User Tools

Site Tools


networking:router:mikrotik_vpn_ipsec

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
networking:router:mikrotik_vpn_ipsec [2022/02/24 11:18]
gcooper
networking:router:mikrotik_vpn_ipsec [2023/06/21 15:26] (current)
gcooper
Line 74: Line 74:
 /ip ipsec policy /ip ipsec policy
 add dst-address=$SubnetBehindRouter2 sa-dst-address=$Router2WanAddr sa-src-address=$Router1WanAddr \ add dst-address=$SubnetBehindRouter2 sa-dst-address=$Router2WanAddr sa-src-address=$Router1WanAddr \
-  src-address=$SubnetBehindRouter1 tunnel=yes+  src-address=$SubnetBehindRouter1 peer=$Site2Name tunnel=yes
  
 # NAT bypass rule # NAT bypass rule
Line 110: Line 110:
 /ip ipsec policy /ip ipsec policy
 add dst-address=$SubnetBehindRouter1 sa-dst-address=$Router1WanAddr sa-src-address=$Router2WanAddr \ add dst-address=$SubnetBehindRouter1 sa-dst-address=$Router1WanAddr sa-src-address=$Router2WanAddr \
-  src-address=$SubnetBehindRouter2 tunnel=yes+  src-address=$SubnetBehindRouter2 peer=$Site1Name tunnel=yes
  
 # NAT bypass rule # NAT bypass rule
Line 150: Line 150:
 <note tip>To convert a S2S VPN connection from **two-sides-static** to **one-side-dynamic**: <note tip>To convert a S2S VPN connection from **two-sides-static** to **one-side-dynamic**:
  
-  * Modify the (dynamic IP) peer on the router with static WAN IP:+  * Modify the (dynamic IP) peer definition on the router with static WAN IP:
     * Set the IP address to ''0.0.0.0/0''     * Set the IP address to ''0.0.0.0/0''
     * Select ''Passive''     * Select ''Passive''
     * Deselect ''Send INITIAL_CONTACT''     * Deselect ''Send INITIAL_CONTACT''
     * Responder     * Responder
-  * Modify the (static IP) peer on the router with dynamic WAN IP:+  * Modify the (static IP) peer definition on the router with dynamic WAN IP:
     * Set the IP address to the static WAN IP address of the other router     * Set the IP address to the static WAN IP address of the other router
     * Deselect ''Passive''     * Deselect ''Passive''
Line 169: Line 169:
 /ip ipsec peer /ip ipsec peer
 add name=peername passive=yes add name=peername passive=yes
-/ip ipsec profile 
-set [ find default=yes ] enc-algorithm=aes-256,aes-128,3des 
 /ip ipsec identity /ip ipsec identity
 add peer=peername secret=yourpresharedkey add peer=peername secret=yourpresharedkey
networking/router/mikrotik_vpn_ipsec.1645726697.txt.gz · Last modified: 2022/02/24 11:18 by gcooper