Page 1 of 1

Inter-VLAN Routing Across IPSec VPN

Posted: Thu Mar 17, 2022 6:57 pm
by t04s
RouterOS: v6.48.4
Router: CCR1036-12G-4S


We have a remote site with four VLANs configured such as;

  • Management VLAN -
  • VLAN 1 -
  • VLAN 2 -
  • VLAN 3 -

Inter-VLAN routing is enabled and we restrict back VLAN traffic using the built-in firewall. Locally, we can connect to the Management VLAN and can ping the local VLAN gateways and also any devices which are allowed to pass-through the firewall.

Now, on the local network we have a subnet and this is connected via IPSec VPN to the remote Management VLAN This allows local admins to access and administer the remote network. The problem is when we connect over VPN Inter-VLAN routing is no longer functional and we can't ping/access any of the VLAN gateways. It doesn't seem to be a firewall problem as you would still expect to get a response from the VLAN gateways and there are allow rules permitting traffic from the local network.

As a workaround we have configured multiple phase twos on the VPN whereby we have a phase two per subnet. This is sub-optimal from a security perspective as we're now connecting our local network directly to each remote VLAN, which is bypassing the security policy. Ideally, we want to be able connect into the management network and route traffic as normal to the other VLANs, respecting the firewall rules accordingly.

Does anybody know a way to achieve this?


Re: Inter-VLAN Routing Across IPSec VPN

Posted: Wed May 11, 2022 7:29 pm
by t04s
Does anyone have any ideas about the best way to achieve this?


Re: Inter-VLAN Routing Across IPSec VPN

Posted: Wed May 11, 2022 8:30 pm
by anav
Surely someone in your organization is certified on MT IPSEC?
If not -

Re: Inter-VLAN Routing Across IPSec VPN

Posted: Wed May 11, 2022 8:36 pm
by t04s
I'm sorry, I thought this was a forum to post questions and ask for help... otherwise what's the point of it?


Re: Inter-VLAN Routing Across IPSec VPN

Posted: Wed May 11, 2022 9:37 pm
by anav
Well, hopefully somebody will come by and provide that assistance. Since you have a work around, the business you are supporting can wait until a better solution is found, or they can hire someone trained.

Re: Inter-VLAN Routing Across IPSec VPN

Posted: Wed May 11, 2022 9:48 pm
by t04s
I'm not sure what business or organisation you are referring to.

There already is a better solution in place so it's not an issue. This was a question purely for understanding. If you don't want to contribute, discuss and/or help then I don't understand what the purpose of you responding is.

Re: Inter-VLAN Routing Across IPSec VPN

Posted: Wed May 11, 2022 10:01 pm
by Larsa
Hi t04s!

If both the remote and local site consists of Mikrotik boxes it would help if you are able to show the respective configuration (ie "/export -hide-sensitive") that we can analyze and discuss further about.

Re: Inter-VLAN Routing Across IPSec VPN

Posted: Wed May 11, 2022 10:28 pm
by t04s
Hi Larsa,

Thanks for the reply. Unfortunately the local side is a Draytek 3910 but I can certainly get that from the remote side.

No problem, I'll come back on that.


Re: Inter-VLAN Routing Across IPSec VPN

Posted: Sun May 15, 2022 1:04 am
by t04s

When reviewing this, I'm not sure what specific configuration you would like me to provide? I don't think I explained fully, but both sides are not Mikrotik devices for the IPSec VPN connection. On the side in question the Mikrotik is uplinked to a firewall that provides WAN, NAT, Internet firewall, VPN. The Mikrotik provides local routing and firewalling between VLANs.

So the problem is when I connect into the Management VLAN, I can only access resources on that subnet which is expected. I'm trying to make the further VLAN subnets accessible so I assume I may need to mark and route the IPSec traffic, or similar?


Re: Inter-VLAN Routing Across IPSec VPN

Posted: Sun May 15, 2022 2:34 am
by tdw
No. There are no 'IPsec interfaces' to apply routes to as Mikrotik do not implement an equivalent of Cisco VTI, or similar by other manufacturers.

IPsec policies match traffic to be transported or tunneled based on some combination of addresses, protocols and ports. A packet matching a policy gets encapsulated on egress and decapsulated on ingress. See ... Interfaces