Mikrotik Pptp Server

1 view
Skip to first unread message

Martin Glow

unread,
Aug 5, 2024, 2:50:24 PM8/5/24
to lidtadade
Weare having issues with customers who connect having very low tcp speed when connected via mikrotik PPTP/L2TP. Users who subscribe typically to 20Mbps are are only getting speeds of 4Mbps when connected to either mikrotik pptp or l2tp server even with encryption disabled. The same users to a windows or linux pptp server are able to get speeds higher than 20Mbps.

There is currently a github project named accel-ppp - High performance PPTP/L2TP/PPPoE/IPoE server for Linux. Would it be possible to integrate it into splynx 2.0 with the right dictionary templates as a work around for mikrotik issues with pptp speeds?


All tests performed from the server side to the client side. Notice from the server side for tcp tests speed max at 7Mbps. Which means highest speed client can get is 7Mbps. However same client connect to a linux server or microsft server implementing pptp server is only limited by the speed of the physical connection.


I think this is the issue of your local configuration or network design, maybe there is a MTU issue somewhere between points, that can cause MSS TCP problems and TCP cannot send large segments of data , maybe there is wrong queues settings, who knows.


Usually issues on PPtP or PPPoE are MTU related.

Too small MTU in the tunnel will lead to higher fragmentation and therefore more pps and decreased total performance while to high MTU will lead to timeouts and retransmissions.


PPPoE connection are ok no issues. The issues is with the PPTP and L2TP connections. I think its mikrotik specific issue. Linux (Debian8/9 and Centos9 tested) as well as Windows Servers located at same place as the mikrotik server do not have that issue so we can rule out Path MTU.


Alright my peoples. This one will show you how to do a simple PPTP setup on your Mikrotik and even how to configure your Windows machine to connect to said PPTP server. This will allow you to securely access your network remotely by creating a secure tunnel over the internet.


Hello, after start VPN connection I get Ip address 192.168.1.21 and default gateway is the same.How could I change it?If it is so, I can`t access on another PC.I need to have the same default gateway for all VPN connections.


Hello, thank you for tutorial, but it doesn`t works right.When I`m connected to Mikrotik through VPN I have IP address and gateway the same.Then I can`t acces to another computer which is connected through VPN to Mikrotik too.Where could I set default gateway for all connections?Thanks.


Are you trying to print from the hub site to the remote or are you printing from the remote to the hub site. I assume it is the hub site. You have the printer mapped straight on your machine, or are you using a print server?


I have a problem. I can connect to the pptp and it gives me a IP in the same subnet, but I cannot connect to devices on that network or ping any devices. I had to forward ports on the Mikrotik thats on the public IP to a mikrotik that is connected via Radio towers. I can ping the mikrotik but no devices.

Thanks in advance


A good one. thank you. I, a rookie has been able to successfully configure VPN using PPTP. But how do i do Active Directory Authentication so users can authenticate with same username and password they use to log in to the domain to log in to the VPN.


Excellent tutorial! I was able to set up the tunnel that I have been working on for hours in minutes!

Question, it does not seem to be assigning me a gateway ip. it just shows 0.0.0.0 and I am not able to access anything on the remote network. Any hot ideas?


I have done this an am successfully able to get connected. I have enabled proxy-arp on the internal interface. I can ping devices in my VPN network by IP address by not by name. I cannot access anything buy doing \\server in a run command. Any ideas?


@jay

Try [windows key]+r to bring up your run window. Then type the IP with slashes \\x.x.x.x.

Also check that the network you are connected to is not set as public in your file sharing. Then check to make sure that file sharing is enabled for work and private networks.


PPTP l 1 giao thức để kết nối VPN đ ra đời từ rất lu của Microsoft, PPTP c nhiều vấn đề bảo mật. Tuy nhin giao thức ny vẫn được sử dụng đến ngy nay v sự phổ biến v tiện dụng của n.


M hnh lab sẽ sử dụng 1 router MikroTik kết nối với card NAT trn Pnetlab. Do đy l lab ảo, nn chng ta sẽ kết nối trực tiếp VPN với my tnh Windows đang lm lab lun. Điều ny cũng sẽ giống như bạn đang truy cập VPN từ ngoi internet vo router MikroTik.


Cấu hnh đặt tn cc interface, đặt IP cho cc cổng, tạo DHCP server cho LAN,.. Card NAT trn Pnetlab sẽ cấp IP cho cổng WAN của router MikroTik. Trong phạm vi bi lab, IP ny dng để kết nối VPN, ta tưởng tượng n như IP Public tĩnh m ta đăng k với nh mạng trong thực tế nh.


Trong mục PPP, ta tạo 1 Profile v gắn pool vừa tạo ở bước trn để thực hiện cấu hnh tiếp cho bước sau nh. Phn ny bạn chỉ cầu cấu hnh như hnh bn dưới, chọn OK l xong.


Như vậy l chng ta đ cấu hnh xong VPN client to site sử dụng giao thức PPTP trn router MikroTik. Với cc bản OS khc sẽ c giao diện khc 1 cht nhưng cc bước vẫn thực hiện như trn.


Lưu : Trong qu trnh kết nối VPN th c thể gặp trường hợp người dng khng thế kết nối được do firewall ở cng ty đ chặn cc port dịch vụ VPN PPTP. Chng ta cần mở cc port sau để thực hiện kết nối nh.


Tuy rằng giao thức PPTP đ ra đời từ rất lu nn tnh năng bảo mật km hơn cc giao thức kết nối VPN mới như: L2TP/IPSec VPN. Nhưng PPTP vẫn l 1 giao thức được sử dụng rộng ri v bởi tnh phổ biến của n. V c thể l 1 phương n dự phng trong trường hợp cc giao thức kết nối VPN khc bị lỗi.

Qua bi ny viết, CNTTShop đ hướng dẫn thnh cng cấu hnh VPN PPTP trn m hnh lab ảo, trong thực tết bạn hon ton c thể lm theo hướng dẫn ny. Chc cc bạn thnh cng!

>> Xem thm sản phẩm MikroTik tại: -mikrotik


L chuyn gia trong lĩnh vực Network System, Security, Server.. C kinh nghiệm nhiều năm tư vấn giải php mạng, triển khai cc giải php CNTT v phn phối thiết bị mạng Switch, Wifi, Router, My chủ Server, Lưu trữ Storage, Tường lửa Firewall, Video Conferencing, Module quang, Load Balancing. Hiện tại ti l Founder v Managing Director cng ty TNHH Cng Nghệ Việt Thi Dương (CNTTShop.vn).

3a8082e126
Reply all
Reply to author
Forward
0 new messages