Community discussions

MikroTik App

Search found 19 matches

by xpkiller
Mon Mar 10, 2014 6:29 pm
Forum: Beginner Basics
Topic: Allow users to internet for ARP list only
Replies: 3
Views: 4861

Re: Allow users to internet for ARP list only

I need static ARP because PCI-DSS..
and I tried make static in /ip arp but I get this: "Couldn't add New ARP - already have such arp (6)"
I have 6.5 and 6.7 os versions.
What could be the problem?
by xpkiller
Tue May 15, 2012 4:58 pm
Forum: General
Topic: ipsec VPN with srcnat
Replies: 3
Views: 1443

Re: ipsec VPN with srcnat

The problem is not on my side. The partner has wrong config.
I have bulit a test system and I simulated each side and my config is good.
by xpkiller
Sun May 13, 2012 3:48 pm
Forum: General
Topic: ipsec VPN with srcnat
Replies: 3
Views: 1443

Re: ipsec VPN with srcnat

So, I have two policy route rule for this ipsec. Question, can I have two policy rule for one ipsec peer? If don't then how can I solve this? I need to route to remote side two exact IP (not a net) eg. 10.1.42.27 and 10.1.48.193 therefore I made it. If I have two policy route then I will have two SA...
by xpkiller
Fri May 11, 2012 8:30 pm
Forum: General
Topic: ipsec VPN with srcnat
Replies: 3
Views: 1443

Re: ipsec VPN with srcnat

I don't know what would be the problem.
I made packet-sniffer and other ...now I think packet go to good interface but only one IP.
About the second IP I don't see where does it want to go. I see when it come from server but I don't see when it goes to out.
by xpkiller
Thu May 10, 2012 12:54 am
Forum: General
Topic: ONE Ipsec VPN restart
Replies: 4
Views: 5365

Re: ONE Ipsec VPN restart

New problem is that if I change or add a new ipsec/vpn peer then all established vpn is disconnected until I flush all SA :(
by xpkiller
Thu May 10, 2012 12:51 am
Forum: General
Topic: Q: VPN L2TP/IPSec
Replies: 30
Views: 8503

Re: Q: VPN L2TP/IPSec

Someone should rename this topic to a more meaningful name. Anyhow, same problem here with L2TP/IPSec and multiple clients behind one public IP. Is there really no solution or workaround? OpenVPN w/ mikrotik isn't a solution since UDP support is missing; PPTP on the other hand isn't secure. Why can...
by xpkiller
Thu May 10, 2012 12:17 am
Forum: General
Topic: ipsec VPN with srcnat
Replies: 3
Views: 1443

ipsec VPN with srcnat

Hi, I have a problem. We have a lot of ipsec vpn and leased line and we are using vlan and other things but we don't have ipsec vpn with srcnat yet (only dnat) Unfortunately we have a partner and it need 10.0.0.0/8 and therefore I have a static route for it. But, now I need a new ipsec vpn and remot...
by xpkiller
Tue Apr 24, 2012 11:58 pm
Forum: General
Topic: Q: VPN L2TP/IPSec
Replies: 30
Views: 8503

Re: Q: VPN L2TP/IPSec

Don't use i- pad/phone.. use Linux/Android.. ;)

so you can chose a simple client for openvpn: http://openvpn.net/index.php/open-source.html it is working well.
(and Linux knows openvpn basically)
by xpkiller
Tue Apr 10, 2012 4:35 pm
Forum: General
Topic: Q: VPN L2TP/IPSec
Replies: 30
Views: 8503

Re: Q: VPN L2TP/IPSec


I had about 60 VPN users and they are offten on the same remote LAN and need to connect to office, but they cant...
Ok, but this is not problem of the mikrotik!
This is a property of ipsec.
a solution: use openvpn
by xpkiller
Tue Apr 10, 2012 12:53 pm
Forum: General
Topic: Q: VPN L2TP/IPSec
Replies: 30
Views: 8503

Re: Q: VPN L2TP/IPSec

and how could you test it? from same public IP? because ipsec can not generate policy rule if you come same public IP. (I tested it) eg. if your users behind same firewall and it has a public IP and it is NATing your users then they will be shown with same public IP this is what I need to solve. I ...
by xpkiller
Sun Apr 08, 2012 12:18 pm
Forum: General
Topic: Q: VPN L2TP/IPSec
Replies: 30
Views: 8503

Re: Q: VPN L2TP/IPSec

Please check assigned IPs for userA and userB. Do you use pool for local and remote IP assignements? Solutions: 1. you assign from pool but you need set for local and remote too!! (you can not give fix IP for local and dynamic for remote! because /30 mask) 2. you give fix IP for local and remote too...
by xpkiller
Fri Apr 06, 2012 8:03 pm
Forum: General
Topic: Q: VPN L2TP/IPSec
Replies: 30
Views: 8503

Re: Q: VPN L2TP/IPSec

Ok, you are right! Need NAT-T for NATed user. But I don't understand your all config because I tested today with my 1100AH (ROS 5.14) and I needed this: mod: I tested with: win7, winXP and Android phone are working well. 1. (you need separate l2tp-server /user with user-name) /interface l2tp-server ...
by xpkiller
Fri Apr 06, 2012 12:26 am
Forum: General
Topic: Q: VPN L2TP/IPSec
Replies: 30
Views: 8503

Re: Q: VPN L2TP/IPSec

"nat-traversal=yes "
Why?

and where is this?
add action=accept chain=input disabled=no protocol=ipsec-esp in-interface=eth01.WAN;
(ip protocol 50 for ESP)
by xpkiller
Fri Apr 06, 2012 12:05 am
Forum: General
Topic: ONE Ipsec VPN restart
Replies: 4
Views: 5365

Re: ONE Ipsec VPN restart

Yes, but this is the problem: /ip ipsec installed-sa flush sa-type=all that I have written I can not flush all SA because I have a lot of ipsec VPN and all tunnel under using and if I flush all SA then all TCP opened session will be lost. Therefore I am waiting this feature. (that I can restart one ...
by xpkiller
Fri Apr 06, 2012 12:02 am
Forum: General
Topic: Q: VPN L2TP/IPSec
Replies: 30
Views: 8503

Re: Q: VPN L2TP/IPSec

What is your ROS version??
by xpkiller
Thu Apr 05, 2012 11:56 pm
Forum: General
Topic: Q: VPN L2TP/IPSec
Replies: 30
Views: 8503

Re: Q: VPN L2TP/IPSec

I think you have one l2tp server (?) and one secret config (?) if you have a lot of user you need separetly secret and l2tp server for each user. (but this is a idea I haven't done l2tp only openvpn and ipsec tunnel) yes, there is posibility to turn on only one server and users are dynamic no, ever...
by xpkiller
Tue Mar 27, 2012 10:50 pm
Forum: General
Topic: ONE Ipsec VPN restart
Replies: 4
Views: 5365

Re: ONE Ipsec VPN restart

I written to support and they have sent answers.
They said I can not restart one ipsec tunnel now but they will put this function to a future OS version.

I am waiting it very!
by xpkiller
Sat Mar 24, 2012 9:32 pm
Forum: General
Topic: Q: VPN L2TP/IPSec
Replies: 30
Views: 8503

Re: Q: VPN L2TP/IPSec

I think you have one l2tp server (?) and one secret config (?) if you have a lot of user you need separetly secret and l2tp server for each user.
(but this is a idea I haven't done l2tp only openvpn and ipsec tunnel)
by xpkiller
Sat Mar 24, 2012 7:19 pm
Forum: General
Topic: ONE Ipsec VPN restart
Replies: 4
Views: 5365

ONE Ipsec VPN restart

Hi, I am new here but not in IT professional. So, we have a lot of mt1100ah and we have a lot of ipsec vpn. Sometimes I have seen vpn is establised but I can not send packet through tunnel. I would like to restart this connection but this feature is not supported just each ipsec tunnel. I can not re...