jdMobiusIT
Legacy tunnels can be migrated to something else. I've migrated from OpenWrt/OpenVPN to RouterOS/IKEv2 without issues, they ran in parallel until migration was complete.
You just have to take the time to do it. You'll have to at some point anyway.
Oh really? Migrate a SIP Phone to RouterOS.
Any particular reason you're insisting on OpenVPN ?
Considering it lacks hardware acceleration among other things.
Compatibility?


Guys I'd love to migrate to IPsec/Wireguard but there are many reasons that i need multiple OpenVPN servers.
And I'd love to get rid of all pfSense boxes.

Re: Why openvpn server on routeros?

Posted: Tue Nov 09, 2021 8:24 pm
by Znevna
If you bought hardware that only supports OpenVPN (and you need the VPN client on the phone for some reason?) go with something that supports OpenVPN properly.
Or find another solution to your setup.

Re: Why openvpn server on routeros?

Posted: Wed Nov 10, 2021 4:43 am
by jdMobiusIT
If you bought hardware that only supports OpenVPN (and you need the VPN client on the phone for some reason?) go with something that supports OpenVPN properly.
Or find another solution to your setup.
Very wise words. Your answers are very valuable and well thought out.

Re: Why openvpn server on routeros?

Posted: Wed Nov 10, 2021 9:23 pm
by Znevna
Surely I won't buy devices that I can't use properly with the hardware available already.
Are you using FreePBX? that has OpenVPN server support afaik, you don't even need to run it on your router.