Panduan mendalam implementasi VPN pada MikroTik RB941: L2TP/IPsec, PPTP, SSTP, dan WireGuard.
Remote access secure ke jaringan kantor dari mana saja.
Konfigurasi dual: CLI (Terminal) & WinBox (GUI).
RB941 hAP lite dengan kemampuan VPN server. Support L2TP/IPsec, PPTP, SSTP, dan WireGuard (RouterOS v7+).
Cocok untuk remote access 5-10 client concurrent.
CPU
AR9344 - 650MHz
RAM
32 MB DDR2
STORAGE
16 MB FLASH
ETHERNET
4x 10/100 Mbps
VPN SUPPORT
L2TP, PPTP, SSTP
WIREGUARD
RouterOS v7+
VPN CLIENT MAX
~5-10 concurrent
VPN SPEED
~10-20 Mbps
POWER
5V DC / USB
OS
RouterOS v6 L4
DIMENSI
113 x 89 x 28mm
BERAT
160 gram
CATATAN VPN: RB941 support L2TP/IPsec, PPTP, SSTP. WireGuard hanya di RouterOS v7+. Performa VPN tergantung CPU. Untuk performa VPN terbaik, pertimbangkan upgrade ke hAP ac^2 atau CCR series.
KONSEP VPN (VIRTUAL PRIVATE NETWORK)
FUNDAMENTAL
VPN (Virtual Private Network) membuat tunnel terenkripsi melalui internet untuk akses aman ke jaringan private.
Client remote bisa akses jaringan kantor seolah-olah terhubung langsung.
JENIS-JENIS VPN
L2TP/IPsec
Layer 2 Tunneling Protocol dengan IPsec encryption. Paling secure dan widely supported.
✓ Secure, widely supported, cross-platform
✗ Complex setup, slower performance
PPTP
Point-to-Point Tunneling Protocol. Oldest VPN protocol, easy setup but less secure.
✓ Easy setup, fast, widely supported
✗ Less secure, outdated
SSTP
Secure Socket Tunneling Protocol. Microsoft protocol, good for Windows clients.
✓ Good for Windows, firewall-friendly
✗ Windows-centric, slower
WireGuard
Modern VPN protocol. Fast, simple, secure. Requires RouterOS v7+.
✓ Fast, simple, secure, modern
✗ RouterOS v7+ only
KEUNGGULAN VPN
ENCRYPTED TUNNEL
Semua traffic dienkripsi melalui tunnel. Data aman dari eavesdropping di internet.
REMOTE ACCESS
Akses jaringan kantor dari mana saja. Seolah-olah terhubung langsung ke jaringan kantor.
SECURE
Data terenkripsi end-to-end. Aman dari eavesdropping, man-in-the-middle attack.
ACCESS ANYWHERE
Akses dari mana saja dengan internet. Remote work, WFH, mobile access.
PENTING: VPN mempengaruhi performa. Enkripsi membutuhkan CPU. RB941 dengan CPU 650MHz bisa handle 5-10 VPN client concurrent. Untuk lebih banyak client, upgrade hardware.
TOPOLOGI VPN
SCHEMA
// TOPOLOGI VPN REMOTE ACCESS //[ REMOTE CLIENT ](Remote Location)
|
| VPN Tunnel (Encrypted)
| L2TP/IPsec, PPTP, SSTP, WireGuard
v
[ INTERNET ]
|
| Public Internet
v
+-------------------+
| MIKROTIK RB941 |
| VPN SERVER |
| |
| ether1: WAN | Public IP
| ether2-4: LAN | Private Network
| wlan1: WIFI |
+-------------------+
|
v
[ OFFICE NETWORK ]192.168.10.0/24Servers, Printers, ResourcesVPN CLIENT:- Dapat IP dari VPN pool (10.5.5.0/24)- Bisa akses 192.168.10.0/24- Traffic encrypted via VPN tunnel
VPN WORKING: Remote client connect ke VPN server -> dapat IP dari VPN pool -> bisa akses jaringan kantor (192.168.10.0/24) -> semua traffic encrypted via VPN tunnel.
ANIMASI VPN CONNECTION
LIVE FLOW
Visualisasi VPN tunnel: Remote client connect ke VPN server melalui internet. Traffic dienkripsi melalui tunnel.
VPN Tunnel
Encrypted Traffic
VPN TUNNEL: Remote client connect ke VPN server melalui internet. Semua traffic dienkripsi melalui VPN tunnel. Client bisa akses jaringan kantor seolah-olah terhubung langsung.
SETUP BASIC ROUTER
STEP 01
Setup basic router sebelum konfigurasi VPN: identity, interface, IP address, DHCP, NAT.
TIPS: L2TP/IPsec paling secure dan widely supported. Gunakan IPsec dengan AES-256 untuk encryption terbaik. Port yang dibutuhkan: UDP 500, 1701, 4500, dan IPsec ESP protocol.
PPTP VPN CONFIGURATION
VPN
PPTP adalah VPN protocol tertua. Easy setup tapi less secure. Gunakan hanya jika L2TP/IPsec tidak bisa.
WARNING: PPTP less secure. Gunakan hanya jika L2TP/IPsec tidak bisa. PPTP sudah diketahui memiliki vulnerability. Gunakan L2TP/IPsec atau WireGuard untuk keamanan terbaik.
SSTP VPN CONFIGURATION
VPN
SSTP (Secure Socket Tunneling Protocol) adalah Microsoft protocol. Good untuk Windows clients, firewall-friendly (port 443).
TIPS: Firewall rules harus berurutan. Allow established/related di paling atas. Allow VPN protocols. Allow VPN traffic to LAN. Drop all other di paling bawah.
CLIENT CONFIGURATION - WINDOWS
CLIENT
Konfigurasi VPN client di Windows 10/11. Support L2TP/IPsec, PPTP, SSTP built-in.
Windows 10/11
Built-in VPN client. Support L2TP/IPsec, PPTP, SSTP.
L2TP/IPsec CONFIGURATION
VIA SETTINGS
1
Settings -> Network & Internet -> VPN
2
Add a VPN connection
3
VPN provider: Windows (built-in)
4
Connection name: Office VPN
5
Server name or address: vpn-server-public-ip
6
VPN type: Layer 2 Tunneling Protocol with IPsec (L2TP/IPsec)
7
Sign-in info: Username and password
8
Username: vpnuser, Password: vpnpassword
9
IPsec pre-shared key: ipsec-secret
10
Save -> Connect
VIA CONTROL PANEL
1
Control Panel -> Network and Sharing Center
2
Set up a new connection or network
3
Connect to a workplace
4
Use my Internet connection (VPN)
5
Internet address: vpn-server-public-ip
6
Destination name: Office VPN
7
VPN type: L2TP/IPsec
8
Pre-shared key: ipsec-secret
9
Username: vpnuser, Password: vpnpassword
10
Create -> Connect
TIPS: Windows built-in VPN client support L2TP/IPsec, PPTP, SSTP. Untuk L2TP/IPsec, perlu IPsec pre-shared key. Untuk SSTP, perlu certificate.
CLIENT CONFIGURATION - ANDROID
CLIENT
Konfigurasi VPN client di Android. Built-in support L2TP/IPsec, PPTP. Untuk WireGuard, perlu app.
Android
Built-in VPN client. Support L2TP/IPsec, PPTP. WireGuard app available.
L2TP/IPsec CONFIGURATION
VIA SETTINGS
1
Settings -> Network & Internet -> VPN
2
Add VPN profile
3
Name: Office VPN
4
Type: L2TP/IPsec PSK
5
Server address: vpn-server-public-ip
6
L2TP secret: (leave blank)
7
IPsec pre-shared key: ipsec-secret
8
Username: vpnuser, Password: vpnpassword
9
Save -> Connect
WIREGUARD APP
1
Install WireGuard app dari Play Store
2
+ Add tunnel -> Add empty tunnel
3
Name: Office VPN
4
Generate keypair
5
Addresses: 10.5.8.2/32
6
DNS servers: 8.8.8.8
7
Add peer: Public key from server
8
Endpoint: vpn-server-public-ip:51820
9
Allowed IPs: 192.168.10.0/24
10
Save -> Activate
TIPS: Android built-in VPN client support L2TP/IPsec dan PPTP. Untuk WireGuard, install WireGuard app dari Play Store. WireGuard lebih fast dan secure.
CLIENT CONFIGURATION - iOS
CLIENT
Konfigurasi VPN client di iOS (iPhone/iPad). Built-in support L2TP/IPsec, IKEv2, IKEv2. Untuk WireGuard, perlu app.
iOS (iPhone/iPad)
Built-in VPN client. Support L2TP/IPsec, IKEv2. WireGuard app available.
L2TP/IPsec CONFIGURATION
VIA SETTINGS
1
Settings -> General -> VPN & Device Management
2
Add VPN Configuration
3
Type: L2TP
4
Description: Office VPN
5
Server: vpn-server-public-ip
6
Account: vpnuser
7
Password: vpnpassword
8
Secret: ipsec-secret
9
Done -> Connect
WIREGUARD APP
1
Install WireGuard app dari App Store
2
+ Add tunnel -> Add empty tunnel
3
Name: Office VPN
4
Generate keypair
5
Addresses: 10.5.8.2/32
6
DNS servers: 8.8.8.8
7
Add peer: Public key from server
8
Endpoint: vpn-server-public-ip:51820
9
Allowed IPs: 192.168.10.0/24
10
Save -> Activate
TIPS: iOS built-in VPN client support L2TP/IPsec dan IKEv2. Untuk WireGuard, install WireGuard app dari App Store. WireGuard lebih fast dan secure.
TIPS: Monitor VPN connections secara berkala. Check active connections, traffic, dan performance. Monitor CPU usage karena VPN encryption membutuhkan CPU.
TROUBLESHOOTING VPN
SUPPORT
Masalah umum VPN dan solusinya.
VPN TIDAK BISA CONNECT
KEMUNGKINAN PENYEBAB:
1. VPN server tidak enabled
2. Firewall block VPN ports
3. Username/password salah
4. IPsec pre-shared key salah (L2TP/IPsec)
5. Certificate salah (SSTP)
6. Public IP salah atau tidak accessible SOLUSI: Cek VPN server status. Cek firewall rules. Cek credentials. Cek public IP accessibility.
VPN CONNECT TAPI TIDAK BISA AKSES LAN
KEMUNGKINAN PENYEBAB:
1. Firewall block VPN traffic ke LAN
2. Routing salah
3. VPN pool IP conflict dengan LAN
4. Firewall forward rule salah SOLUSI: Cek firewall forward rules. Cek routing table. Cek VPN pool IP range. Pastikan tidak conflict dengan LAN.
VPN LAMBAT
KEMUNGKINAN PENYEBAB:
1. CPU overload (VPN encryption)
2. Internet connection lambat
3. Terlalu banyak VPN client
4. VPN protocol lambat (PPTP)
5. Encryption overhead SOLUSI: Cek CPU usage. Upgrade hardware jika perlu. Gunakan WireGuard untuk performa terbaik. Kurangi jumlah VPN client.
L2TP/IPsec TIDAK CONNECT
KEMUNGKINAN PENYEBAB:
1. IPsec tidak enabled
2. IPsec peer/secret salah
3. Firewall block IPsec ports (UDP 500, 4500, ESP)
4. NAT traversal issue
5. Client tidak support IPsec SOLUSI: Enable IPsec. Cek peer dan secret. Cek firewall rules. Pastikan client support IPsec.
SSTP TIDAK CONNECT
KEMUNGKINAN PENYEBAB:
1. Certificate tidak valid atau expired
2. Certificate common name tidak match
3. Client tidak trust certificate
4. Firewall block port 443 SOLUSI: Generate certificate baru. Pastikan common name match. Import certificate ke client. Cek firewall port 443.
WIREGUARD TIDAK CONNECT
KEMUNGKINAN PENYEBAB:
1. WireGuard tidak enabled (RouterOS v7+)
2. Public key salah
3. Allowed addresses salah
4. Firewall block UDP port
5. Endpoint address/port salah SOLUSI: Pastikan RouterOS v7+. Cek public key. Cek allowed addresses. Cek firewall. Cek endpoint.