Community discussions

MikroTik App
 
xarmac
just joined
Topic Author
Posts: 3
Joined: Wed Jun 11, 2014 6:10 pm

PPTP VPN can ping mikrotik can't ping any device in LAN

Wed Jun 11, 2014 9:52 pm

I'm new to the Mikrotik routers and I followed the steps for setting up the PPTP VPN. Connection to PPTP VPN server seems to work. The clients obtain an IP address.

As a result I get an IP adres from the pool defined. For some reason the subnet is 255.255.255.255 and gateway is set to 0.0.0.0 which is strange I would say.
The local network of the client is in the range of 192.168.10.0/24

I can ping the mikrotik (10.22.8.254) and my assigned IP is 10.22.8.240 (or one in the pool of 10.22.8.240-10.22.8.249, subnet 255.255.255.0).
Using the ping in /tools ping I cannot ping the assigned IP (10.22.8.240). If a second connection is made I can ping the other device ( 10.22.8.243 for example).

If added the arp-proxy to the interface (ether2-master-lan) which should solve all my problems.

DHCP of the Mikrotik is disabled since there is a Windows Server handling this functionallity.

I've added the export file.

Anybody an idea what this could be?

Kind regards,
Roland
You do not have the required permissions to view the files attached to this post.
 
nmeastman
just joined
Posts: 10
Joined: Wed Jun 04, 2014 2:12 am

Re: PPTP VPN can ping mikrotik can't ping any device in LAN

Thu Jun 12, 2014 6:52 pm

From the config, you added a pptp-server interface, but did not add it to the bridge. You don't need the interface at all unless you want to do some firewall or connection tracking specifically for certain profiles or connections made. The MikroTik will dynamically add interfaces as users connect.

My suggestion would be either:
  • Add the pptp-server interface to the bridge
  • Set the bridge to use proxy-arp
OR:
  • Remove the pptp-server interface
  • Set the bridge to use proxy-arp
  • Set your ppp profile to use the bridge

Also, if you are going to use bridges, it is better to set the IP on the bridge and not a specific interface. I haven't tried it lately, but have had issues with some devices when the IP is on an interface on the bridge instead of the bridge itself.
 
xarmac
just joined
Topic Author
Posts: 3
Joined: Wed Jun 11, 2014 6:10 pm

Re: PPTP VPN can ping mikrotik can't ping any device in LAN

Fri Jun 13, 2014 9:11 am

Thanks. I'm going to try this tommorrow.

I'm not completely sure if it is going to work. Is your solution also valid for a single mikrotik where connections are made with windows clients. I do not know if that was clear in my previous post.

I'll let you know if it was the solution.
 
nmeastman
just joined
Posts: 10
Joined: Wed Jun 04, 2014 2:12 am

Re: PPTP VPN can ping mikrotik can't ping any device in LAN

Fri Jun 13, 2014 5:22 pm

Yes, it will work for Windows clients. We have mikrotik PPTP set up for various businesses, including our own. I have connected Windows, Linux, Mac, and iOS clients to it.
 
xarmac
just joined
Topic Author
Posts: 3
Joined: Wed Jun 11, 2014 6:10 pm

Re: PPTP VPN can ping mikrotik can't ping any device in LAN

Sat Jun 14, 2014 9:56 am

And thank you. I can now at least ping /access from the VPN site the devices on the LAN. For some strange reason I cannot ping from the LAN to the VPN client but my main reason is to control the vpn clients from the LAN is working.

Have a nice weekend.
 
User avatar
spr41178
Member Candidate
Member Candidate
Posts: 114
Joined: Tue Apr 01, 2014 11:11 pm

Re: PPTP VPN can ping mikrotik can't ping any device in LAN

Fri Feb 27, 2015 3:20 pm

Sorry to have to post on this section but i am not allowed to still post a new topic.

My question is similar.

I have a PPTP server set up everything works perfect on my remote site i have 5 RB951Ui2HnD and 5 Engenius Access Points.

My remote range is 172.21.0.0/16 and my access points have static ip's ranging from 172.21.10.11 - 172.21.10.20

The 5 first is Mikrotik Access Points the rest 5 are the engenius.

From the server side i can ping 172.21.10.16 - 172.21.10.20 (engenius access points)
I can't ping 172.21.10.11-172.21.10.15 (the mikrotik access points).

I can ping and access the remote client gateway 172.21.1.1
proxy arp is active

Am i missing something out? Do i have to setup some special firewall rule on these access points? Locally the mikrotik access points ping fine and work fine.

Any help would be much appreciated.