Answer the question
In order to leave comments, you need to log in
How to fix the vpn network speed so that everything starts on Mikrotik?
Central CCR1036 Link 100M (guaranteed channel)
Branches RB750 Link 2M (guaranteed channel)
A PPTP server was raised on the CCR1036 because the branches have dynamic WAN IPs
The only add-ons that were made with FW were filter rules
/ip firewall filter
add action=drop chain=input comment="\C7\E0\E1\EB\EE\EA\E8\F0\EE\E2\E0\F2\FC \
\EF\EB\EE\F5\E8\E5 \EF\E0\EA\E5\F2\FB" connection-state=invalid
add chain=input comment="\D0\E0\E7\F0\E5\F8\E8\F2\FC \F3\F1\F2\E0\ED\EE\E2\EB\
\E5\ED\ED\FB\E5 \F1\EE\E5\E4\E8\ED\E5\ED\E8\FF" connection-state=\
established
add chain=input comment=\
"\D0\E0\E7\F0\E5\F8\E8\F2\FC \EF\F0\EE\F2\EE\EA\EE\EB Ping" disabled=yes \
protocol=icmp
add chain=input comment=\
"\D0\E0\E7\F0\E5\F8\E8\F2\FC \EF\F0\EE\F2\EE\EA\EE\EB GRE" protocol=gre
add chain=input comment=\
"\D0\E0\E7\F0\E5\F8\E8\F2\FC \EF\F0\EE\F2\EE\EA\EE\EB PPTP" dst-port=\
1723 protocol=tcp
add chain=input comment="\D0\E0\E7\F0\E5\F8\E8\F2\FC \EF\EE\EB\ED\EE\E5 \F1\EE\
\E5\E4\E8\ED\E5\ED\E8\E5 \EF\EE \EB\FE\E1\EE\EC\F3 \EF\F0\EE\F2\EE\EA\EE\
\EB\F3 \EB\E8\F1\F2\F3 safe" src-address-list=safe
add action=drop chain=forward comment="Block Adobe" layer7-protocol=adobe \
src-address=10.8.0.0/16 src-address-list=!ACL_IP_IT_SUPPORTS
add action=drop chain=forward comment="Block Corel" layer7-protocol=corel \
src-address=10.8.0.0/16 src-address-list=!ACL_IP_IT_SUPPORT
add action=drop chain=input comment=\
"\C7\E0\E1\EB\EE\EA\E8\F0\EE\E2\E0\F2\FC \E2\F1\B8"
Answer the question
In order to leave comments, you need to log in
Is encryption enabled? If so, try turning it off.
What is the processor load on the RB750 at the time of transmission?
is everything ok with mtu? what mtu costs on pptp tunnels?
Well, I join - what about encryption?
put everywhere no
Test from the branch (10.8.29.100) data center 10.8.254.254
everything is sad
Ping from the branch (10.8.29.100) data center 10.8.254.254
pass, if I start to put -l 1500 does not work - it works fine -l 1400
The problem was solved, everywhere I had a shaper for VoIP so that the speed did not exceed 256kb
/queue simple
add limit-at=256k/256k max-limit=256k/256k name=Phone1 packet-marks=\
Phone1-packet priority=1/1 target="" total-priority=1
add limit-at=256k/256k max-limit=256k/256k name=Phone2 packet-marks=\
Phone2-packet priority=2/2 target="" total-priority=2
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question