7 ms·
Mikrotik router as OpenVPN Client
- pingec 10y agoQuite handy. If anyone has OpenWrt hardware like me, OpenVpn clients and servers work good enough and the setup is well documented: https://wiki.openwrt.org/doc/howto/vpn.openvpn https://wiki.openwrt.org/doc/howto/vpn.openvpn
- machbio 10y agoFor a beginner - I would suggest DD-wrt as its more beginner friendly as compared to Open-Wrt; OPENVPN documentation is pretty good - https://www.dd-wrt.com/wiki/index.php/OpenVPN https://www.dd-wrt.com/wiki/index.php/OpenVPN As for Router support - the best one would be the Archer C7 from TPLink (http://www.dd-wrt.com/wiki/index.php/Supported_Devices#TP-Link http://www.dd-wrt.com/wiki/index.php/Supported_Devices#TP-Li...)
- vetinari 10y agoJust make sure, what batch of C7s are you buying from. TPLink started to lock down the firmware, due to the new regulation about locking down wifi devices. So if you get an unlocked C7, you are fine, if locked, you get to keep their firmware on the device. Currently, the only safe choices for OpenWRT are Linksys WRT1900ACS and Turris Omnia. Both are a bit pricier.
- machbio 10y agoThey are selling the C7 v2's as of now from amazon - dd-wrt has the firmware for it..
- proctor 10y agoI help maintain a page[0] that keeps a list of the best performing routers that support OpenWRT and DD-WRT. It allows to sort by Value, Performance or Price. [0] http://rooftopbazaar.com/routerfirmware/ http://rooftopbazaar.com/routerfirmware/
- orf 10y agoI have a friend who's part of a startup here in the UK that makes routers for gamers called NetDuma[1]. The routers they sell have a VPN client like this ready to go, I've got one and it works well. 1. http://www.netduma.com/ http://www.netduma.com/
- r1ch 10y agoThese are actually Mikrotik devices too, just with OpenWRT pre-installed instead of their proprietary RouterOS.
- Mic92 10y agoMikrotik's support for OpenVPN/IPsec is a joke. They should just allow to specify plain openvpn configuration instead. I would not recommend these routers with original firmware.
- methou 10y agoCouldn't agree more, no TLS Key for OpenVPN, and still no IKEv2.
- r1ch 10y agoNo UDP support after all these years is really quite shameful. Tunneling TCP over TCP is insanely bad, the slightest packet loss and your connections are toast.
- snowwindwaves 10y agostill not? I was moaning about this in 2006. I can't imagine why Mikrotik can't be bothered to implement UDP for OpenVPN when they have added so many other features. This is my #1 gripe with mikrotik, you can't figure out if the feature you want to use is half-baked or not without testing it. And then once it works you had better not upgrade versions or it may very well break. Finding a version which has all the features you need working used to be a nightmare.
- tjohns 10y agoMy understanding is that MikroTik isn't a fan of OpenVPN (for whatever reason), and doesn't want to spend any more development time on the feature. Which is a shame, because it really is a poor choice without UDP support. On the plus side, you can use the VM ("Metarouter") feature to host a real OpenVPN client inside an OpenWRT instance. But you don't get the nice admin console if you do that.
- sathackr 10y agoYea...this is a problem with them. I recently spent several hours trying to implement BFD...only to find out it's broken on CCR, known to be broken, and won't be fixed any time soon [1] But to be fair, I've run across similar things in Cisco land. Spend hours trying to get something to work, when I finally run across an single line somewhere on their site that says what I'm trying to do doesn't work with CEF and I have to disable CEF if I want it to work. Which cuts my throughput by 10x. [1] http://forum.mikrotik.com/viewtopic.php?t=108280 http://forum.mikrotik.com/viewtopic.php?t=108280
- vxxzy 10y agoYou can run OpenWRT as a virtual router (MetaRouter) on top of Mikrotik. That would allow you to get around the TCP limit. Does anyone have any experience with running OpenWRT as a MetaRouter?
- tjohns 10y agoI've done it. It works fine. You just have to keep in mind that most of the Routerboard products have limited RAM, like any other embedded device. The only catch is that anything done inside of OpenWRT has to be configured by hand from a terminal (obviously), instead of through Mikrotik's admin console.
- girzel 10y agoI bought a Mikrotik a month or two ago, expressly so I could install OpenWRT on it, and use it to get around the Chinese firewall with Shadowsocks. The OpenWRT install never worked, so now I just have a (pretty nice) router, doing what routers are supposed to do. It's long since that OpenVPN didn't work in China, but this should provide a good learning experience, and who knows, maybe it will lead me to something that works.
- netheril96 10y agoTo get around GFW, use openconnect instead. That is as or more secure than OpenVPN, and not current filtered.
- vetinari 10y ago> That is as or more secure than OpenVPN How does it achieve that? They both use TLS, in both, you can pick your ciphers. Additionaly, they both use OpenSSL, which is often found buggy and the ciphers are not hw accelerated.
- zurn 10y agoOpenVPN uses its own non-TLS UDP protocol to carry traffic (with an optional TCP fallback), and only uses TLS for connection setup. ref: https://wiki.wireshark.org/OpenVPN https://wiki.wireshark.org/OpenVPN
- netheril96 10y agoOpenVPN does not support many of the more secure ciphers in TLS, while openconnect does.
- ddeck 10y agoFWIW I've never had any issues with OpenVPN tunneled over SSH
- NetStrikeForce 10y agoApparently SoftEther works really well for that and the developers have a free VPN service called vpngate. Worth a try? :-)
- machbio 10y agojust want to suggest this script for OPENVPN setup - much easier to setup for multiple clients - https://github.com/Nyr/openvpn-install https://github.com/Nyr/openvpn-install
- fluential 10y agoBe aware that very few routers actually have enough power to do openvpn encryption with higher bandwith (20Mbit+) links and 256CBC encryption. You may get better results by downgrading your cipher (not every vpn provider supports that) To achieve good performance you are looking for hardware with Intel QuickAssist, I would recommend putting pfsense on something like http://store.netgate.com/ADI/RCC-VE-2440.aspx http://store.netgate.com/ADI/RCC-VE-2440.aspx
- kyrra 10y agoI actually just built one with a C2758 (8 core atom) supermicro board. I put PFsense on it and it's been running great. I have gigabit internet at home, so I opted for the more powerful box. A lot of people on the pfsense forums seem to use one form of these boards. 2 core: http://www.supermicro.com/products/motherboard/Atom/X10/A1SRi-2358F.cfm http://www.supermicro.com/products/motherboard/Atom/X10/A1SR... 4 core: http://www.supermicro.com/products/motherboard/Atom/X10/A1SRi-2558F.cfm http://www.supermicro.com/products/motherboard/Atom/X10/A1SR... 8 core: http://www.supermicro.com/products/motherboard/Atom/X10/A1SRi-2758F.cfm http://www.supermicro.com/products/motherboard/Atom/X10/A1SR...
- ausjke 10y agoMikrotik was pre-Ubnt and had excellent hardware lineups. These days Ubnt is miles ahead in the router/wireless-board field, which puzzled me. While Mikrotick sells its RouterOS, it's not that hard to install Openwrt on it. Ubnt was quite Openwrt friendly at the start, not so any more. These days I'm just assembling my own x86 routers. PCengines and Soekris do not have the best performance/price ratio nowadays, and they somehow just feel a bit out of date.
- sathackr 10y agoI have personally deployed about 100 Mikrotik routers and can say they work well for what they do. They're not designed to be a home router and the learning curve if you want to use one like that would be similar to someone without Cisco IOS knowledge trying to configure a Cisco IOS device as a home router. Not many routers can do 5-10gb/s+ throughput for the price. Their most recent model has 8x10Gb ports, costs USD $2,500 and will route the full 80gb/s [1] They have come a long way since the RB433 and running on Soekris/PCEngines boards. UBNT is just getting started in the real router field(Not their Radio-with-a-router, those are quite mature now but very limited in features) and I do not care for their current EdgeRouter UI. It's a mess. For example: You need local access just to add the interface you're accessing it from to a bridge. (Because you can't add an interface WITH an IP on it to a bridge, and you can't remove the IP from the interface without losing access. You can apply multiple commands at once, but the command validation doesn't honor the order that you enter them, thus tosses an error because it tries to add the interface to the bridge before removing the IP) Sure you can put something x86 together and run one of the many many firewall/routing OSes, or even roll your own with (pick your flavor)Linux, Zebra and IPTables, but I don't have time to make something work and prefer something that just works and isn't priced at the Cisco/Juniper level. I wouldn't recommend either for mission-critical ENTERPRISE grade routing, without significant planning into redundancy, but, if you are doing things at that level, then you probably have the funds to purchase enterprise grade gear. [1] http://www.stubarea51.net/2015/10/09/mikrotik-ccr1072-1g-8s-review-part-3-80-gbps-throughput-testing/ http://www.stubarea51.net/2015/10/09/mikrotik-ccr1072-1g-8s-...
- walrus01 10y ago
- nathanvanfleet 10y agoAt one point I was kind of excited about Mikrotik routers. They seemed pretty beefy, a bit pricey, but cool as a device support OpenWRT and having an OS that they said was "even better" than OpenWRT. However everything I looked at was somewhat disappointing. One router I was looking at had an unpowered USB port, that was a low speed (USB 1), which just seemed to be a weird caveat when consumer routers of the time were all USB-2 and capable of running at least a small pocket hard drive or at least mount a USB key. At this point there seems to be a lot of good commercial routers which are strong, cheap, and don't require much blob code etc and are easy to find (sometimes it was vague what kind of chips you'd get with different commercial hardware).
- sathackr 10y agoMikrotik routers are not designed to be a consumer router. The average consumer would pull his/her hair out trying to configure one. Providing network attached storage is generally not a feature requested of anything but the full-consumer line home routers of the type that you purchase from Best Buy etc...
- tomaac 10y agoThat is not quite true. They have soho product group: http://routerboard.com/products/group/20 http://routerboard.com/products/group/20
- sathackr 10y agoI was not aware they were marketing in that direction...imo they shouldn't be, for the reasons listed by others. The UI just isn't quite intuitive enough for the average-joe that's expecting something like a Linksys/Beldin interface.
- benjohnson 10y agoThe newer firmware also has a single-page setup that let you set the WAN/LAN IP, DHCP server and other basic stuff with ease. Basic port forwarding is still interesting - it's simple once you understand MikroTik, but there's a learning curve.
- jeffdubin 10y agoI started using pfSense on itx Intel-based hardware and have been quite happy with the results, though using it with modern hardware (recommended with today's faster broadband speeds) means it's usually a little pricier than most consumer devices. Now there's news that the pfSense team is working on a small, ARM-based device which sounds like it'd give Miktotik devices competition. If you can hold out a bit, it might be worth the wait.
- jlgaddis 10y agoI'm a network engineer for an ISP (5 years now; ~8 years in the same role at a .edu before this) and I am very much in the Cisco/Juniper camp. When I started at the ISP, I had never even heard of Mikrotik. Having been using high-end Cisco/Juniper gear for years, I was quite skeptical that those cheap little Mikrotiks were worth a damn. I've actually been quite surprised. While all of my "critical" infrastructure runs on Cisco, I've got several Mikrotik routers running in production, almost exclusively as access concentrators (for PPPoE sessions). I really use very little of their features, but they handle PPPoE and OSPF just fine. We also have an MSP side, which is mostly our ISP customers whom we also handle managing their local networks for. Our guys have deployed a handful of Mikrotiks at the edge of these customer networks as well but, again, this is just basic office router functionality (DHCP, NAT, firewalling, etc.). For the price point, they're actually pretty decent devices. I don't own any myself (excluding a couple in my "networking test lab" here at home, but those belong to $work) and wouldn't personally use one. This is mostly on principle -- I disagree with their beliefs when it comes to the GPL and compliance. Also, I wouldn't recommend using them for anything you deem "critical" or even "really important". Just read through the Changelogs for their firmware releases -- some of the bugs/fixes do not instill confidence in their software engineering. FWIW, my router at home (on a fiber connection) is (was?) designed and sold as a RouterOS device [0], although I removed the Mikrotik CF card and replaced it with another one that I installed an OpenBSD image onto [1]. It's mounted read-only (except when I want to modify things, of course) to preserve the lifetime but lately, I've been considering installing an SSD into it. It's actually a pretty powerful (albeit low-end) PC disguised as a router. It can easily provided all the basic network services one might need at home (DHCP, DNS, NAT, firewalling, TFTP, etc.). It wasn't cheap, though -- $600, IIRC, but it's a few years old now. I wrote a bit more about it [2] a few months ago. [0]: http://www.balticnetworks.com/docs/routermaxx%206%20port.pdf http://www.balticnetworks.com/docs/routermaxx%206%20port.pdf (PDF) [1]: http://www.nmedia.net/flashrd/ http://www.nmedia.net/flashrd/ [2]: https://news.ycombinator.com/item?id=10796573 https://news.ycombinator.com/item?id=10796573
- sarahtaylor01 10y agogood site