Community discussions

MikroTik App
 
aleitongci
just joined
Topic Author
Posts: 11
Joined: Tue Nov 22, 2016 10:48 pm

IPSEC VPN Multiples Subnets

Wed Sep 11, 2024 11:57 pm

Hello,

I have been implementing VPNs IPSEC Site to Site but have been facing that i am able to use only one subnet. If I configured more that one subnet on the polices and the nat settings, but only one subnet has communication end to end.
Does anyone faced this issue before?

Kind Regards,
 
User avatar
patrikg
Member
Member
Posts: 362
Joined: Thu Feb 07, 2013 6:38 pm
Location: Stockholm, Sweden

Re: IPSEC VPN Multiples Subnets

Thu Sep 12, 2024 8:29 am

Sounds like you need to add some static routes.
If you can provide some diagram of what you want to achieve, it is a little easier for the members of the forum to help you.
 
User avatar
sindy
Forum Guru
Forum Guru
Posts: 11115
Joined: Mon Dec 04, 2017 9:19 pm

Re: IPSEC VPN Multiples Subnets

Thu Sep 12, 2024 9:30 am

If I configured more that one subnet on the polices and the nat settings, but only one subnet has communication end to end.
Set the level of all the policies you've added to unique. If that does not help, post the configuration exports from both devices.
 
aleitongci
just joined
Topic Author
Posts: 11
Joined: Tue Nov 22, 2016 10:48 pm

Re: IPSEC VPN Multiples Subnets

Thu Sep 12, 2024 5:57 pm

Hello.
Attached topology, its very straight forward, i got a server on one end and several networks at the other end. The only way to make this work is summarizing the remote networks in just one line, but its not scalable at all and sometimes its not possible.
Have you ever add several network segments to an ipsec tunnel on mikrotik?
Best Regards,
You do not have the required permissions to view the files attached to this post.
 
BrunoLeao
just joined
Posts: 8
Joined: Thu Jun 11, 2020 3:49 pm
Location: Sao Paulo / Brazil
Contact:

Re: IPSEC VPN Multiples Subnets

Thu Sep 12, 2024 6:10 pm

So use BGP, configure it and put the summarized prefix.
 
aleitongci
just joined
Topic Author
Posts: 11
Joined: Tue Nov 22, 2016 10:48 pm

Re: IPSEC VPN Multiples Subnets

Thu Sep 12, 2024 6:17 pm

Hello,

I already used BGP and a summarized route and it works. But now i am facing another site in which summarization is not possible.
 
BrunoLeao
just joined
Posts: 8
Joined: Thu Jun 11, 2020 3:49 pm
Location: Sao Paulo / Brazil
Contact:

Re: IPSEC VPN Multiples Subnets

Tue Sep 17, 2024 4:30 am

Hello,

I already used BGP and a summarized route and it works. But now i am facing another site in which summarization is not possible.
Oh, now i see. Vpn with cisco is a bit anoying. Just go to ipsec > policies > action and set unique on the tunnel policy.
You do not have the required permissions to view the files attached to this post.
 
aleitongci
just joined
Topic Author
Posts: 11
Joined: Tue Nov 22, 2016 10:48 pm

Re: IPSEC VPN Multiples Subnets

Fri Sep 27, 2024 5:38 pm

Hello BrunoLeao,

It works!! I configured ipsec policies as unique for all subnets and its working properly.

Thanks so much for your valuable help.

Regards.

Who is online

Users browsing this forum: Artemis and 22 guests