Page 1 of 1

magic of icmp

Posted: Tue Sep 23, 2014 8:38 am
by andrace
Hi all. Please advise me.
I have such scheme :

[192.168.250.0/23]--------[10.10.0.0/24(DFL800)]---IPSEC-----[192.168.75.0/24(Mikrotik)]

I made an ipsec channel between dfl800 and mikrotik but have a little problem

All working excluding an icmp traffic from 192.168.250.0/23 and 10.10.0.0/24 to 192.168.75.0/24
And also I see no dropped or other icmp traffic on the mikrotik.
But from the mikrotik side these subnets pinging. What may it be?

Re: magic of icmp

Posted: Tue Sep 23, 2014 2:43 pm
by Zorro
probably something different with D-link DFL defaults. thats why i like their conventional DSR devices - bit more, despite lack of some features and similarly ancient processors.
you should extensively check DFL manual i suppose.

Re: magic of icmp

Posted: Tue Sep 23, 2014 3:01 pm
by andrace
Before was the DFL instead the mikrotik and all worked. But after replacement not working only ICMP, all other traffic passing correctly. I can't understand where I need to dig/

Re: magic of icmp

Posted: Sun Sep 28, 2014 4:52 pm
by andrace
found no solution till this time. Anybody can make another advise how to resolve this issue

Re: magic of icmp

Posted: Fri Oct 03, 2014 7:02 pm
by andrace
bump

Re: magic of icmp

Posted: Fri Dec 05, 2014 7:36 pm
by andrace
The problem is still here

Re: magic of icmp

Posted: Fri Dec 05, 2014 9:46 pm
by BartoszP
I use DFL800 too and process of switching my mind from DFL to Mikrotik is still painfull.
What does mean "all working" ? Is there eg. WWW on 75's subnet accessible from 250's one ? Are 250's devices visible from 75's subnet ? More datails please.
IMHO Mikrotik does not know where the 250 subnet is and you need set the static route on mikrotik to 10.x.x.x. DFL sets many rules automatically and you do not even know that eg. new route is created during IPSEC tunell creation.

Re: magic of icmp

Posted: Wed Feb 18, 2015 2:03 pm
by andrace
The problem solved. ( incorrect rules on the dfl side )