Build an accessible network environment using RouterOS and OpenVPN

Source: Internet
Author: User
Tags routeros

RouterOS is a very powerful routing system. With the hardware of MikroTik, you can save a lot of cost and implement superior functions such as routing, multiple upstream lines, multiple wireless transceiver, BGP, and OSPF. You can even set a connection to a specific VPN and use the VPN as the default route across network barriers and support OpenVPN. It can be said that it is a civil-level price, enterprise-level function. Given the high reliance on the latest technology, shooter technology also uses RouterOS as a key component of the network environment. A wireless uplink node WiFi is used at the same time) and a network leased line wired ). Downlink is connected to a Gigabit Switch for intra-network Gigabit communication.

RouterOS features a high level of configuration complexity. First, briefly introduce the configuration points of OpenVPN:
1. Drag the Certificate file to the WinBox file (Files) project.
2. Import the Certificate file you just created in the System-Certificates Project
3. Create an OpenVPN connection under the PPP project and use the certificate just imported
Note that currently, RouterOS only supports tcp and does not enable lzo compression for OpenVPN servers.

Then configure the route table. The idea may be contrary to the intuition of most people. It is to set the default route as the gateway of OpenVPN, but the value of Distance is higher, that is, the priority is lower ). The default leased line gateway is used to set routes for IP addresses in China. Of course, the IP address of the OpenVPN server must also be set as a direct connection route ). This is because overseas IP addresses are not directly blocked, but are still affected by keywords. In addition, the number of IP segments in China is small, which is relatively easy to maintain.

Because the route table is still large, use the command line/ip route to enter the console:
Modify the file and change GateWay = ether1 to the name of the real line router Interface. And paste all the content to the console.

Then the entire network environment is accessible. Of course, common websites such as wikipedia and msdn are recommended to use image cache systems such as varnish to build self-built images on the Intranet to save traffic.
 

Edit recommendations]

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.