Community discussions

MikroTik App
 
wa4zlw
Member Candidate
Member Candidate
Topic Author
Posts: 177
Joined: Sat Jun 03, 2006 10:37 pm
Location: Blandon, PA
Contact:

OSPF and IPSec tunnels

Sun Jan 13, 2013 4:08 am

Hi there

I've got OSPF running and it seems to be ok but we have an IPSec tunnel to a friends house which terminates on a fortinet firewall and we can't get OSPF working.
I do have OSPF working over a PPTP link to another mikrotik and two mikrotiks in the house. all in same area.

any ideas?

Thanks Leon
 
faisali
Member Candidate
Member Candidate
Posts: 180
Joined: Fri Oct 08, 2010 5:11 am

Re: OSPF and IPSec tunnels

Sun Jan 20, 2013 12:02 am

Speaking in general..

What do you want to accomplish by running OSPF to the Fortinet via IPSec Tunnel ?

When running dynamic protocols in a tunnel, one has to pay attention to a few key items.

1. You have to setup the External Routing as static, so that when you activate the dynamic routing protocol, the external routes don't get overridden by the routes being exchanged via the dynamic routes.
2. If you have a multi-homed connection, you need to have a mechanism to make sure packets entering the router via one interface go back out via the same interface / connection.

Of course there is more to it ..
so back to the first question.. What are you trying to accomplish ?
 
User avatar
nz_monkey
Forum Guru
Forum Guru
Posts: 2104
Joined: Mon Jan 14, 2008 1:53 pm
Location: Over the Rainbow
Contact:

Re: OSPF and IPSec tunnels

Sun Jan 20, 2013 6:13 am

Hi there

I've got OSPF running and it seems to be ok but we have an IPSec tunnel to a friends house which terminates on a fortinet firewall and we can't get OSPF working.
I do have OSPF working over a PPTP link to another mikrotik and two mikrotiks in the house. all in same area.

any ideas?

Thanks Leon
You need to run GRE over IPSEC to the Fortigate. This is CLI only on the FortiGate.

Normally you would just run VTI but Mikrotik do not support it :(

I have been lobbying Mikrotik for 5 years now to get them to add VTI support to their IPSEC implementation, so far with no success (Hi Janis). Maybe one day...
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: OSPF and IPSec tunnels

Thu Jan 24, 2013 6:48 pm

You can run IPIP tunnel over ipsec and set OSPF on IPIP.

Who is online

Users browsing this forum: Ahrefs [Bot], seriousblack, vetal12311 and 78 guests