Community discussions

MikroTik App

Search found 5 matches

by BertV
Thu Dec 13, 2018 12:58 pm
Forum: General
Topic: Sham links unreliable?
Replies: 1
Views: 1028

Sham links unreliable?

Hi, I'm trying to make a fully redundant setup which includes sham links: 2x CE devices in HQ 2x PE mikrotiks in HQ 2x PE mikrotiks in a remote office: one connected via a DSL link, another one connected via a 4G link 2x CE devices in HQ I configured 4x VPN tunnels between those mikrotiks: HQ1 - rem...
by BertV
Wed Nov 28, 2018 12:42 pm
Forum: General
Topic: 6.40rc11 — IPsec peers can now be specified with DNS names, but what about policies?
Replies: 7
Views: 4478

Re: 6.40rc11 — IPsec peers can now be specified with DNS names, but what about policies?

+1 That's all tied to how IPsec works behind the scene. For L2L tunnels, policies are expected to come into the game first, and are used to find a proper SA. And only in case there's no established SA, a peer configuration is searched for, and then an ISAKMP or IKEv2 exchange is initiated based on t...
by BertV
Fri Dec 22, 2017 9:31 pm
Forum: General
Topic: Feature request - Diffie Hellman groups 19-21
Replies: 6
Views: 4905

Re: Feature request - Diffie Hellman groups 19-21

They are now officially supported! Kudos to the devs!

What's new in 6.41 (2017-Dec-22 11:55):
*) ipsec - added DH groups 19, 20 and 21 support for phase1 and phase2;
by BertV
Thu May 11, 2017 5:12 pm
Forum: General
Topic: Feature request - Diffie Hellman groups 19-21
Replies: 6
Views: 4905

Re: Feature request - Diffie Hellman groups 19-21

Although I'm not a cryptographic specialist (nor a programmer), I understand that Elliptic Curve Cryptography should be more efficient. (source: http://www.cisco.com/c/en/us/about/security-center/next-generation-cryptography.html#9). The implementation of DH19-21 (which use ECC) could possibly impro...
by BertV
Tue May 09, 2017 4:20 pm
Forum: General
Topic: Feature request - Diffie Hellman groups 19-21
Replies: 6
Views: 4905

Feature request - Diffie Hellman groups 19-21

Hello, Are there any plans to support Diffie Hellman Groups 19 to 21 (ecp256, ecp384, ecp521)? There is support for DH15-18, which - according to Cisco - offer acceptable and good security. (Source: http://www.cisco.com/c/en/us/about/security-center/next-generation-cryptography.html) I understand ho...