Community discussions

MikroTik App
 
m3a2r1
newbie
Topic Author
Posts: 25
Joined: Sat Mar 29, 2014 12:11 pm

RouterOS 6.48.6 + IPSEC IKEv2

Wed Nov 29, 2023 9:31 pm

Hello, I'm using RB4011 with ROS 6.48.6 and IPSEC IKEv2. Certificates are issued on Windows Server and uploaded to router. It works correctly since last 2 years but 2 days ago I've upgraded my servers from 2012R2 to 2022 and it stopped to work. Can anybody help me with fix it?
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 13045
Joined: Thu Mar 03, 2016 10:23 pm

Re: RouterOS 6.48.6 + IPSEC IKEv2

Wed Nov 29, 2023 9:40 pm

Where exactly does it break? Is it upload phase or certificate import phase? Describe how exactly are you doing the failing phase.

And a suggestion: upgrade ROS to latest long-term version (6.49.10).
 
m3a2r1
newbie
Topic Author
Posts: 25
Joined: Sat Mar 29, 2014 12:11 pm

Re: RouterOS 6.48.6 + IPSEC IKEv2

Wed Nov 29, 2023 10:30 pm

I can upload certificate but connection can't establish correct - on pc I have message "IKE authentication credentials cannot be accepted", on ROS I see connection established but with no traffic - it disappears after 2 minutes.
 
m3a2r1
newbie
Topic Author
Posts: 25
Joined: Sat Mar 29, 2014 12:11 pm

Re: RouterOS 6.48.6 + IPSEC IKEv2

Wed Nov 29, 2023 10:36 pm

When I upgraded Windows Server to 2022, all of directly connected computers have refreshed their certificates. And these computers can't connect to VPN. All computers which didn't have connect and didn't get new certificate, still work.
 
oskarsk
MikroTik Support
MikroTik Support
Posts: 64
Joined: Mon May 13, 2019 9:41 am

Re: RouterOS 6.48.6 + IPSEC IKEv2

Thu Nov 30, 2023 7:52 am

Enable ipsec debug logging on ROS and you will see why it disappears after 2 minutes.
Use latest ROS version.
 
m3a2r1
newbie
Topic Author
Posts: 25
Joined: Sat Mar 29, 2014 12:11 pm

Re: RouterOS 6.48.6 + IPSEC IKEv2

Thu Nov 30, 2023 8:43 am

I've updated ROS to 6.49.10. There is nothing readable in log after 2 minutes.
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 13045
Joined: Thu Mar 03, 2016 10:23 pm

Re: RouterOS 6.48.6 + IPSEC IKEv2

Thu Nov 30, 2023 11:35 am

I can upload certificate but connection can't establish correct ...

I'd say that it has something to do with key type, used in certificate. ROS v6 is pretty outdated with regard to support of security features (encryption protocols, key types, etc.) and it could be that recent windows servers deprecated use of older security features while ROS v6 doesn't support the (now) required newer ones.

If you can afford doing it, upgrade your router to v7 (7.12.1 is latest stable at the tiem being) and see if things improve for you. Beware that upgrade from v6 to v7 can cause some hiccups, so prepare yourself for some (extended) downtime.
Alternatively, you can try to manually enable use of deprecated security features on windows machines to see if it helps. This probably won't help if the reason for problems is certificate, generated by Windows, and is thus unusable in ROS. Which actually seems to be the case as the only change in VPN clients is use of newer certificates ...
 
m3a2r1
newbie
Topic Author
Posts: 25
Joined: Sat Mar 29, 2014 12:11 pm

Re: RouterOS 6.48.6 + IPSEC IKEv2

Thu Nov 30, 2023 9:49 pm

I'll try with CHR in lab, only with ike2 functionality. When it will be work, I'll set chr only as vpn server, not router. I have no time to downtime after upgrade ROS to 7.x
 
m3a2r1
newbie
Topic Author
Posts: 25
Joined: Sat Mar 29, 2014 12:11 pm

Re: RouterOS 6.48.6 + IPSEC IKEv2

Fri Dec 01, 2023 2:06 pm

I've tested IKE2 on CHR 7.12.1 - it works with certificates generated by Mikrotik but doesn't work with certificates from Windows.
 
taksa
just joined
Posts: 2
Joined: Sun Feb 12, 2023 6:45 pm

Re: RouterOS 6.48.6 + IPSEC IKEv2

Fri Dec 15, 2023 10:18 am

Is it possible to tell how you set up the issuance of certificates in the windows server (with what keys) so that mikrotik(ikev2) would work with them?

Who is online

Users browsing this forum: No registered users and 39 guests