S
S
Semyon Sviridov2015-11-02 18:24:38
Mikrotik
Semyon Sviridov, 2015-11-02 18:24:38

How to access a remote ftp server via vpn on mikrotik?

Good afternoon dear ones. There was a need for a remote connection to the FTP server via VPN. I access the Internet through Mikrotik. Dynamic with white IP. When creating a tunnel on a computer, everything works. I connect to ftp without problems. Created a PPTP connection on Mikrotik. Launched. Does not work. Added then a static route. Pings went to ftp. But I can't log in from my computer. Ping also does not pass from the computer. Please tell me what else you need to add rules or routes. Firewall is empty. Screenshots are attached. Thanks in advance.
PS As I understand it, I just now need to natit 2 networks (my internal to remote).
0c64e2375cae424c8d84079e7be86996.JPG9b59cdf1390143d9ac9dabc0ce13665e.JPG

Answer the question

In order to leave comments, you need to log in

3 answer(s)
S
Semyon Sviridov, 2015-11-03
@pincher2006

I have nothing but a masquerading rule and two manually forwarded ports. The rest is automatic UPnP. 2c409419973a4b239aef703766d8bc95.JPG1fde82c6a02d485599a02850aaec10c4.JPG95210d94660e493685fb8dab8fec736a.JPGb340d39c283e457aa6694cf4d04e07bc.JPG
This is a trace from a computer with VPN connected.
This is a trace to the public address of the server on which vpn. And Trace to the Oktell server, which I also need to work like ftp on 10.3.5.67
81ac0a93cc444c5b98522755ecad535a.JPG7fb67a37c5494cd1ac3ed1f2529336a6.JPG

M
Maksim, 2015-11-02
@chumayu

It's good to know the principles ....
In short:
1. Prescribe the necessary routes (ping from a microtic, but not from a computer - because the piece of iron you are pinging does not know how to get to your network (namely 192.168.88.0/24) t
.i.e . on
the remote side, you need to say where your home subnet is located. on the remote side, write
routes.If you don't have access, start navigating :)

G
Grims, 2015-11-05
@grims

Hello Semyon!
It seems to me that you have done too many unnecessary actions, delete all the created static Routes (the correct ones are registered independently, marked as "DAC"), you don't need to nat anything, everything that needs to be processed automatically through the Mangle table of the Mikrotika Firewall (after establishing a VPN connection).
I didn't fully understand the structure of your network, but a possible solution for you could be as follows: Enable proxy-arp on Mikrotik-e on the interface from/through which the connection to your remote FTP server is coming from/through.
Proxy-ARP on the port of the receiving interface allows you to combine two networks that are not connected at the link layer into one. Without this, hosts on these networks (even if they are on the same subnet) may not be able to see each other because they are different physical environments.
And one more thing:
1. Be careful with arp-proxy, you can accidentally intercept all network packets, well, you understand what can happen.
2. And the IP addresses of the LAN and PPTP networks should not be from the same subnet, ideally they should be fundamentally different, for example LAN - 192.168.0.1/24; PPTP - 10.0.0.1/24
3. Read the official manual, maybe it will help bring desires and thoughts to the denominator: PPTP

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question