MikroTik RouterOS Easy Policy Based Routing, selective devices through VPN Tunnel

Поділитися
Вставка
  • Опубліковано 17 жов 2024

КОМЕНТАРІ • 37

  • @The-Indefatigable-Otaw
    @The-Indefatigable-Otaw 2 роки тому +1

    Thank you finally I found this solution! Been looking this for weeks.

  • @GlynnRyan
    @GlynnRyan 5 років тому +1

    Thank you! This helped me route work related traffic using an alternate connection whitelisted by my work. Now I don't need to keep toggling address list rules on and off for specific devices when needed.

  • @benyaminyazdian6460
    @benyaminyazdian6460 2 роки тому +1

    very helpfull , thank you , i used to only create mark-routing mangle and i should ve disabled my default internet gateway and created a seperate route for the vpn host address it self to be able to connect , and whole thing was a mess . now with mark-connection mangle it works flawless . not disabling the default internet gateway lets me use domains in vpn server config and not the actual ip address . thanks a lot

  • @meowmeow-00753
    @meowmeow-00753 2 роки тому +1

    Thanks, your video helped me a lot.

  • @jamesrichard166
    @jamesrichard166 4 роки тому +1

    great job steveocee....this really helped me solve similar case i have been battling to solve for a while now...thanks man

  • @OfficialRoot
    @OfficialRoot 2 роки тому +1

    Thanks!!! Good Work!!!

  • @bis0nat0r
    @bis0nat0r Рік тому +1

    Hi Steve, thanks for the clear and well made video tutorial. I just tried this in RouterOS7 but can’t get it to work, there is a different where the routing mark has to be added as a routing table first however it still didn’t work for me, I lose all internet connectivity when adding the IP Route. Not sure if you’re still into MikroTik gear but if so any pointers would be appreciated. Thanks.

    • @andrieshrr
      @andrieshrr 10 місяців тому

      I have the same issue with combining ROS7 and Wireguard VPN - no luck so far :(

    • @SteveoceeCoUk
      @SteveoceeCoUk  5 місяців тому

      I have recently come across a WG and ROS7 problem. I'll figure it out soon.

  • @xshotx2745
    @xshotx2745 6 місяців тому +1

    Hello, i hope you're still active and I appreciate how useful this is. Can you make a tutorial similar to this but with ROS v7? I've been having a hard time figuring it out. Thanks!

    • @SteveoceeCoUk
      @SteveoceeCoUk  5 місяців тому

      I will try (at some point - currently going through a pfsense stage, potentially moving towards UBNT) But will give it a go (y)

  • @gottikkus
    @gottikkus 3 роки тому +2

    Thanks man, helped a lot! The only thing I don't understand, why do you need mark both connections and routing? Why not just mark routing only?

    • @SteveoceeCoUk
      @SteveoceeCoUk  3 роки тому +2

      I have always done both, in theory the "best" way would be mark connection "X" first and then next mangle rule specify anything with connection mark "X" to mark the packets.

    •  3 роки тому

      @@SteveoceeCoUk Hi and thanks for your videos! I am doing it a same way as @Roman mentioned. Is there some issue with it (e.g. security...). Or it is just different approach? I want to have my setups more secure and according the best practices if possible :-)

  • @androjdimo5725
    @androjdimo5725 2 роки тому +1

    Thank you for this, indeed helpful. Would you mind updating it for somewhat more recent version of MikroTikOS (7) ? Also in my case, this method is working, however the connection to the internet via the tunnel is painfully slow. Yet local addresses on the other end of the VPN are working just fine.

  • @yalcin1234
    @yalcin1234 Рік тому +1

    Very helpfull thank you

  • @leezhijiang
    @leezhijiang 2 роки тому

    Can you have a separate tutorial on how to do this for IPSec VPN which covers
    - specific websites that bypass ipsec vpn tunnel
    - specifc websites to specific ipsec peer

  • @jrnmadsen2710
    @jrnmadsen2710 4 роки тому +1

    Well done, great job :)

    • @jrnmadsen2710
      @jrnmadsen2710 4 роки тому +1

      You should do a lot more. You're god at explaining work flow and essentials.
      Would be easier to see, if you zoomed in on "active" window,- some does that, I don't know which tool they use.

  • @junnel2608
    @junnel2608 4 роки тому +1

    easy!!! thank you!

  • @sohelahmad5625
    @sohelahmad5625 3 роки тому

    Is it possible with IKEv2? Nord and Surfshark provide IKEv2 method & I'm stuck there. 😭😭

    • @SteveoceeCoUk
      @SteveoceeCoUk  3 роки тому

      No idea. I don't use/need IKEV2 so it's not an area of focus for me right now.

    • @sohelahmad5625
      @sohelahmad5625 3 роки тому

      @@SteveoceeCoUk My ISP blocked the VPN port. Now solved. Thanks.

  • @AmirMotahari
    @AmirMotahari 4 роки тому

    Hi, thanks alot.
    but I'm confused!
    How to create connection mark for vpn and more?
    I wish you did that from the beginning.
    thanks again

    • @SteveoceeCoUk
      @SteveoceeCoUk  4 роки тому +1

      3:50 is where we create the first rule for initial connection mark.

  • @sohelahmad5625
    @sohelahmad5625 3 роки тому

    Nord use IKEV2, so how to configure that?

    • @SteveoceeCoUk
      @SteveoceeCoUk  3 роки тому

      No idea. I don't use/need IKEV2 so it's not an area of focus for me right now.

    • @sohelahmad5625
      @sohelahmad5625 3 роки тому

      ​@@SteveoceeCoUk Thanks for the response. I found a complete setup guide in Mikrotik wiki.

  • @juliantodiamond9135
    @juliantodiamond9135 4 роки тому +1

    How if you have 2isp? Can u give the tutorial?

    • @SteveoceeCoUk
      @SteveoceeCoUk  4 роки тому

      I can, it is very straight forward but you need to specify if you want alternate routing or a simple failover?

    • @juliantodiamond9135
      @juliantodiamond9135 4 роки тому

      The traffic is passthrough the 2 or more vpn and load balance. If use 3 isp then i will use 3 vpn.
      The real case is you have 3 isp and if traffic want to pass must using vpn tunnel. And we use load balance. And the traffic come in and out from 1 bridge.

  • @jermainebrown8615
    @jermainebrown8615 5 років тому +1

    This method is not working with Netflix

    • @SteveoceeCoUk
      @SteveoceeCoUk  5 років тому +1

      Probably won't work with Netflix. You need to remember that Netflix has a huge CDN which won't be named netflix.com so the rules won't catch. for Netflix you're better specifying the IP of the device you want to take the tunnel or trying some L7 matching rules.

    • @jermainebrown8615
      @jermainebrown8615 5 років тому

      @@SteveoceeCoUk would be nice if you create video about this 😏

    • @pututmargono
      @pututmargono 4 роки тому

      @@SteveoceeCoUk I change addresslist with L7, still not route netflix to VPN. I don't know what I miss. hope you can create video how to do that 😊

    • @SteveoceeCoUk
      @SteveoceeCoUk  4 роки тому

      @@pututmargono Please see comments above. Netflix uses multiple CDN and content caches so every connection won't be tagged with "Netflix" in the URL. I was incorrect in my reply above, L7 probably won't work. You may be able to tag the connection rather than packet which may give you a better result but I still wouldn't guarantee that would work.