Community discussions

MikroTik App
 
metman
just joined
Topic Author
Posts: 13
Joined: Wed Mar 04, 2015 5:05 am

Gre Over IPsec Miktotik to MIKROTIK

Thu Mar 05, 2015 10:52 pm

hi
I try to make a tunnel between mikrotik-mikrotik
Gre over Ipsec
according to this pic
is it correct?

Ip public(2.185.1.1 - 2.185.2.2)
Lan (192.168.1.0 --192.168.226.0)
Gre (172.16.16.1 - 172.16.16.2)

after gre config Ip Peer is gre-ip or public-ip , In Policy Public or gre


Image
 
User avatar
shadowskippie
Member Candidate
Member Candidate
Posts: 213
Joined: Tue Dec 21, 2010 6:20 pm

Re: Gre Over IPsec Miktotik to MIKROTIK

Fri Mar 06, 2015 8:39 am

Why are you specifically using GRE

why don't you just use L2TP with IPSEC over that.
 
metman
just joined
Topic Author
Posts: 13
Joined: Wed Mar 04, 2015 5:05 am

Re: Gre Over IPsec Miktotik to MIKROTIK

Sat Mar 07, 2015 5:02 am

Hi
Why L2TP ?
L2TP or Gre or IPIP?
I try to connect 8 org in different cities by Public IP on internet?
 
User avatar
ZeroByte
Forum Guru
Forum Guru
Posts: 4047
Joined: Wed May 11, 2011 6:08 pm

Re: Gre Over IPsec Miktotik to MIKROTIK

Sat Mar 07, 2015 5:32 am

The only thing that looks off to me is the local/remote traffic selectors for IPSec. Those should match GRE src=localWan dst=remoteWan

IPSec won't see the packets inside the GRE tunnel - only the GRE itself.

The nice thing about GRE over IPSec is that you can route any IP across the tunnel you like without having to change the IPSec traffic selectors. You can even run OSPF over the tunnels and all sites will automatically know how to reach all other sites. Easily supports hub-and-spoke topology - less configuration whenever a new site comes online.
etc.
 
metman
just joined
Topic Author
Posts: 13
Joined: Wed Mar 04, 2015 5:05 am

Re: Gre Over IPsec Miktotik to MIKROTIK

Sat Mar 07, 2015 8:58 pm

IPIP tunnel is better or Gre tunnel over ipsec (for security)

all 8 point have mik.rb

internet : 2mb speed with ip public

2mb is enough?

now ping with 230ms..? why (by ipip/ipsec) very slow
 
User avatar
ZeroByte
Forum Guru
Forum Guru
Posts: 4047
Joined: Wed May 11, 2011 6:08 pm

Re: Gre Over IPsec Miktotik to MIKROTIK

Sat Mar 07, 2015 9:55 pm

Which model routerboard do you have? IPSEC can eat a lot of CPU.
 
metman
just joined
Topic Author
Posts: 13
Joined: Wed Mar 04, 2015 5:05 am

Re: Gre Over IPsec Miktotik to MIKROTIK

Sun Mar 08, 2015 7:10 am

RB 750gl ic cities + RB2011UAS in main office
 
User avatar
ZeroByte
Forum Guru
Forum Guru
Posts: 4047
Joined: Wed May 11, 2011 6:08 pm

Re: Gre Over IPsec Miktotik to MIKROTIK

Sun Mar 08, 2015 6:27 pm

I could see a 2011 not being powerful enough if you have much traffic going between 8 sites at the same time, especially if all 8 sites are tunneling through the main site for Internet access.
Check your CPU utilization in system resources.
 
metman
just joined
Topic Author
Posts: 13
Joined: Wed Mar 04, 2015 5:05 am

Re: Gre Over IPsec Miktotik to MIKROTIK

Mon Mar 09, 2015 8:17 pm

HI
I try to complete my design
but in my cities in left mik. routerboarad cannot ping cisco
i describe in below pic
Image
 
User avatar
ZeroByte
Forum Guru
Forum Guru
Posts: 4047
Joined: Wed May 11, 2011 6:08 pm

Re: Gre Over IPsec Miktotik to MIKROTIK

Mon Mar 09, 2015 8:44 pm

HI
I try to complete my design
but in my cities in left mik. routerboarad cannot ping cisco
I bet the Cisco has a default GW other than 192.168.226.11, and no static route for 195.132.57.0/24

Any host using 192.168.226.9 as the default GW will also be unable to reach PC1 if this is true.

Fix in cisco:
config t
ip route 195.132.57.2 255.255.255.0 192.168.226.11
ip route 172.151.1.0 255.255.255.252 192.168.226.11
end
(or use the correct netmask for the IPIP tunnel if it's not a /30)

Any hosts on the other side of the Cisco will need correct routes as well.

Who is online

Users browsing this forum: gianry and 21 guests