Community discussions

MikroTik App
 
snarkyboojum
just joined
Topic Author
Posts: 2
Joined: Wed Jan 02, 2013 8:03 am

RouterBOARD suggestion for VPN

Wed Jan 02, 2013 8:09 am

Hi guys,

I'm wondering what is the simplest, and cheapest RouterBOARD option for doing IPSec VPN using BGP. My VPN requirements are:

- IKE using pre-shared keys
- IPSec SAs in tunnel mode
- AES 128 bit encryption function
- SHA-1 hash function
- Diffie-Hellman PFS in group 2 mode
- Do packet fragementation prior to encryption
- BGP support
- Route based VPN (bind tunnels to logical interfaces)
- IPSec dead peer detection

Keen to buy some devices and play around with them if I can get hardware supporting all of the above.

Cheers,
Adrian.
 
snarkyboojum
just joined
Topic Author
Posts: 2
Joined: Wed Jan 02, 2013 8:03 am

Re: RouterBOARD suggestion for VPN

Fri Jan 04, 2013 6:38 am

*Bump* - anyone have any suggestions/ideas?
 
User avatar
tomaskir
Trainer
Trainer
Posts: 1162
Joined: Sat Sep 24, 2011 2:32 pm
Location: Slovakia

Re: RouterBOARD suggestion for VPN

Fri Jan 04, 2013 10:35 am

Any RouterBoard will do all of this, is just depends on how much traffic you need passing through the IPSec encryption engine. One thing tho:

- Route based VPN (bind tunnels to logical interfaces)
You will have to use a GRE logical tunnel and use IPSec in transport mode. But then you can do OSPF over the links.

Who is online

Users browsing this forum: Bing [Bot], GoogleOther [Bot], Semrush [Bot], techcomtecnico and 130 guests