我記得好似唔使做port forward
你不如系CLI從頭做一次
/ip pool add name="L2TP-Pool" ranges=192.168.89.1-192.168.89.20
/ppp profile add name=l2tp-profile local-address=L2TP-Pool remote-address=L2TP-Pool use-encryption=required change-tcp-mss=yes dns-server=8.8.8.8
/interface l2tp-server server set authentication=mschap2 default-profile=l2tp-profile enabled=yes ipsec-secret=MYKEY max-mru=1460 max-mtu=1460 use-ipsec=yes
/ppp secret add name=MYUSER password=MYPASSWORD service=l2tp profile=l2tp-profile
/ip ipsec proposal add name=L2TP-Proposal auth-algorithms=sha1 enc-algorithms=3des,aes-256-cbc pfs-group=none
/ip ipsec peer add address=0.0.0.0/0 port=500 auth-method=pre-shared-key secret=MYKEY generate-policy=port-override exchange-mode=main-l2tp
send-initial-contact=yes nat-traversal=yes hash-algorithm=sha1 enc-algorithm=3des,aes-256 dh-group=modp1024
/ip ipsec policy add src-address=::/0 dst-address=::/0 protocol=all template=yes group=default action=encrypt level=require ipsec-protocols=esp tunnel=no sa-src-
address=0.0.0.0 sa-dst-address=0.0.0.0 proposal=L2TP-Proposal |