ROS (pptp-xxx) graphic configuration:
Activating PPTP Server
As shown in the following:
Add PPTP Server
As shown in the following:
Adding rules to Ppp--profiles
As shown in the following:
Add a dial-up user in Ppp--secrets
As shown in the following:
Then open PPTP and GRE services in Ip--firewall--service ports. This is the basic XXX configuration is complete.
Things to note are as follows:
XXX User network segment is not the same as the intranet segment.
Problem 1,XXX cannot access the public network after dialing in, that is because of the problem of Nat reflux,
Just remove the Src.address network segment. It's 10.0.0.0/24.
As shown in the following:
Problem 2, the intranet can dial into XXX, and the public network cannot dial in.
Adding a policy 2 rules
Chain:input protocol:tcp dst.port:1723 action:accept
Chain:input Protocol:gre action:accept
Be sure to bring these 2 strategies up, mentioning the first 2 articles.
As shown in the following:
As shown in the following:
As shown in the following:
As shown in the following:
As shown in the following:
Question 3, the Public network dial in XXX, unable to access the intranet share information.
Processing method: Open the Firewall Policy TCP 137-139 port, direct access to the share will prompt for no permissions, use "Mapped network drive" To access the intranet shared resources. (This reason is not clear, continue to study ...) )
Mikrotik Ros * * Borrowing line