Community discussions

MikroTik App
 
andrace
newbie
Topic Author
Posts: 42
Joined: Sun Sep 21, 2014 8:41 am

magic of icmp

Tue Sep 23, 2014 8:38 am

Hi all. Please advise me.
I have such scheme :

[192.168.250.0/23]--------[10.10.0.0/24(DFL800)]---IPSEC-----[192.168.75.0/24(Mikrotik)]

I made an ipsec channel between dfl800 and mikrotik but have a little problem

All working excluding an icmp traffic from 192.168.250.0/23 and 10.10.0.0/24 to 192.168.75.0/24
And also I see no dropped or other icmp traffic on the mikrotik.
But from the mikrotik side these subnets pinging. What may it be?
Last edited by andrace on Tue Sep 23, 2014 3:02 pm, edited 1 time in total.
 
Zorro
Long time Member
Long time Member
Posts: 675
Joined: Wed Apr 16, 2014 2:43 pm

Re: magic of icmp

Tue Sep 23, 2014 2:43 pm

probably something different with D-link DFL defaults. thats why i like their conventional DSR devices - bit more, despite lack of some features and similarly ancient processors.
you should extensively check DFL manual i suppose.
 
andrace
newbie
Topic Author
Posts: 42
Joined: Sun Sep 21, 2014 8:41 am

Re: magic of icmp

Tue Sep 23, 2014 3:01 pm

Before was the DFL instead the mikrotik and all worked. But after replacement not working only ICMP, all other traffic passing correctly. I can't understand where I need to dig/
 
andrace
newbie
Topic Author
Posts: 42
Joined: Sun Sep 21, 2014 8:41 am

Re: magic of icmp

Sun Sep 28, 2014 4:52 pm

found no solution till this time. Anybody can make another advise how to resolve this issue
 
andrace
newbie
Topic Author
Posts: 42
Joined: Sun Sep 21, 2014 8:41 am

Re: magic of icmp

Fri Oct 03, 2014 7:02 pm

bump
 
andrace
newbie
Topic Author
Posts: 42
Joined: Sun Sep 21, 2014 8:41 am

Re: magic of icmp

Fri Dec 05, 2014 7:36 pm

The problem is still here
 
User avatar
BartoszP
Forum Guru
Forum Guru
Posts: 3095
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: magic of icmp

Fri Dec 05, 2014 9:46 pm

I use DFL800 too and process of switching my mind from DFL to Mikrotik is still painfull.
What does mean "all working" ? Is there eg. WWW on 75's subnet accessible from 250's one ? Are 250's devices visible from 75's subnet ? More datails please.
IMHO Mikrotik does not know where the 250 subnet is and you need set the static route on mikrotik to 10.x.x.x. DFL sets many rules automatically and you do not even know that eg. new route is created during IPSEC tunell creation.
 
andrace
newbie
Topic Author
Posts: 42
Joined: Sun Sep 21, 2014 8:41 am

Re: magic of icmp

Wed Feb 18, 2015 2:03 pm

The problem solved. ( incorrect rules on the dfl side )