RouterOS set up VPN automatic dialing to realize scientific internet

Source: Internet
Author: User
Tags routeros winbox
Description

RouterOS Version: RouterOS 5.25

Network card 1 (ether1): Connect the external network

ip:192.168.21.100

Subnet Mask: 255.255.255.0

Gateway: 192.168.21.2

Dns:

8.8.8.8

8.8.4.4

Nic 2 (ETHER2): Connect intranet

ip:192.168.237.100

Subnet Mask: 255.255.255.0

VPN Server account password:

VPN server: 10.0.0.100

Account Number: PPTP

Password: 123456

To achieve the purpose:

By setting up VPN automatic dialing in RouterOS, we can visit the original network of the domestic website and visit the foreign website to take the VPN line.

Specific actions:

First, RouterOS network configuration

RouterOS Router management tool winbox download address: Http://download2.mikrotik.com/winbox.exe

RouterOS 5.16 Flexible routing installation Illustrated Tutorial: http://www.111cn.net/archives/4037.html

The following actions are performed after you log on to the RouterOS console

1, set RouterOS login password

Note: After the default installation, login account: admin password is empty

The following login password for admin is set: 123456

Password

Old Password:

New password:123456 #输入密码

Retype new password:123456 #再次输入密码

Password Setup Complete

2, configure the network card IP address

interface Print #显示可用的网卡信息

will appear ether1 Ether2 and other network card information

Here Ether1 represents the network card 1, we use to connect the extranet

Ether2 represents network card 2, used to connect intranet

IP address #设置网卡接口IP地址

Add address=192.168.21.100/24 Inter class=apple-converted-space> #设置外网地址

Add address=192.168.237.100/24 Inter class=apple-converted-space> #设置内网地址

/IP Address Print #查看接口地址

3, use Winbox login RouterOS

Setting up a local area network client

ip:192.168.237.254 (last: 1-254, except 100 is OK)

Subnet Mask: 255.255.255.0

Gateway: 192.168.237.100

DNS is not set

As shown in the following figure

When Setup is complete, open Winbox

CONNETCT to (Connect to): 192.168.237.100

Login (login name): admin

Password (password): 123456

Tick Keep Password (save password)

Check secure mode (safe modes)

Load Previous Session (read previous sessions): Since we are logged on for the first time, we do not check

Note: You can default, you can also fill out your own

When set, point Connect (Connect)

Enter the RouterOS control interface

The following actions are performed in Winbox

4, modify the interface name of the network card

Interfaces

Double hit Open ether1-general

Name:wan

Point Comment (remark)

External network

Ok

Apply-ok

The same method modifies ether2 for LAN, and notes for intranet

5, set the external network gateway (set the default route)

Ip-routes

The + number in the upper-left corner of the point

gateway:192.168.21.2

Dot Comment

External network Gateway (default route)

Ok

The other defaults can be

Apply-ok

6, set up NAT network address translation, map out the network, all the intranet access requests are mapped to the external network 192.168.21.100 above

That is, all the clients within the LAN are ip:192.168.21.100 to the Internet via the RouterOS router's extranet.

Ip-firewall-nat

The + number in the upper-left corner of the point, switch to action

Action:masquerade

Dot Comment

NAT Network Address Translation

Finally, Aply-ok

7. Set up DNS server

Ip-dns

Services:

8.8.8.8

8.8.4.4

Apply-ok

8. Set up a DHCP server

Ip-dhcp Server

Switch to DHCP

Point DHCP Setup

DHCP Server Interface:lan

Next

DHCP Address space:192.168.237.0/24

Next

Gateway for DHCP network:192.168.237.100

Next

DHCP can assign IP addresses as follows

192.168.237.1-192.168.237.99

192.168.237.101-192.168.237.254

Default Next

DNS servers:8.8.8.8

Next

DHCP lease time, by default

Next

Click OK set to complete

Test:

Client IP address in LAN is set to automatically get

Open Web page, be able to surf the Internet, configure successfully

Second, VPN dialing settings

Interface

Dot + Number Select PPTP Client

Switch to dial out

Connect to:10.0.0.100

User:pptp

password:123456

Apply

Ok

Switch to traffic

Can see the flow through, indicating that the VPN server has been connected

Mark all other IP addresses in the RouterOS except for the Chinese segment IP

1. Import IP address of China section

China segment IP address download: HTTP://AUTOROSVPN.GOOGLECODE.COM/FILES/ADDRESS-LIST.RSC

Open files

Drag the ADDRESS-LIST.RSC file from the computer in

Open new Terminal

Input: Import FILE=ADDRESS-LIST.RSC

Ip-firewall-address Lists

You can see the IP address you just imported in

2. Mark IP Address

Ip-firewall-mangle

General

Chain:prerouting

Dst. address:!192.168.237.0/24

In.Interface:LAN

Advanced

Dst. Address List:!novpn

Extra

Dst. Address Type

Address type:local

TICK: Invert

Action

Action:mark Routing

New Routing Mark:vpn

Apply

Ok

3. Set up VPN line routing

Ip-routes

Dst. address:0.0.0.0/0

Gateway:pptp-out1

Distance:1

Routing Mark:vpn

Apply

Ok

After the setup is complete, visit the domestic website, go to the original line, visit the foreign website to go the VPN line
Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.