Help with Mikrotik PPTP VPN and Routing

OnyxxOr

New Member
Joined
Jan 15, 2008
Messages
3
Reaction score
0
Hi guys,

Hoping this is the right forum for this! :)

Please can I ask for some help from the experts with my home network setup?
I have added a mikrotik to my network, but not as my primary router. I have a TP-Link GB modem router as my primary, and I have added the mikrotik (10/100 only alas) for the sole purpose of providing a VPN entry point.

I have gotten pretty far, but I seem to be missing the final piece. The below image will help describe my problem, but in a nutshell, I can connect to the VPN, acquire an IP Address, and devices on my internal network can see (ping) my remote device.

I ended up putting my VPN clients on a second subnet, as I was able to get this to work on a single subnet, but ONLY if added a static route on my PC (Where I can route a single IP on mask 255.255.255.255 to the mikrotik, on the same LAN. On my TP-Link it is impossible to route within the same subnet - it just won't allow it). This would have been OK, expect I can't put static routes onto my Non-PC devices, primarily my IP Cams, so the only way I could see around this was with a different subnet, routing from my TP-Link back down the network to the mikrotik (sitting on my primary subnet).

All of this works, except the remote devices are not seeing clients on the network (However, they ARE seeing the routers, both the TP-Link (DNS and GW for the mikrotik) and the Mikrotik itself to which they are attached.

Any help would be hugely appreciated!! --> Network Diagram below;

Regards
Dylan

http://i1382.photobucket.com/albums/ah280/OnyxxOr/HomeNetwork_zpsff98d533.jpg
 
It is 1 of 2 possible cases, I think.

1. Looks like something on your network doesn't like asynchronous routing, eg. A route from 10.81.6.x contacts devices in the 10.81.5.0/24 range directly, while routing to it happens via the TP link device.

2. 10.81.5.4 has a firewall that accepts packets from the the 10.81.5.0/24 home network, but does not trust packets from 10.81.6.0/24

You should check # 2 first, as that is the easier one to fix.

# 1 will be a bit trickier to get routing asynchronous. It is also more difficult to know whether that is actually the problem.

PS. Awesome pic, helps quite a bit with looking at the setup!
PPS. How the heck is this only your 2nd post after joining in 2008?
 
Tinuva, Thanks mate! :) ,

Ok, checked out the firewewall option which turned up blank unfortunately... sort of expected that though since non-FW devices (like the Cams) are responding the same way (aka "not" replying on ping :erm:).

Thanks for the idea on the asynch routing - that is something new to me and a google chain for me to follow!
I was sort of thinking it was a stock routing issue, though if I torch my VPN interface from the mikrotik while pinging my PC, I see TX from the PC, but no RX on the VPN client. This bit confused me since the outbound route from the PC is good (If the source of ping), so since the VPN was hitting the PC and I saw TX from the PC, it should have picked up the route from the TP-Link back through the Mikrotik :confused: ... I'm in the mind to test 2 alternatives, which is hard-lining a static on the PC again (forcing it back through the mikrotik), just to confirm that part, then moving the mikrotik to it's own subnet instead of sharing the 10.81.5.x, bridging it at the TP Link.

I'll check these 3 out (and learn about Asynch routing on the way ^^).

Thanks again!

P.S. Yeah Guilty as charged - I generally tend to find 99.9% of my answers through google-fu; this is a rare case where I can't google my way out of a painted corner!! Admittedly I should try and contribute though - I'm motivated to now though! \m/

P.P.S looking forward to feeding back once solved with a completed config diagram - I'm pretty sure there are others who would be looking at this network architecture, and to be honest, there is nothing like this online, that I have bumped into anyway...

Shotto!
 
Top
Sign up to the MyBroadband newsletter
X