Hello.
I want to "IPSec from Mikrotik Router (1) behind other Router (2) with NAT and dynamic IP to Mikrotik Router (3) with public fixed IP" ...
I have one Mikrotik Router (1) that's inside an existing LAN, the LAN is behind an existing Router (2) that has NAT to the WAN Interface with dynamic IP. The other Mikrotik Router (3) has an fixed public IP.
Please see my attached paper with details.
I only want to use IPSec. The Router (2) has free access to WAN but accepts only stateful answer pakets. Network 10.10.16.0/24 should get access to network 10.10.15.0/24 - only one direction.
Is it this possible at all?
I have a config. Policy is only configured on the inside Mikrotik (1). But what "sa-src-address" do have to use there? On the other side (3) I configured "address=0.0.0.0/0" to welcome all IPs from WAN. How can IP pakets get back to the inside Mikrotik (1)? The public IP from Router (2) is not shown on Router (3).
Happy to get some input - Thanks !!