Community discussions

MikroTik App
 
konstg
newbie
Topic Author
Posts: 40
Joined: Wed Oct 29, 2008 11:22 am
Location: Russia

VPN problem - 1

Wed Apr 14, 2010 9:05 am

Hello to all!

In "PPP" module in tab "Interface" I created new "PPTP Server" (pptp-in1) for user "user1". Then I made enabled "PPTP Server" (using checkbox). Then in tab "Secrets" I created new "user1" with "Local Address" = "192.168.200.1" and "Remote Address" = "192.168.200.200". VPN connection from Windows client works normally.

In "IP->Firewall->Filter Rules" created two rules:
"Chain" = "forward", "In.Interface" = "pptp-in1", "Out.Interface" = "local_ether2", "Action" = "accept"
"Chain" = "forward", "In.Interface" = "local_ether2", "Out.Interface" = "pptp-in1", "Action" = "accept"

Therefore, I can ping from 192.168.200.200 (vpn client) to 192.168.200.x (office lan) but can't ping back.

When "user1" was created with "Remote Address" = "192.168.100.200" (for example) ping going well in both ways. I think this is routing issue.

Can anybody tell me what is wrong in my configuration and show right one? :shock:

Thanks in advance,
Konstantin.
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8712
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: VPN problem - 1

Wed Apr 14, 2010 11:18 am

have you enabled Proxy ARP on your ether interface?
 
konstg
newbie
Topic Author
Posts: 40
Joined: Wed Oct 29, 2008 11:22 am
Location: Russia

Re: VPN problem - 1

Wed Apr 14, 2010 12:31 pm

have you enabled Proxy ARP on your ether interface?
Yes, I have. You mean local_ether?
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8712
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: VPN problem - 1

Wed Apr 14, 2010 12:42 pm

yes, local_ether.

so, you can ping in one direction, and at the same time cannot ping in another one? maybe check you firewall?..
 
konstg
newbie
Topic Author
Posts: 40
Joined: Wed Oct 29, 2008 11:22 am
Location: Russia

Re: VPN problem - 1

Wed Apr 14, 2010 2:54 pm

yes, local_ether.

so, you can ping in one direction, and at the same time cannot ping in another one? maybe check you firewall?..
Yes, can ping in one direction only...
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7199
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: VPN problem - 1

Wed Apr 14, 2010 2:58 pm

looks to me like a firewall issue. Try to disable all drop rules in your firewall and check if you can ping then.
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8712
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: VPN problem - 1

Wed Apr 14, 2010 3:05 pm

or maybe even NAT or load balancing helps to mess up things...
 
konstg
newbie
Topic Author
Posts: 40
Joined: Wed Oct 29, 2008 11:22 am
Location: Russia

Re: VPN problem - 1

Wed Apr 14, 2010 3:22 pm

Drop rules are disabled. The same...
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8712
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: VPN problem - 1

Wed Apr 14, 2010 3:37 pm

what does tracert show? look at your mangle rules - maybe you're routing those packets to the Internet, not to your VPN client...
 
konstg
newbie
Topic Author
Posts: 40
Joined: Wed Oct 29, 2008 11:22 am
Location: Russia

Re: VPN problem - 1

Wed Apr 14, 2010 3:59 pm

Here two routes, they are created dynamically. May be here is some contradiction?
Tracert show only asterisks... :shock:

Cos when route2 is for 192.168.100.50, it works...
You do not have the required permissions to view the files attached to this post.
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8712
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: VPN problem - 1

Wed Apr 14, 2010 4:45 pm

mangle, mangle =)
 
konstg
newbie
Topic Author
Posts: 40
Joined: Wed Oct 29, 2008 11:22 am
Location: Russia

Re: VPN problem - 1

Thu Apr 15, 2010 9:00 am

Mangle rules:
You do not have the required permissions to view the files attached to this post.