Community discussions

MikroTik App
 
dalami
Member Candidate
Member Candidate
Topic Author
Posts: 156
Joined: Mon Dec 12, 2011 9:18 am

Layer 2 tunnel via IPSEC/IKEv2

Tue Jan 28, 2020 2:52 am

I've got working connections from multiple remotes to my primary router via IPSEC. Each remote peer is defined in "/ip ipsec" with their signatures, mode config, etc. The exchange modes are all "IKE2" - I don't know if that means my tunnels are IKEv2 or not. But I do seem to have good layer 3 connections.

Now I need the ability for full layer 2 tunneling. There's a lot of options and I don't know which to go with. At the moment the IPSEC nodes are all Mikrotik so I'm not interoperating with anything else - today. Possibly with a Windows or Android client - no other networking gear will be involved.

Looking at some of the tunnel interface options I see configuration choices for IPSEC. Does this mean such tunnels establish their own IPSEC connections independent of the configuration of "/ip ipsec"? What method should I start with given my current configuration?
 
User avatar
ingdaka
Trainer
Trainer
Posts: 457
Joined: Thu Aug 30, 2012 3:06 pm
Location: Albania
Contact:

Re: Layer 2 tunnel via IPSEC/IKEv2

Tue Jan 28, 2020 3:06 pm

If you need L2 Tunneling and all devices are Mikrotik user EoIP.
 
dalami
Member Candidate
Member Candidate
Topic Author
Posts: 156
Joined: Mon Dec 12, 2011 9:18 am

Re: Layer 2 tunnel via IPSEC/IKEv2

Wed Jan 29, 2020 7:17 am

Thank you - I'll look at EoIP again. What is the difference between using the existing IPSEC connections and configuring the EoIP interfaces with internal IP's compared with explicitly setting IPSEC secrets and external IP's in the EoIP interfaces?
 
kermu
just joined
Posts: 11
Joined: Fri Nov 26, 2010 11:59 pm

Re: Layer 2 tunnel via IPSEC/IKEv2

Sun Aug 22, 2021 1:26 pm

If you need L2 Tunneling and all devices are Mikrotik user EoIP.
But for IPSEC on particular devices is possible to use hardware acceleration as opposed to EoIP.

Who is online

Users browsing this forum: DanMos79 and 50 guests