

Set html-directory=flash/hotspotĪdd connection-mark=ProtonVPN name=ProtonVPN responder=no src-address-list=\Īdd dh-group=modp4096,modp2048,modp1024 dpd-interval=disable-dpd \Įnc-algorithm=aes-256 hash-algorithm=sha256 name=ProtonVPNĪdd address=nl. exchange-mode=ike2 name=ProtonVPN profile=\Īdd auth-algorithms=sha256 enc-algorithms=aes-256-cbc name=ProtonVPN \Īdd name=VL20_POOL ranges=10.0.20.100-10.0.20.200Īdd name=V元0_POOL ranges=10.0.30.100-10.0.30.200Īdd name=VL40_POOL ranges=10.0.40.100-10.0.40.200Īdd name=BASE_POOL ranges=192.168.10.100-192.168.10.200Īdd address-pool=VL20_POOL disabled=no interface=VL20_VPN name=VL20_DHCPĪdd address-pool=V元0_POOL disabled=no interface=V元0_CLRNET name=V元0_DHCPĪdd address-pool=VL40_POOL disabled=no interface=VL40_IOT name=VL40_DHCPĪdd address-pool=BASE_POOL disabled=no interface=BASE_VLAN name=BASE_DHCPĪdd bridge=BR1 frame-types=admit-only-vlan-tagged ingress-filtering=yes \Īdd bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged interface=\Īdd bridge=BR1 tagged=BR1,ether2,ether3,ether4 untagged=ether5 vlan-ids=10Īdd bridge=BR1 tagged=BR1,ether2,ether3,ether4 vlan-ids=20Īdd bridge=BR1 tagged=BR1,ether2,ether3,ether4 vlan-ids=30Īdd bridge=BR1 tagged=BR1,ether2,ether3,ether4 vlan-ids=40Īdd address=192.168.10.1/24 interface=BASE_VLAN network=192.168.10.0Īdd address=10.0.20.1/24 interface=VL20_VPN network=10.0.20.0Īdd address=10.0.30.1/24 interface=V元0_CLRNET network=10.0.30.0Īdd address=10.0.40.1/24 interface=VL40_IOT network=10.0.40.0Īdd disabled=no interface=ether1 use-peer-dns=no use-peer-ntp=noĪdd address=10.0.30.203 client-id=**:**:**:**:**:** comment=\ Set ssid=MikroTikĪdd interface=BR1 name=BASE_VLAN vlan-id=10Īdd interface=BR1 name=VL20_VPN vlan-id=20Īdd interface=BR1 name=V元0_CLRNET vlan-id=30Īdd interface=BR1 name=VL40_IOT vlan-id=40 I guess something terribly wrong in in the firewall rules.Ĭode: Select all # dec/03/2020 21:48:43 by RouterOS 6.47.7Īdd name=BR1 protocol-mode=none vlan-filtering=yesĪdd name=vpn_blackhole protocol-mode=none The IPSec tunnel is correctly established (I get an active peer and 2 SAs) but the traffic in the VPN VLAN is not redirected through ProtonVPN if I activate the killswitch in the firewall mangle, all the traffic in that VLAN stops. As far as I know, the VLANs are working as expected. Three of the router's ports are trunks and the fifth one is an access port assigned to the management VLAN. Mi router is a hAP ac2 and 4 VLAN have been defined there (BASE/management, VPN/protonVPN, CLRNET/normal and IoT). I am trying to assign one of my VLAN to an IPSec tunnel in ProtonVPN and a killswitch to avoid traffic leaking. Thus, the problem I have probably is something evident for most of you.

I switched from pfSense to ROS some days ago and I am still learning a lot.
