Building my first system with Mikrotik Routers - and trying to get the foillowing up and running.
HQ - 192.168.201.0/24 - Public IP 78.111.168.100
BO - 192.168.202.0/24 - Public IP 78.111.168.210 -------------------------------------------------------------------------------------------
Actually I think I've got the actual tunnel running - from what I can see in the logfile:
Code: Select all
DPD R-U-There-Ack- recieved
Recieved an R-U-ThereACK
Code: Select all
Filter Rules:
1 chain=input action=accept src-address=192.168.201.0/24 in-interface=WAN log=yes log-prefix="VPN"
NAT RULES:
0 ;;; Nat to Gannebro
chain=srcnat action=accept to-addresses=0.0.0.0 src-address=192.168.201.0/24 dst-address=192.168.202.0/24 log=yes log-prefix="VPN"
1 ;;; Nat From Gannebro
chain=dstnat action=dst-nat to-addresses=192.168.201.0/24 src-address=192.168.202.0/24 dst-address=192.168.201.0/24 log=yes log-prefix="From Gannebro"
VPN PEER:
0 address=78.111.168.210/30 local-address=:: passive=no port=500 auth-method=pre-shared-key secret="*********" generate-policy=no
policy-template-group=default exchange-mode=main send-initial-contact=no nat-traversal=yes proposal-check=obey hash-algorithm=sha1
enc-algorithm=aes-256 dh-group=modp1024 lifetime=1d lifebytes=0 dpd-interval=2m dpd-maximum-failures=
VPN POLICY:
src-address=192.168.201.0/24 src-port=any dst-address=192.168.202.0/24 dst-port=any protocol=all action=encrypt level=require ipsec-protocols=esp
tunnel=yes sa-src-address=78.111.168.100 sa-dst-address=78.111.168.210 proposal=default priority=0
VPN Proposal:
name="default" auth-algorithms=sha1 enc-algorithms=aes-256-cbc lifetime=30m pfs-group=non
ROUTE:
3 A S 192.168.202.0/24 WAN 1
Code: Select all
Filter Rules:
1 ;;; Incoming NAT FROM HQ
chain=input action=accept src-address=192.168.201.0/24 log=yes log-prefix="VPN"
NAT Rules:
0 ;;; Nat To HQ
chain=srcnat action=accept src-address=192.168.202.0/24 dst-address=192.168.201.0/24 log=no log-prefix=""
1 ;;; Nat From HQ
chain=dstnat action=dst-nat to-addresses=192.168.202.0/24 src-address=192.168.201.0/24 dst-address=192.168.202.0/24 log=no log-prefix="FromHQ"
VPN PEER:
0 address=78.111.168.100/30 local-address=:: passive=no port=500 auth-method=pre-shared-key secret="******" generate-policy=no policy-template-group=default exchange-mode=main send-initial-contact=yes nat-traversal=yes proposal-check=obey hash-algorithm=sha1 enc-algorithm=aes-256 dh-group=modp1024 lifetime=1d lifebytes=0 dpd-interval=2m dpd-maximum-failures=5
VPN POLICY:
1 src-address=192.168.202.0/24 src-port=any dst-address=192.168.201.0/24 dst-port=any protocol=all action=encrypt level=require ipsec-protocols=esp tunnel=yes sa-src-address=78.111.168.210 sa-dst-address=78.111.168.100 proposal=default priority=0
Proposal
1 name="default" auth-algorithms=sha1 enc-algorithms=aes-256-cbc lifetime=30m pfs-group=none
ROUTE:
2 A S 192.168.201.0/24 WAN
I've allso tried to create some route on each But cannot get any connection between the 2 different locations - Can anyone se what am I missing here !