Community discussions

MikroTik App
 
User avatar
AlexPebody
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 54
Joined: Fri Nov 12, 2021 3:50 pm

IPSec Mode Config issue

Tue Oct 10, 2023 5:57 pm

Hi guys )

Could you tell me please... I am using Mikrotik VPN to access external servers like 78.140.200.18 (for example) and the same for internal lan 192.168.150.0/24 (for example) and Windows OS working fine all routes pushes and no any troubles, but on Macbook not working if I using Split Include 78.140.200.18 only, all is ok, but together with 192.168.150.0/24 - not working... ( I think some issue with IKEv2 traffic and some other issues... maybe 192.168.150.0/24 set limit for 78.140.200.18, if I set 0.0.0.0/0 all working, but all Internet tfaffic going through MIkrotik VPN, but I need only Split Include routes. How can I do this? Other way, like L2TP VPN for Macbook where I can set Gateway default, because in Macbook IKEv2 by default all traffic want going through VPN and Macbook haven't settings gateway for IKEv2... So many thx! p.s About Firewall Mikrotik, for test and 1st rule I set allow for 192.168.150.0/24 and 78.140.200.18 ofcourse. And my IPSec Policy is 0.0.0.0/0 to 172.16.0.0/24 - VPN internal IP's.
 
User avatar
Kentzo
Long time Member
Long time Member
Posts: 631
Joined: Mon Jan 27, 2014 3:35 pm
Location: California

Re: IPSec Mode Config issue

Tue Oct 10, 2023 10:23 pm

For IKEv2 you should be able to ditch the split-include extension and configure proper traffic selectors.

IIRC on macOS IKEv2 client respects only the first network in the split. Didn't test this in a while though, because see above.