Unveiling the Best VPN for MikroTik Routers

  Рет қаралды 37,695

The Network Berg

The Network Berg

Күн бұрын

Пікірлер: 49
@gunchag
@gunchag 2 жыл бұрын
Great comparision! Thak you! In my opinion you missed to mention one important thing about L2TP/IPsec. In Mikrotik environment is old issue that clients reaching the server via NAT do work but only one at a time per each public address.
@netrionio1
@netrionio1 2 жыл бұрын
My man, my pro it teacher , I hail you and greetings from Greece! I have a fast internet connection but no access to public IP in my first WAN . My second WAN has slow internet connection and I have it as a backup. So Zerotier was a lifesaver ! I really admire you and I deeply appreciate what you do. Keep up the good work. Thumbs up!
@charalamposparlaloglou6863
@charalamposparlaloglou6863 2 жыл бұрын
I Just deployed a wireguard mesh vpn network between 7 sites and many road warriors clients. Performance speed touches 98% of line bandwidth and latency is awesome .
@khwezidushu
@khwezidushu 7 ай бұрын
Is Cisco anyconnect any different?
@nezu_cc
@nezu_cc 2 жыл бұрын
Mikrotik for life. ZeroTier is awesome but It managed to bork itself on 2 of my production systems already (1 windows and 1 linux box). Rock solid of MT though. Wiregaurd is my go-to nowadays if I have a public IP accessible somewhere. Super fast, super simple, and using a modern stream cipher.
@Darkk6969
@Darkk6969 Жыл бұрын
Love Wireguard that I'm using in pfsense. I've always wondered how reliable and stable ZeroTier is since you're relying on their infrastructure. I rather run Wireguard myself on my own network so I wouldn't have to worry about cloud services going down.
@jembodo
@jembodo 2 жыл бұрын
Was using L2TP + IPsec because of native Mac and Windows support for a while until Wireguard came along. Now I primarily use Wireguard on MT and OpenVPN on another server as backup.
@karlmarks9885
@karlmarks9885 Жыл бұрын
Hello, Johnny! Appreciate your work and talent of presentation. May I kindly ask you to specify few things? 1. L2TP was tested with ipsec, right? 2. You wrote “Unable to test” for IKEv2 in a table. Do you mean - tests failed in browser? Did “speedtest”/”fast” webpages load with no errors? 3. I’ve noticed poor results for PPTP. Maybe you have some thoughts about it (despite of low CPU/memory requirements pptp loses to others)? Have you ever tried to establish PPTP tunnels from some other locations? Thank you so much in advance.
@drumer2142
@drumer2142 2 жыл бұрын
Your video right on time for me. I was wondering what to use and because you have the experience I can tell that you know what you are talking about. Thanks you and keep up the good work !!!
@TandSylvester
@TandSylvester 2 жыл бұрын
Thank you for the awesome video. Really appreciate the effort with the comparisons. Perhaps do show things like the IPIP, EoIP tunnels as well as the dynamic routing protocols. Really love the content and keep it going!!!!
@steveb1739
@steveb1739 2 жыл бұрын
Thanks Meneer, very informative. Using Wireguard here in the UK, to access the office NAS from my phone, inter alia.
@barnaczukor4235
@barnaczukor4235 4 ай бұрын
I want to connect two locations with VPN, but both lack the static IP address. However DDNS is working for both places and clients can connect to both routers easily. Can I use IPSEC with two DDNS enabled routers? If not, which protocol do you recommend for permament connection? Thanks for your answer.
@pbrigham
@pbrigham 2 жыл бұрын
ZeroTier here as well, the piece of mind of not having any ports open is just unbeatable.
@RuhollahNoruzi
@RuhollahNoruzi Жыл бұрын
can you tell about install v2ray protocol on microtik? thanks
@bandzo87
@bandzo87 Жыл бұрын
Bcs I have CHR as main location I'm stuck with wireguard and cant complain. Works very well, but we will see how it hold hundreads off peers. For older V6 routers we still use l2tp but with ipsec.
@Anavllama
@Anavllama 2 жыл бұрын
Zerotier is excellent if you have two endpoints (routers) that do not have publicly accessible IPs. Limits, yes ARM devices but also dependency on third party servers. It can handle complex scenarios and wide variety of needs. Wireguard is maybe a bit faster but its strength is relatively easy to setup and it is truly independent. Never used OPENVPN and will never see myself needing to use it and not completely implemented in MT OS anyway. Where things get interesting which no one addresses head on is the issue of MTU which manifests in no browsing, slow browsing or some website not reachable. For example in wirguard, ensure ICMP is not blocked first and foremost. One method to address this is to try putting the MTU from default 1420 to 1500 on both client and server ends, or mangle/MSS clamping on the client side, OR............ MRRU finessing by using an unencrypted L2TP tunnel within an encrypted wireguard tunnel to send ones data. L2TP settings allow MRRU through MLPPP. One uses the very basic L2TP settings and ensures MRRU is set at 1504 at both ends of the L2TP connection. Dont use pptp................. no reason to.
@brandonbrand2338
@brandonbrand2338 Жыл бұрын
ZT Rocks man! It get's my vote indeed. Nice video Network Berg
@thepcfd
@thepcfd Жыл бұрын
can you make video how to make openvpn on miktorik in router os 7 with extracking ovpn file form it and ppp profile?
@Richard-kl8wr
@Richard-kl8wr 2 жыл бұрын
its possbiel to create sito to site via Wireguard ? for example to cloud ( Mikrotik - Linux Machine )
@TheNetworkBerg
@TheNetworkBerg 2 жыл бұрын
Yes, totally viable and many people will do stuff like that
@martinmasera8887
@martinmasera8887 2 жыл бұрын
Thank Berg for very nice video. I used Zerotier, but not happy with speed, only around 25Mbits.
@AlirezaNikyar
@AlirezaNikyar 2 жыл бұрын
Please teach about open VPN settings of ExpressVPN company on mikrotik
@Ripperua
@Ripperua Жыл бұрын
@The Network Berg Hi there i've issue with L2TP+IPSEC latency +3-5ms compared to direct ping side to client plus little fluctuating +2-3ms. Is there any advices where to dig to?
@vedatyilmaz4577
@vedatyilmaz4577 Жыл бұрын
One more great, very informative video, thanks.
@maaknlani1
@maaknlani1 2 жыл бұрын
Hou nie van Mikrotik, but can't deny its a good product. Use raspberry with wireguard for port customizations.
@ZagatoZee
@ZagatoZee 2 жыл бұрын
Thanks for this. Makes me feel better about waiting for an ARM based MikroTik device for my primary usege. I have a MikroTik mAP (both lite and non lite versions actually) to play with while I wait on the Arm based AX models being available in my region. I'd like to setup a VPN that my friends in other countries can use to avoid region restrictions, but NOT give them any access to my home network. mAP would have to be behind an ISP modem. Is this possible? Is there an ELI5 guide for this anywhere? It seems that all VPN guides are for the (etirely normal) setup: secure access to the network. I just want it for geolocation avoidance - not local network access. Any pointers on how one could accomplish this?
@sayem4you
@sayem4you 8 ай бұрын
please make a IKE2 VPN server for android..because android now support only ike2 vpn. struggling to make a ike2 vpn server ...
@kirksteinklauber260
@kirksteinklauber260 2 жыл бұрын
Nice video!! Any VPN using TCP will suffer what is called TCP meltdown (TCP inside from the app in another TCP like the VPN tunnel creates) that impacts badly the throughput so stay away of TCP VPNs such as SSTP or OVPN over TCP
@ShaneFromSA
@ShaneFromSA Жыл бұрын
Can you run Zerotier and Wireguard on the same router at the same time? If I enable Zerotier package, wireguard no longer works.
@jankalisek5508
@jankalisek5508 Жыл бұрын
Yes, you can. I have on my RB5009 2 instances of Zerotier (one for RoadWarriors and 1 as HUB-Spokes VPN) plus Wireguard as site-to-site VPN for older Mikrotik router.
@brodie7838
@brodie7838 2 жыл бұрын
I had ZT fully working across 5 sites and it was amazing just like you said. Then I disabled the ZT interface in WinBox in one of the site configs and the whole thing suddenly tanked, and I've never been able to get it working again and been using SSTP in its place for now. I'm genuinely baffled.
@rolandomota7474
@rolandomota7474 2 жыл бұрын
did you figured out? maybe in the ZT forums somebody can help.
@haydenbarker5049
@haydenbarker5049 Жыл бұрын
Hi there ! I was wondering if you were in a position to do a video, or comment on, the ability to do 2FA/MFA with Mikrotik VPN's. Websites like rublon and miniOrange seem to provide the services.
@TheNetworkBerg
@TheNetworkBerg Жыл бұрын
Definitely an interesting topic, unfortunately I have never needed to deploy MFA to MikroTik VPN users in my own production network. But I would like to see if this can be done on MikroTik, perhaps with the aid of some scripting on it, it may be doable. If I do figure it out I will definitely make a video on the subject.
@haydenbarker5049
@haydenbarker5049 Жыл бұрын
@@TheNetworkBerg there is a free trial for MiniOrange with no credit card required... 2FA is becoming fairly standard request it would seem.
@haydenbarker5049
@haydenbarker5049 Жыл бұрын
@@TheNetworkBerg I need it for a client project coming up in January.. I'll do my best to keep you posted as well.. you have been of so much help to me !
@urZcszyYo3TMEDmW
@urZcszyYo3TMEDmW 2 жыл бұрын
Why mikrotik doesn't implement zerotier to other platforms other than ARM, any ideas?
@TheNetworkBerg
@TheNetworkBerg 2 жыл бұрын
I honestly do not have any idea, I would have thought that at the very least that virtual devices like x86 or CHR would support it, maybe one day it will but only MikroTik can really answer it and on their forums they just state that there are no plans for Zerotier on any other architecture
@dhiaahmed5420
@dhiaahmed5420 2 жыл бұрын
Great information
@TheNetworkBerg
@TheNetworkBerg 2 жыл бұрын
Glad you think so!
@antoniomax3163
@antoniomax3163 2 жыл бұрын
pls more about sstp on mikrotik. also sert
@rolandomota7474
@rolandomota7474 2 жыл бұрын
can you connect to a sonicwall vpn ?
@TheNetworkBerg
@TheNetworkBerg 2 жыл бұрын
You can definitely create VPN tunnels to Sonicwalls, IKEv2 should work just fine.
@creepr524
@creepr524 2 жыл бұрын
ROS v7 sucks tho. It wont register OSPF LSAs from v6 devices :(
@rolandomota7474
@rolandomota7474 2 жыл бұрын
idk why mikrotik made ROS V7 not compatible with V6 ...that sux big time , some stuff do not play well between versions , i have friends who have big setups runing on V6 cause it is a PiTA to start over changing all net config if they upgrade to V7
@testaccount-xl3ki
@testaccount-xl3ki 2 ай бұрын
ipsec will never go away. Everything support it😂
@netcip
@netcip 7 ай бұрын
The most garbage routers you can buy on the market.
Build your own Cloud-Based VPN Server with MikroTik in minutes!
32:29
The Network Berg
Рет қаралды 25 М.
Tailscale VS Zerotier
25:33
Lawrence Systems
Рет қаралды 129 М.
ТВОИ РОДИТЕЛИ И ЧЕЛОВЕК ПАУК 😂#shorts
00:59
BATEK_OFFICIAL
Рет қаралды 2,9 МЛН
Человек паук уже не тот
00:32
Miracle
Рет қаралды 4 МЛН
ЛУЧШИЙ ФОКУС + секрет! #shorts
00:12
Роман Magic
Рет қаралды 31 МЛН
Из какого города смотришь? 😃
00:34
МЯТНАЯ ФАНТА
Рет қаралды 1,6 МЛН
Dynamic Routing with Wireguard, Optimize your MikroTik network!
25:55
The Network Berg
Рет қаралды 21 М.
DO NOT design your network like this!! // FREE CCNA // EP 6
19:36
NetworkChuck
Рет қаралды 3,3 МЛН
Is your MikroTik vulnerable...?
19:43
The Network Berg
Рет қаралды 15 М.
☁️Easy IPSEC Site-To-Site VPN Guide, MikroTik ROSv7☁️
30:21
The Network Berg
Рет қаралды 73 М.
Subnet Routers | Tailscale Explained
12:25
Tailscale
Рет қаралды 39 М.
What is VPN? And what it is not.
5:46
MikroTik
Рет қаралды 7 М.
Securely Access Your Home Network with WireGuard VPN on OPNsense
25:39
Home Network Guy
Рет қаралды 17 М.
Set Up Secure VPN in Minutes with GL.iNet Routers!
19:54
Crosstalk Solutions
Рет қаралды 82 М.
FREE Domain and SSL for Local Network | Nginx Proxy Manager on Docker - #13
16:22
Tech - The Lazy Automator
Рет қаралды 59 М.
ТВОИ РОДИТЕЛИ И ЧЕЛОВЕК ПАУК 😂#shorts
00:59
BATEK_OFFICIAL
Рет қаралды 2,9 МЛН