P
P
pred8or2021-03-28 12:57:54
Mikrotik
pred8or, 2021-03-28 12:57:54

How to connect a device on a network at a remote site to the office network?

There is a local area network in/on an abstract organization/building/site.

60604d3a54b60558639965.png

It is necessary to connect a device with minimal impact on the environment, which would be in the local network of the parent organization, as in the figure.

60604d8c292ad401578020.png

Neither the device nor the router through which it connects should ideally require any configuration on site (of course, they must be configured before being issued). They brought it, connected it, the connection was established, it worked. So far the presentation is:

The head office network uses VLAN100 for connected devices, VLAN200 for managing network equipment. The router of the parent organization has a white address. A router at a remote site connects to that site's LAN instead of (say) a computer. The computer connects to the specified port on the router and works as before. The required device is connected to another specified port of the router. Through the tunnel created by the router, this device connects to the local network of the parent organization VLAN100, receives an address from there via DHCP and works. The router itself is controlled from the parent organization, being in VLAN200.

So far, SSTP is considered as a tunnel (we believe that no measures need to be taken at the remote site to release SSL to the outside) and having the ability to authenticate using certificates.

So, how feasible is such a task, what are the pitfalls and / or better alternatives? Well, examples of RouterOS spells will also help a lot

Answer the question

In order to leave comments, you need to log in

1 answer(s)
P
poisons, 2021-03-30
@poisons

Completely working solution. From the point of view of the "fenced enemy network" - the choice of SSTP is obvious. Everything else can be cut.
If you really really want l2 to be there, wrap EoIP inside SSTP as well, and hook its ends to the vlans you need.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question