Home > Articles > Networking > Routing & Switching

Creating a VPN Server with RouterOS

  • Print
  • + Share This
Eric Geier,author of Wi-Fi Hotspots: Setting Up Public Wireless Internet Access, continues his RouterOS series by discussing its VPN capabilities. He shows you how to configure everything so you can remotely connect to access files. You’ll also learn how to set up site-to-site tunnels so you can create a WAN and connect all your locations.
Editor's Note: You may also be interested in Eric's first RouterOS article, Turn an Old PC into a LAN Server with RouterOS, Part 1.
Like this article? We recommend

Two earlier tutorial articles discussed RouterOS, an open source operating system that can convert your generic PC into an advanced, enterprise-type router and LAN server.

In Part 1 of that series, you built the machine, installed the Linux-based software, and started setting it up.

In Part 2, you configured the DHCP server to manage the IP addresses, enabled NAT to share the Internet, and configured the wireless interface for Wi-Fi access.

Now that all the basic setup is done, you can play around with the features. In this part, you’ll tinker around with the VPN capabilities.

More specifically, you’ll set up a L2TP/IPsec VPN server.

Then users can remotely connect via the Internet to access files through the tunnel or to just use it to secure their connection on a public network.

Plus you’ll configure site-to-site tunnels, so all your networks are connected.

Configuring the VPN (L2TP) Server

First, make sure that you have the PPP package installed. If it is, you’ll have a menu for it on the console or WinBox interface.

Then you can follow these steps to get the server working using the WinBox utility:

  1. Click PPP and select the Secrets tab.
  2. Click the Plus button.
  3. Enter a Name and Password.
  4. Enter a Local Address (such as and Remote Address (such as
  5. Click OK.

Now you can enable the server. Follow these steps:

  1. On the main PPP window, select the Interface tab.
  2. Click the L2TP Server button.
  3. Mark the Enabled checkbox and click OK.

Now you need to add an IPSec peer. Follow these steps:

  1. Click IP > IPsec and select the Peer tab.
  2. Click the Plus button.
  3. Make sure that the Auth Method is Pre-Shared Key.
  4. For Secret, enter a password to serve as the pre-shared key secret. You'll input this later when configuring Windows.
  5. Verify that the Hash Algorithm is sha and the Encryption Algorithm is 3des, which are used by default in Windows.
  6. Mark the Generate Policy checkbox.
  • + Share This
  • 🔖 Save To Your Account