R
R
Ruslan Nevelyaev2021-06-15 21:19:34
Mikrotik
Ruslan Nevelyaev, 2021-06-15 21:19:34

How to redirect traffic that bypasses RKN blocking from home Mikrotik to cloud CHR?

Hello! I decided to make myself a permanent personal VPN to bypass blocking using the free Free Tier from AMAZON, since it has a choice of Mikrotik CHR in the database of operating systems, and a free instance is more than enough for such needs. At home on microte, a personal Open VPN server for various tasks has been successfully working for a long time, so I decided to create a foreign server for myself, at least for the sake of interest. CHR is bare from scratch, unlike the usual ROS on new routers, where there is still an initial configuration, WAN and LAN ports, bridges, etc. are defined. I determined the initial configuration (standard firewall rules, login-password), created a pool 192.168.0.2-100, created an OVPN server, profiles-passwords-users-certificates, there are no problems with this. Created an OVPN Server Binding interface for the OVPN user, created a Bridge and bound it to the OVPN interface. Created WAN, LAN interfaces, tied a single "physical" interface to the WAN, OVPN-In interface to the LAN. The home microt connects, receives an IP address from the pool, the house responds with CHR, from the house 192.168.0.1 too. The CHR address on the OVPN interface was assigned, of course, at the beginning of the pool (192.168.0.1). In turn, I created an address list on my home microte, attached to it, for example, Rutracker.org. He immediately parsed the IP address and also added it to this address list. In Mangle, I created a rule to mark packets with the RKN label for addresses from this list. I created an empty Dst route. Address 0.0.0.0/0) to gateway 192.168.0.1 for packets labeled RKN. When creating a route, the gateway was defined on the corresponding OVPN interface. When trying to type Rutracker.org, the provider's ban window no longer pops up, but the "Resource not found" error is displayed. When trying to tracert on rutracker, tracing starts on the home gateway (.1.1), and ends on it. What to do and where exactly the plug - until I understand. At least how to correctly formulate a search query in order to find similar schemes.

Answer the question

In order to leave comments, you need to log in

2 answer(s)
D
Drno, 2021-06-15
@nevelaev

I have the same thing done at home. Everything is correct with the settings - add a sheet to the address, then create a manga with marking, then add routing (added a picture)
60c8fc2c7f6ea530816540.jpeg
On CHR - is there a masqurade rule for VPN connections? So that CHR knows what can be a gateway for VPN clients? Same rule as for WAN. I (mk vpn stupidly personal) just made Out. Interface - all ppp

T
Talyan, 2021-06-15
@flapflapjack

The topic of the question is very interesting, and as a network engineer, I would like to help. But I won't read it. No paragraph, no separate questions. Nothing. Complete disrespect for those responsible.
Eat yourself.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question