Android fritz vpn

broken image
broken image

to use a NAT rule to change source addresses of packets sent from 192.168.88.0/24 towards 192.168.0.0/24 (the network behind Fritz) to 192.168.1.2

broken image

to change Mikrotik's LAN for clients to 192.168.1.0/24 (it needs to change dhcp pool and dhcp network accordingly) But according to your picture, your Mikrotik's clients get addresses from 192.168.88.0/24. The configuration of Fritz assigns 192.168.1.0/24 to the client's subnet, which means that only packets with source addresses from this network will get to the tunnel. All the other-than-Mikrotik IPsec clients you connect to your Fritz are individual devices, right? So they get assigned an IP address from there.

broken image