Community discussions

MikroTik App
 
sebus504
newbie
Topic Author
Posts: 29
Joined: Thu Mar 29, 2012 10:30 pm

ipsec three subnet

Fri Sep 30, 2016 2:55 pm

Hello is this config ok?
1
src-address=192.168.7.0/24 src-port=any dst-address=192.168.10.0/24 dst-port=any protocol=all action=encrypt
level=unique ipsec-protocols=esp tunnel=yes sa-src-address=x.x.x.x sa-dst-address=y.y.y.y
proposal=proposal1 priority=0

2
src-address=192.168.7.0/24 src-port=any dst-address=192.168.11.0/24 dst-port=any protocol=all action=encrypt
level=unique ipsec-protocols=esp tunnel=yes sa-src-address=x.x.x.x sa-dst-address=y.y.y.y
proposal=proposal1 priority=0

3
src-address=192.168.7.0/24 src-port=any dst-address=192.168.12.0/24 dst-port=any protocol=all action=encrypt
level=unique ipsec-protocols=esp tunnel=yes sa-src-address=x.x.x.x sa-dst-address=y.y.y.y

my side 192.168.7.0/24
client side: 192.168.10.0/24 (this one works)
192.168.11.0/24
192.168.12.0/24
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7188
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: ipsec three subnet

Fri Sep 30, 2016 5:04 pm

At least policy configuration looks ok.
 
sebus504
newbie
Topic Author
Posts: 29
Joined: Thu Mar 29, 2012 10:30 pm

Re: ipsec three subnet

Fri Sep 30, 2016 5:26 pm

Ok, thanks. So independently what kind of router is on other side that should work?

The rest of config (nat, route)

NAT

chain=srcnat action=accept src-address=192.168.7.0/24 dst-address=192.168.10.0/24 log=no log-prefix=""
chain=srcnat action=accept src-address=192.168.7.0/24 dst-address=192.168.11.0/24 log=no log-prefix=""
chain=srcnat action=accept src-address=192.168.7.0/24 dst-address=192.168.12.0/24 log=no log-prefix=""

ROUTE

dst address pref source gateway
192.168.10.0/24 192.168.7.250 WAN1 19
192.168.11.0/24 192.168.7.250 WAN1 19
192.168.12.0/24 192.168.7.250 WAN1 19

Who is online

Users browsing this forum: johnson73, jvanhambelgium, MrBurger and 73 guests