K
K
Kirill 12014-03-01 23:42:59
Mikrotik
Kirill 1, 2014-03-01 23:42:59

Vlan via l2tp\IPSec mikrotik: how?

Good time, I combined two offices via l2tp \ IPSec on mikrotiks, but I can’t figure out whether it’s really possible to forward through the vlan channel?
Office 1 has vlan 15 and vlan 20, they are also available in office two, it is necessary that traffic from office two gets into its own vlan to access resources, is it possible to implement this task through the already raised l2tp \ IPSec?

Answer the question

In order to leave comments, you need to log in

4 answer(s)
C
Cyril 1, 2014-03-02
@SmileyK

Drank so to speak. We create a bridge into it, we put the vlans we need, Next, we raise the l2tp / IPSec tunnel on the server where the profile of our tunnel is located, we specify our bridge.
As a result, we get (what I needed) vlans that are located in our head office, they are also located in our branches.

M
Maxim Chilikin, 2014-04-02
@AntiHelper

Follow the logic...
Question: How to forward VLANs over the Internet?
Problem conditions:
1) VLANs work at the 2nd layer of the OSI model, therefore they need any transport that supports the second layer.
2) Bridges emulate the second level using the Linux kernel, therefore any tunnels that work or emulate the second level can be connected to them.
3) VLANs can be connected to the bridge, because both work on the second level.
Conclusion: You need to find a kind of tunnel that can be connected to the bridge, and which can forward VLAN, this tunnel must work at the second level of the OSI model, or emulate it.
Answer: Of all the tunnels that are in Mikrotik, at least 2 types of tunnels fit these conditions:
1 - MPLS, habrahabr.ru/post/169103
2 - EoIP, nixman.info/?p=1347
EoIP - easy to configure, easy to work with VLANs, works quite stable if you understand what you are doing.
MPLS - without serious theoretical training, and do not even try tests on cats.
When using any tunnel of the 2nd level, you will increase the amount of traffic by 10-20%. Other problems will appear, such as rings, network connectivity, and so on.
If you really need VLAN forwarding, then what I have listed is the only solution. If you just need a more manageable and reliable network, there are many other, more reliable ways. I can help with this in my free time on a disinterested basis.

W
wladimirmir64, 2014-03-01
@wladimirmir64

Try to add routes to the necessary vlans on Mikrotik after establishing the l2tp\IPSec connection

N
nimbo, 2014-03-02
@nimbo

why not eoip over l2tp? there and vlan'y tried to send.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question