<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="id">
	<id>https://paksamsul.smkn1pogalan.sch.id/index.php?action=history&amp;feed=atom&amp;title=OpenVPN_Site_to_Site</id>
	<title>OpenVPN Site to Site - Riwayat revisi</title>
	<link rel="self" type="application/atom+xml" href="https://paksamsul.smkn1pogalan.sch.id/index.php?action=history&amp;feed=atom&amp;title=OpenVPN_Site_to_Site"/>
	<link rel="alternate" type="text/html" href="https://paksamsul.smkn1pogalan.sch.id/index.php?title=OpenVPN_Site_to_Site&amp;action=history"/>
	<updated>2026-04-28T03:25:14Z</updated>
	<subtitle>Riwayat revisi halaman ini di wiki</subtitle>
	<generator>MediaWiki 1.41.1</generator>
	<entry>
		<id>https://paksamsul.smkn1pogalan.sch.id/index.php?title=OpenVPN_Site_to_Site&amp;diff=1156&amp;oldid=prev</id>
		<title>Samsul: ←Membuat halaman berisi &#039;Sumber: https://www.marthur.com/networking/mikrotik-setup-a-site-to-site-openvpn-connection/314/    %MikroTik Identity%  HQ  %Client Name%        Cabang  %MikroTik Loc...&#039;</title>
		<link rel="alternate" type="text/html" href="https://paksamsul.smkn1pogalan.sch.id/index.php?title=OpenVPN_Site_to_Site&amp;diff=1156&amp;oldid=prev"/>
		<updated>2023-01-25T16:16:30Z</updated>

		<summary type="html">&lt;p&gt;←Membuat halaman berisi &amp;#039;Sumber: https://www.marthur.com/networking/mikrotik-setup-a-site-to-site-openvpn-connection/314/    %MikroTik Identity%  HQ  %Client Name%        Cabang  %MikroTik Loc...&amp;#039;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Halaman baru&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Sumber: https://www.marthur.com/networking/mikrotik-setup-a-site-to-site-openvpn-connection/314/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 %MikroTik Identity%  HQ&lt;br /&gt;
 %Client Name%        Cabang&lt;br /&gt;
 %MikroTik Local IP%  192.168.88.198&lt;br /&gt;
 %Passphrase%         123456789&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==MIKROTIK A (SERVER): CERTIFICATE SETUP &amp;amp; EXPORT==&lt;br /&gt;
&lt;br /&gt;
===CREATE THE CERTIFICATES===&lt;br /&gt;
&lt;br /&gt;
 /certificate add name=ca-template common-name=CA-HQ key-usage=key-cert-sign,crl-sign&lt;br /&gt;
 /certificate add name=server-template common-name=SERVER&lt;br /&gt;
 /certificate add name=client-Cabang-template common-name=client-Cabang&lt;br /&gt;
&lt;br /&gt;
===SIGN THE CERTIFICATES===&lt;br /&gt;
&lt;br /&gt;
Butuh waktu, jangan copy paste sekaligus.&lt;br /&gt;
&lt;br /&gt;
 /certificate sign ca-template ca-crl-host=192.168.88.198 name=CA-HQ&lt;br /&gt;
 /certificate sign ca=CA-HQ server-template name=SERVER&lt;br /&gt;
 /certificate sign ca=CA-HQ client-Cabang-template name=client-Cabang&lt;br /&gt;
&lt;br /&gt;
===ENABLE “TRUSTED” FOR THE CERTIFICATE AUTHORITY AND SERVER ONLY===&lt;br /&gt;
&lt;br /&gt;
 /certificate set CA-HQ trusted=yes&lt;br /&gt;
 /certificate set SERVER trusted=yes&lt;br /&gt;
&lt;br /&gt;
The Certificates window should now look similar to this screenshot.&lt;br /&gt;
&lt;br /&gt;
===EXPORT THE CERTIFICATES===&lt;br /&gt;
&lt;br /&gt;
 /certificate export-certificate CA-HQ&lt;br /&gt;
 /certificate export-certificate client-Cabang export-passphrase=123456789&lt;br /&gt;
&lt;br /&gt;
Ambil file menggunakan FTP&lt;br /&gt;
&lt;br /&gt;
 cert_export_CA-HQ.crt&lt;br /&gt;
 cert_export_client-Cabang.key&lt;br /&gt;
 cert_export_client-Cabang.crt&lt;br /&gt;
&lt;br /&gt;
==MIKROTIK B (CLIENT): CERTIFICATE SETUP &amp;amp; IMPORT==&lt;br /&gt;
&lt;br /&gt;
Upload file menggunakan FTP&lt;br /&gt;
&lt;br /&gt;
 cert_export_CA-HQ.crt&lt;br /&gt;
 cert_export_client-Cabang.key&lt;br /&gt;
 cert_export_client-Cabang.crt&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===IMPORT THE CERTIFICATES===&lt;br /&gt;
&lt;br /&gt;
 /certificate import file-name=cert_export_CA-HQ.crt passphrase=&amp;quot;&amp;quot;&lt;br /&gt;
 /certificate import file-name=cert_export_client-Cabang.crt passphrase=123456789&lt;br /&gt;
 /certificate import file-name=cert_export_client-Cabang.key passphrase=123456789&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==MIKROTIK A (SERVER): OPENVPN PPP CONFIGURATION==&lt;br /&gt;
&lt;br /&gt;
===IMPORT THE CERTIFICATES===&lt;br /&gt;
&lt;br /&gt;
 /ppp profile add name=openvpn local-address=10.10.200.1 remote-address=10.10.200.2 change-tcp-mss=yes use-compression=no use-encryption=required&lt;br /&gt;
&lt;br /&gt;
==CREATE A PPP SECRET (MODIFY COMMAND AS NEEDED)==&lt;br /&gt;
&lt;br /&gt;
 /ppp secret add name=Cabang password=123456789 profile=openvpn service=ovpn&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===CONFIGURE THE OVPN SERVER (MODIFY COMMAND AS NEEDED)===&lt;br /&gt;
&lt;br /&gt;
 /interface ovpn-server server set certificate=SERVER cipher=blowfish128,aes128,aes192,aes256 default-profile=openvpn enabled=yes require-client-certificate=yes&lt;br /&gt;
&lt;br /&gt;
===CREATE A ROUTE (MODIFY COMMAND AS NEEDED)===&lt;br /&gt;
&lt;br /&gt;
 /ip route add dst-address=192.168.200.0/24 gateway=10.10.200.2&lt;br /&gt;
&lt;br /&gt;
==MIKROTIK A (SERVER): OPENVPN FIREWALL/NAT CONFIGURATION==&lt;br /&gt;
&lt;br /&gt;
CREATE THE FIREWALL FILTER AND NAT BYPASS RULES (MODIFY COMMAND AS NEEDED):&lt;br /&gt;
&lt;br /&gt;
 # /ip firewall filter add chain=input dst-port=1194 protocol=tcp&lt;br /&gt;
 # /ip firewall nat add chain=srcnat src-address=192.168.100.0/24 dst-address=192.168.200.0/24 place-before=0&lt;br /&gt;
&lt;br /&gt;
==MIKROTIK B (CLIENT): OPENVPN PPP CONFIGURATION==&lt;br /&gt;
&lt;br /&gt;
===CREATE A OVPN CLIENT (MODIFY COMMAND AS NEEDED)===&lt;br /&gt;
&lt;br /&gt;
 # /interface ovpn-client add certificate=cert_export_client-Cabang.crt_0 cipher=aes256 connect-to=71.157.75.49 mac-address=02:2F:03:6C:10:59 name=ovpn-Texas password=NyTx325 profile=default-encryption user=NewYork&lt;br /&gt;
&lt;br /&gt;
 /interface ovpn-client add certificate=cert_export_client-Cabang.crt_0 cipher=aes256 connect-to=10.10.200.1 name=ovpn-ke-HQ password=123456789 profile=default-encryption user=Cabang&lt;br /&gt;
&lt;br /&gt;
===CREATE A ROUTE (MODIFY COMMAND AS NEEDED)===&lt;br /&gt;
&lt;br /&gt;
 /ip route add dst-address=192.168.100.0/24 gateway=10.10.200.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
MIKROTIK B (CLIENT): OPENVPN FIREWALL/NAT CONFIGURATION&lt;br /&gt;
CREATE THE FIREWALL FILTER AND NAT BYPASS RULES (MODIFY COMMAND AS NEEDED):&lt;br /&gt;
&lt;br /&gt;
 # /ip firewall filter add chain=input dst-port=1194 protocol=tcp&lt;br /&gt;
 # /ip firewall nat add chain=srcnat src-address=192.168.88.0/24 dst-address=192.168.100.0/24 place-before=0&lt;br /&gt;
&lt;br /&gt;
==Referensi==&lt;br /&gt;
&lt;br /&gt;
* https://www.marthur.com/networking/mikrotik-setup-a-site-to-site-openvpn-connection/314/&lt;/div&gt;</summary>
		<author><name>Samsul</name></author>
	</entry>
</feed>