Community discussions

MikroTik App
 
User avatar
satman1w
Member Candidate
Member Candidate
Topic Author
Posts: 287
Joined: Mon Oct 02, 2006 11:47 am

VPN between two identical subnets

Fri Jan 25, 2013 3:16 am

Hi all,

Situation:
Location "A": RB450 as PPTP server on bridged ADSL and private subnet 192.168.10.0/24, MS Server, AD.....
Location "B": same subnet (192.168.10.0/24) and single windows PPTP client connecting to location "A" and accessing terminal server (RDP).

As you can suspect after VPN is established there is not much more you can do because all the traffic for 192.168.10.0/ stays within local subnet as it is the same as remote.
At the moment there is no way to change either of the subnet addresses.

What do you suggest as the simplest solution to the problem?

Regards
 
User avatar
StubArea51
Trainer
Trainer
Posts: 1742
Joined: Fri Aug 10, 2012 6:46 am
Location: stubarea51.net
Contact:

Re: VPN between two identical subnets

Fri Jan 25, 2013 3:24 am

This is a pretty common scenario...usually you will NAT one side only for traffic that is destined across the VPN. A few mangle rules should fix it up for you.
 
User avatar
cybernetus
newbie
Posts: 41
Joined: Sat Sep 08, 2012 1:39 am
Location: Belo Horizonte/MG/Brazil
Contact:

Re: VPN between two identical subnets

Fri Jan 25, 2013 5:03 am

Hi all,

Situation:
Location "A": RB450 as PPTP server on bridged ADSL and private subnet 192.168.10.0/24, MS Server, AD.....
Location "B": same subnet (192.168.10.0/24) and single windows PPTP client connecting to location "A" and accessing terminal server (RDP).

As you can suspect after VPN is established there is not much more you can do because all the traffic for 192.168.10.0/ stays within local subnet as it is the same as remote.
At the moment there is no way to change either of the subnet addresses.

What do you suggest as the simplest solution to the problem?

Regards
I need to create a solution too for a problem like this.

Sent from my GT-I9100 using Tapatalk 2
 
glucz
Member Candidate
Member Candidate
Posts: 123
Joined: Wed Jun 06, 2007 10:25 pm

Re: VPN between two identical subnets

Fri Jan 25, 2013 12:47 pm

If you don't want to mess with routing or NAT, you can put an EOIP tunnel over the VPN. That will join the 2 network segments, however you have to be careful with DHCP because you probably have it on both netowks and now they will conflict with each other ... so you may want to switch to manual configs or use STATIC rules to configure specific MAC addresses. Since you are bridging the networks together, you cannot filter DHCP in the firewall unless you switch on IP FIREWALL for the bridge, but even then I'm not sure how it can be done.

Another possible problem is that you will have a lot of added traffic on your VPN like broadcasts. So if you are on a low bandwidth connection, it might not be the best solution.
 
User avatar
satman1w
Member Candidate
Member Candidate
Topic Author
Posts: 287
Joined: Mon Oct 02, 2006 11:47 am

Re: VPN between two identical subnets

Fri Jan 25, 2013 1:15 pm

This is a pretty common scenario...usually you will NAT one side only for traffic that is destined across the VPN. A few mangle rules should fix it up for you.

I did not quite understand the idea, can you be more specific.

If I was not clear enough, there is only one Mikrotik router, at the "A" location, and on the other side there is single Windows client....
 
User avatar
satman1w
Member Candidate
Member Candidate
Topic Author
Posts: 287
Joined: Mon Oct 02, 2006 11:47 am

Re: VPN between two identical subnets

Fri Jan 25, 2013 1:20 pm

If you don't want to mess with routing or NAT, you can put an EOIP tunnel over the VPN. That will join the 2 network segments, however you have to be careful with DHCP because you probably have it on both netowks and now they will conflict with each other ... so you may want to switch to manual configs or use STATIC rules to configure specific MAC addresses. Since you are bridging the networks together, you cannot filter DHCP in the firewall unless you switch on IP FIREWALL for the bridge, but even then I'm not sure how it can be done.

Another possible problem is that you will have a lot of added traffic on your VPN like broadcasts. So if you are on a low bandwidth connection, it might not be the best solution.
How do you plan to establish EOIP between Wndows client and Mikrotik router??? AFAIK EoIP is possible only between Mikrotik routers !?
Am I right?
 
User avatar
mmv
Trainer
Trainer
Posts: 67
Joined: Wed Feb 24, 2010 5:03 pm
Location: Moscow, Russia
Contact:

Re: VPN between two identical subnets

Fri Jan 25, 2013 3:11 pm

This is a pretty common scenario...usually you will NAT one side only for traffic that is destined across the VPN. A few mangle rules should fix it up for you.

I did not quite understand the idea, can you be more specific.

If I was not clear enough, there is only one Mikrotik router, at the "A" location, and on the other side there is single Windows client....
You can configure DST-NAT to represent resources from A as it in different subnet.
 
neticted
Member Candidate
Member Candidate
Posts: 137
Joined: Wed Jan 04, 2012 10:36 am

Re: VPN between two identical subnets

Mon Jan 28, 2013 4:23 am

How do you plan to establish EOIP between Wndows client and Mikrotik router??? AFAIK EoIP is possible only between Mikrotik routers !?
Am I right?
Well, if you seriously need to connect two networks you will use Mikrotik on both sides of the link. As glucz mentioned you will have to block DHCP to pass through tunnel (it works fine), and possibly some more settings, that you cannot control properly if Mikrotik is not on both sides.

Let the routers do networking and Windows do it's stuff.
 
CelticComms
Forum Guru
Forum Guru
Posts: 1765
Joined: Wed May 02, 2012 5:48 am

Re: VPN between two identical subnets

Mon Jan 28, 2013 12:11 pm

At the end with the Windows PPTP client is there anything else on the local subnet that the Windows PC needs access to other than the gateway/router?

If not and if you don't mind the Windows PC accessing the internet via "Location A" then PPTP and proxy-ARP could work until a better solution can be arranged.