Community discussions

MikroTik App
 
gcxo
just joined
Topic Author
Posts: 13
Joined: Wed Apr 15, 2015 11:57 pm

Wireguard and L2tp/IPSEC Incompatibility

Sat Aug 17, 2024 9:55 pm

I have two sites which are connected via a L2TP/IPSEC VPN. Everything works fine, the connection, the routing, etc..

I wanted to try WIreguard to connect both Mikrotik ROuters and it was not working until I disabled the L2TP/IPSEC. Once I disable the Lt2p/IPSEC VPN , the wireguard work correctly and traffic can flow through that interface.


Why are they not compatible?
 
User avatar
sindy
Forum Guru
Forum Guru
Posts: 11227
Joined: Mon Dec 04, 2017 9:19 pm

Re: Wireguard and L2tp/IPSEC Incompatibility

Sat Aug 17, 2024 10:14 pm

Why are they not compatible?
They are, you can have both these tunnels in parallel, but you have to take some measures. The IPsec policy used to transport the L2TP packets must selectively match on UDP port 1701, which is the case if you let RouterOS create it for you but may not be the case if you have configured the IPsec part manually, so you may end up with "Wireguard over IPsec". And you have to use proper routing of the payload so that you can control which payload uses which tunnel if both are active.

Without seeing the export of configurations of both devices, nothing more exact can be said.
 
gcxo
just joined
Topic Author
Posts: 13
Joined: Wed Apr 15, 2015 11:57 pm

Re: Wireguard and L2tp/IPSEC Incompatibility

Sun Aug 18, 2024 12:32 am

Thanks for the prompt response. How do I configure IPSEC Policy to use Port 1701 for L2TP packets?
 
User avatar
nichky
Forum Guru
Forum Guru
Posts: 1392
Joined: Tue Jun 23, 2015 2:35 pm

Re: Wireguard and L2tp/IPSEC Incompatibility

Sun Aug 18, 2024 7:12 am

ip ipsec policy/
src-port=1701
dst-port=1701
protocol=udp


Make sure is in transport mode
 
gcxo
just joined
Topic Author
Posts: 13
Joined: Wed Apr 15, 2015 11:57 pm

Re: Wireguard and L2tp/IPSEC Incompatibility

Sun Aug 18, 2024 12:09 pm

Thanks, it works. I have both tunnels working!!

Who is online

Users browsing this forum: CloudRouting, sindy, StuckSomewhere and 75 guests