Community discussions

MikroTik App
 
Zewa
just joined
Topic Author
Posts: 4
Joined: Wed Dec 21, 2011 10:46 am

MTK - MTK (RB450G) IPSec Tunnel (some questions)

Wed Dec 21, 2011 11:08 am

I have two RB450G routers. I connect them using this scheme

Image

On the left side I have: |||||||||||||||||| On the right side I have:
Public IP = 212.xx.xxx.xxx ||||||||||||||||||| Public IP = 195.xxx.xx.xx
Local IP = 192.168.77.0/24 ||||||||||||||||||| Local IP = 192.168.88.0/24
Computer = 192.168.77.157 |||||||||||||||||| Computer = 192.168.88.253

I used tutorial from http://www.gregsowell.com, configured both routers. Now then I ping from right router to left after two tryes everything is OK, tunnel is ON. If i ping from left router to right connection isn't establishing. Then connection is established I can ping from 192.168.77.157 to 192.168.88.253, but not reverse if I try ping from 192.168.88.253 to 192.168.77.157 ping isn't going, but I can ping to remote router 192.168.77.1.

Now I have two questions:
1) Why can't I ping from 192.168.88.253 to 192.168.77.157 ?
2) If I restart router connection is lost until I ping from right router to left one. How can I make them connect automaticaly after restart ?


Edit:

I noticed that if I restart one of routers I have to ping from that restarted router to another to make tunnel to establish connection. If I ping from another one I get timeouts...

For automatic reconnection I found netwatch is something common, but he allways see other router as down if I ping to it's local IP, I can't find how to change Interface in netwatch...

Edit 2011-12-23:
For automatic connection I used Sheduler and it works for me now. But what about pinging from 192.168.88.253 to 192.168.77.157 ?
Last edited by Zewa on Fri Dec 23, 2011 10:48 am, edited 1 time in total.
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7195
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: MTK - MTK (RB450G) IPSec Tunnel (some questions)

Wed Dec 21, 2011 12:08 pm

After router is rebooted, you have to clear installed SAs manually on other router. Or set up DPD.
 
Zewa
just joined
Topic Author
Posts: 4
Joined: Wed Dec 21, 2011 10:46 am

Re: MTK - MTK (RB450G) IPSec Tunnel (some questions)

Wed Dec 21, 2011 12:25 pm

After router is rebooted, you have to clear installed SAs manually on other router. Or set up DPD.
It doesn't change anything... If i reboot one router I still need to ping from that router to another, in oposite way connection doesn't establish