<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title>Mikrotik.moscow [тема: L2TP-сервер.]</title>
		<link>http://mikrotik.moscow</link>
		<description>Новое в теме L2TP-сервер. форума RouterOS на сайте Mikrotik.moscow [mikrotik.moscow]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Thu, 06 Aug 2026 03:55:43 -0400</pubDate>
		<item>
			<title>L2TP-сервер.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277130">L2TP-сервер.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Для полноты картины упомянем, что клиентский PPTP тоже не особо дружит с NAT. Если PPTP-клиент находится за NAT-устройством, то этому устройству потребуется специальная поддержка PPTP в его NAT-коде, если более одного PPTP-клиента должен проходить через NAT-устройство одновременно. У большинства очень дешёвых DSL/Cable NAT-роутеров для домашнего пользователя с этим возникают проблемы – большинство их реализаций NAT настолько сломаны, что они могут затягивать чёрные дыры через нанотрубки. <br />
			<i>26.08.2005 10:31:00, tneumann.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277130</link>
			<guid>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277130</guid>
			<pubDate>Fri, 26 Aug 2005 10:31:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>L2TP-сервер.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277129">L2TP-сервер.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Пока вам не требуется использовать IPSEC по техническим причинам, чтобы отключить его, нужно изменить ключ реестра на всех клиентских ПК. Это нарушит весь остальной IPSEC-трафик на этом ПК. Поэтому я предпочитаю PPTP, пока MT не будет поддерживать NAT-T. Это намного проще. С уважением, Andrew. <br />
			<i>26.08.2005 07:48:00, andrewluck.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277129</link>
			<guid>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277129</guid>
			<pubDate>Fri, 26 Aug 2005 07:48:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>L2TP-сервер.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277128">L2TP-сервер.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Тебе никто не заставляет использовать IPSec. <br />
			<i>26.08.2005 06:41:00, normis.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277128</link>
			<guid>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277128</guid>
			<pubDate>Fri, 26 Aug 2005 06:41:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>L2TP-сервер.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277127">L2TP-сервер.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			L2TP работает с NAT без проблем, да, но как только он оказывается внутри IPsec, и тут уже то, о чем говорит Эндрю, приходится спорить о дружественности IPsec к NAT… –Том. <br />
			<i>26.08.2005 06:37:00, tneumann.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277127</link>
			<guid>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277127</guid>
			<pubDate>Fri, 26 Aug 2005 06:37:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>L2TP-сервер.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277126">L2TP-сервер.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Трассировка NAT не поддерживается на MT L2TP сервере (если я что-то не упустил в версии 2.9). Там нет ничего для поддержки, L2TP сам по себе дружелюбен к NAT. Это не как PPTP. Так что твой комментарий не соответствует действительности. <br />
			<i>26.08.2005 05:57:00, normis.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277126</link>
			<guid>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277126</guid>
			<pubDate>Fri, 26 Aug 2005 05:57:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>L2TP-сервер.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277125">L2TP-сервер.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Трассировка через NAT не поддерживается на MT L2TP сервере (если я что-то не упустил в версии 2.9). С учетом этого, PPTP имеет больше шансов заработать. С уважением, Andrew. <br />
			<i>25.08.2005 16:50:00, andrewluck.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277125</link>
			<guid>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277125</guid>
			<pubDate>Thu, 25 Aug 2005 16:50:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>L2TP-сервер.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277124">L2TP-сервер.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Насколько я знаю, Windows использует IPsec для защиты L2TP-туннелей. Ты можешь либо отключить IPsec для L2TP на машине с W2K (какой-то замудренный ключ реестра, спроси у Google), либо настроить RouterOS, чтобы он тоже использовал IPsec. Самый быстрый способ сделать это – выполнить следующую команду: /ip ipsec peer add address=&lt;IP-адрес машины с W2K&gt; secret=&lt;IPsec-секрет, который ты настроил на машине с W2K&gt; generate-policy=yes И, конечно, тебе стоит знать, как настроить IPsec на стороне Windows. <br />
			<i>25.08.2005 07:19:00, Eugene.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277124</link>
			<guid>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277124</guid>
			<pubDate>Thu, 25 Aug 2005 07:19:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>L2TP-сервер.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277123">L2TP-сервер.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я выполнил все инструкции ниже. Теперь как заставить машину с Windows 2000 подключиться к этому? Нужно ли настраивать что-то в разделе /ip ipsec? Стоит ли использовать что-то другое? Я пытаюсь использовать клиентский ПК и подключить его к Tik-боксу, который обеспечит безопасное соединение с LAN-стороной Tik-бокса.<br /><br />**Подключение удалённого клиента через L2TP-туннель**<br /><br />Следующий пример показывает, как подключить компьютер к сети удалённого офиса через L2TP-шифрованный туннель, предоставив этому компьютеру IP-адрес из той же сети, что и удалённый офис (без необходимости создания туннелей EoIP). Пожалуйста, ознакомьтесь с соответствующим руководством по настройке L2TP-клиента с помощью используемого вами программного обеспечения.<br /><br />Роутер в этом примере:<br /><br />* &nbsp; [RemoteOffice]<br /> &nbsp; &nbsp;* &nbsp; Интерфейс ToInternet 192.168.81.1/24<br /> &nbsp; &nbsp;* &nbsp; Интерфейс Office 10.150.1.254/24<br /><br />Клиентский компьютер может получить доступ к роутеру через Интернет. На L2TP-сервере должен быть создан пользователь для клиента:<br /><br />* &nbsp; [admin@RemoteOffice]<br /> &nbsp; &nbsp;* &nbsp; ppp secret&gt; add name=ex service=l2tp password=lkjrht local-address=10.150.1.254 remote-address=10.150.1.2<br />* &nbsp; [admin@RemoteOffice]<br /> &nbsp; &nbsp;* &nbsp; ppp secret&gt; print detail<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; Flags: X - disabled<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; 0 name=“ex” service=l2tp caller-id=“” password=“lkjrht” profile=default local-address=10.150.1.254 remote-address=10.150.1.2 routes==“”<br />* &nbsp; [admin@RemoteOffice]<br /> &nbsp; &nbsp;* &nbsp; ppp secret&gt;<br />Затем пользователь должен быть добавлен в список L2TP-сервера:<br /><br />* &nbsp; [admin@RemoteOffice]<br /> &nbsp; &nbsp;* &nbsp; interface l2tp-server&gt; add name=FromLaptop user=ex<br />* &nbsp; [admin@RemoteOffice]<br /> &nbsp; &nbsp;* &nbsp; interface l2tp-server&gt; print<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; Flags: X - disabled, D - dynamic, R - running<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; NAME &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; USER &nbsp; &nbsp; &nbsp; &nbsp; MTU &nbsp; CLIENT-ADDRESS &nbsp;UPTIME &nbsp; ENC…<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; 0 &nbsp; &nbsp; FromLaptop &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ex<br />* &nbsp; [admin@RemoteOffice]<br /> &nbsp; &nbsp;* &nbsp; interface l2tp-server&gt;<br />И сервер должен быть активирован:<br /><br />* &nbsp; [admin@RemoteOffice]<br /> &nbsp; &nbsp;* &nbsp; interface l2tp-server server&gt; set enabled=yes<br />* &nbsp; [admin@RemoteOffice]<br /> &nbsp; &nbsp;* &nbsp; interface l2tp-server server&gt; print<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; enabled: yes<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; mtu: 1460<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; mru: 1460<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; authentication: mschap2<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; default-profile: default<br />* &nbsp; [admin@RemoteOffice]<br /> &nbsp; &nbsp;* &nbsp; interface l2tp-server server&gt;<br />Наконец, необходимо включить прокси ARP на интерфейсе ‘Office’:<br /><br />* &nbsp; [admin@RemoteOffice]<br /> &nbsp; &nbsp;* &nbsp; interface ethernet&gt; set Office arp=proxy-arp<br />* &nbsp; [admin@RemoteOffice]<br /> &nbsp; &nbsp;* &nbsp; interface ethernet&gt; print<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; Flags: X - disabled, R - running<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; NAME &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; MTU &nbsp; MAC-ADDRESS &nbsp; &nbsp; &nbsp; ARP<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; 0 &nbsp;R ToInternet &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1500 &nbsp;00:30:4F:0B:7B:C1 enabled<br /> &nbsp; &nbsp; &nbsp; &nbsp;* &nbsp; 1 &nbsp;R Office &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1500 &nbsp;00:30:4F:06:62:12 proxy-arp <br />
			<i>24.08.2005 21:16:00, wkm001.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277123</link>
			<guid>http://mikrotik.moscow/forum/forum57/70043-l2tp_server./message277123</guid>
			<pubDate>Wed, 24 Aug 2005 21:16:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
	</channel>
</rss>
