Answer the question
In order to leave comments, you need to log in
Is it possible to tunnel between Linux machine and Mikrotik behind NAT?
Good afternoon!
I ask you to suggest the most optimal technology for creating a VPN tunnel for the following configuration:
- VPS Linux with a "white" IP as a server;
- Mikrotik SXT R (LTE) client behind the provider's NAT (there is no possibility of obtaining a "white" IP).
Before that, I tried 2 options - there are comments on both:
1. OpenVPN - the Mikrotik client does not support UDP, the speed drops over TCP, a large load on the Mikrotik processor due to encryption;
2. IPIP tunnel + IPSec. The implementation is detailed here. The connection turned out to be very unstable, perhaps due to LTE, or a crookedly configured IPSec. The main problem is that ping does not show losses between hosts, ICMP packets pass in both directions, at the same time, application traffic is periodically completely blocked - I have not found the reason. The speed is about 5 times lower compared to OpenVPN, the CPU load on Mikrotik is around 25-35%.
Please share your experience, perhaps someone has already solved a similar problem.
Answer the question
In order to leave comments, you need to log in
You put it on vps https://github.com/Kingston-kms/setup-ipsec-vpn and connect from Mikrotik
Please share your experience, perhaps someone has already solved a similar problem.
miroctic as a client on VPS (in the sense of mikrotik for VPS - a client, he addresses him). Strongswan is installed on the VPS, there is ikev2 on Mikrotik (I don’t know how it is in SXT, there is level3 ROS), but in general the Mikrotik VPS on Linux has been working for years without breaks (I mean IPSec, by the way, it doesn’t need any towns like an IPIP tunnel - it works fine by itself)
ipsec ike2.
In routeros7, openvpn udp seems to have been delivered, it has even been released and is more or less stable in simple configurations.
Openvpn. Works and does not ask for
food On udp - do not care
The rest can be cut by the mobile provider
Upgrade your Mikrotik hardware to RouterOS v7 and use UDP in openvpn or wireguard right away.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question