Community discussions

MikroTik App
 
infused
Member
Member
Topic Author
Posts: 313
Joined: Fri Dec 28, 2012 2:33 pm

IPSec spoke wan issue

Fri Jun 30, 2017 2:36 am

Hi Guys.

Is there anyway to have each router endpoint in an ipsec wan able to talk to each other?

If we configure DNS on one of the ipsec routers to use DNS of a sever in another network, the traffic routes out the wan. even with nat src rules in place.
 
nescafe2002
Forum Veteran
Forum Veteran
Posts: 915
Joined: Tue Aug 11, 2015 12:46 pm
Location: Netherlands

Re: IPSec spoke wan issue

Fri Jun 30, 2017 4:12 am

Add a route for remote subnet via lan interface. This way the MT will pick correct source IP address.
 
idlemind
Forum Guru
Forum Guru
Posts: 1146
Joined: Fri Mar 24, 2017 11:15 pm
Location: USA

Re: IPSec spoke wan issue

Fri Jun 30, 2017 9:14 am

Do you mean dynamic spoke to spoke traffic? That's more of a feature of Cisco's DMVPN and isn't available in RouterOS.

If you mean traffic from a spoke to another spoke through the hub then that's totally possible. You shouldn't need NAT rules, particularly NAT exclusion styled rules. You just need to route the traffic appropriately. You can use OSPF with NBMA neighbors or BGP if you are using IPSec with L2TP or if you are using GRE wrapped in IPSec OSPF or RIP will via multicast and exchange routes.

Who is online

Users browsing this forum: benonet, dogenzenji, jaclaz, nekrikstas and 68 guests