Community discussions

MikroTik App
 
Argon
just joined
Topic Author
Posts: 9
Joined: Mon Mar 26, 2012 12:17 pm

Routing between two IPSec Tunnels

Fri Apr 11, 2014 1:22 pm

I have a setup like this

Network 1 <IPSEC TUNNEL> Network 2 <IPSEC TUNNEL> Network 3

RB750GL is in network 2.

I can communicate between Net 1 and Net 2, Net 2 and Net 3.

But no communication between Net 1 and Net 3?

Is it possible to crate policies for communication between 1 and 3?

I've tried to enable Generate Policy feture in IPsec Peers options. After some delay it creates very interesting rules like src:net1 dst=net3, sa src=mikrotik, sa dst=net1 gw. The traffic from Net 1 to Net 3 begins to flow for some time. But traffic Net 1 and Net 2, Net 2 and Net 3 stops to flow. After some time, all traffic stops to flow.

What should I do to make all traffic directions possible?
 
efaden
Forum Guru
Forum Guru
Posts: 1708
Joined: Sat Mar 30, 2013 1:55 am
Location: New York, USA

Re: Routing between two IPSec Tunnels

Fri Apr 11, 2014 3:27 pm

I have a setup like this

Network 1 <IPSEC TUNNEL> Network 2 <IPSEC TUNNEL> Network 3

RB750GL is in network 2.

I can communicate between Net 1 and Net 2, Net 2 and Net 3.

But no communication between Net 1 and Net 3?

Is it possible to crate policies for communication between 1 and 3?

I've tried to enable Generate Policy feture in IPsec Peers options. After some delay it creates very interesting rules like src:net1 dst=net3, sa src=mikrotik, sa dst=net1 gw. The traffic from Net 1 to Net 3 begins to flow for some time. But traffic Net 1 and Net 2, Net 2 and Net 3 stops to flow. After some time, all traffic stops to flow.

What should I do to make all traffic directions possible?
I don't believe so. On RouterOS IPSec tunnels are not routable. You would have to use a IPIP/GRE/EOIP etc over IPSec setup.
 
andriys
Forum Guru
Forum Guru
Posts: 1543
Joined: Thu Nov 24, 2011 1:59 pm
Location: Kharkiv, Ukraine

Re: Routing between two IPSec Tunnels

Fri Apr 11, 2014 4:01 pm

Is it possible to crate policies for communication between 1 and 3?
Yes, it's possible.
I've tried to enable Generate Policy feture in IPsec Peers options.
Don't use "Generate policy" option here, it is not needed in your case.

I remember myself replying to a similar question some time ago. Have a look at this thread, it contains a working example of what you're asking for.
 
Argon
just joined
Topic Author
Posts: 9
Joined: Mon Mar 26, 2012 12:17 pm

Re: Routing between two IPSec Tunnels

Fri Apr 11, 2014 6:37 pm

Is it possible to crate policies for communication between 1 and 3?
Yes, it's possible.
I've tried to enable Generate Policy feture in IPsec Peers options.
Don't use "Generate policy" option here, it is not needed in your case.

I remember myself replying to a similar question some time ago. Have a look at this thread, it contains a working example of what you're asking for.
Thanks a lot, it really works! You made my day! Also a had to set 'level=unique' instead of 'require' to make it work.
 
efaden
Forum Guru
Forum Guru
Posts: 1708
Joined: Sat Mar 30, 2013 1:55 am
Location: New York, USA

Re: Routing between two IPSec Tunnels

Fri Apr 11, 2014 7:11 pm

Is it possible to crate policies for communication between 1 and 3?
Yes, it's possible.
I've tried to enable Generate Policy feture in IPsec Peers options.
Don't use "Generate policy" option here, it is not needed in your case.

I remember myself replying to a similar question some time ago. Have a look at this thread, it contains a working example of what you're asking for.
Thanks a lot, it really works! You made my day! Also a had to set 'level=unique' instead of 'require' to make it work.
Thats actually really good to know...

Who is online

Users browsing this forum: AshuGite, tarfox, thahemp and 19 guests