A
A
Alexey2017-10-01 12:32:58
Mikrotik
Alexey, 2017-10-01 12:32:58

How to set up an optional proxy on mikrotik to work with VPN?

There is a home mikrotik, on it, in addition to the provider's gateway, there is also a vpn channel.
Some of the requests are sent to this vpn, I configured it.
Now the question is, is it possible to raise a proxy on Mikrotik (a web proxy is enough) so that when working through it, all requests go to vpn, bypassing the main getway? The idea is that it makes no sense to register all blocked resources in the system - in general, I use this tunnel as a means of bypassing the blocking of GRE traffic on the provider's side, tk. to connect to work, you need to raise a pptp channel (the provider blocks GRE, because the channel does not rise, you have to wrap it in the l2tp channel of the shared vpn).
But sometimes you need to get to sites that are closed from us by our analogue of the Chinese firewall. There is an option to deploy a separate network for this, but it is inconvenient to use, and it is not necessary in general - it does not let you in and high with it. I would like to raise a proxy, which can simply be set in the browser and all traffic through this proxy will go into the tunnel. At the same time, the proxy should not intercept all traffic, but only work with the one that is forcibly sent to it.
I just started working with Mikrotiks and I can’t figure out how to set it up correctly ...

Answer the question

In order to leave comments, you need to log in

4 answer(s)
A
Alexander Karabanov, 2017-10-01
@karabanov

Complicated. Do not do it this way.
There is an easy way: https://habrahabr.ru/post/335436/

A
Alexey, 2017-10-01
@Lezenford

What if I raise socks and send all its traffic to the desired gateway? How to mark such traffic correctly?

A
akelsey, 2017-10-02
@akelsey

And why drive all traffic through VPN, I don’t understand.
Create an address-list, mark them in a mangle and wrap them in a tunnel.
I met a blocked resource - they threw it into the FQDN list - the latest Mikrotik firmware resolves them to IP themselves. And so quietly the base itself will accumulate.
Pros wagon - only blocked resources open via VPN, the rest are all quickly through a local ISP.

G
ganzales, 2019-07-02
@ganzales

Did you manage to implement such a scheme?

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question