Community discussions

MikroTik App
 
fermorite
just joined
Topic Author
Posts: 3
Joined: Thu Feb 22, 2024 9:21 am

IPsec identities keep getting disabled

Wed Mar 06, 2024 9:46 am

Hello,

We own a CRS125-24G-1S-2HnD-IN cloud router switch. We have configured IPsec VPN. Our issue is that somehow some specific IPsec identities keep getting disabled without user interaction. We reenable them but after a couple of days, the same identity is disabled again. Can you please help us? Thank you.
 
fermorite
just joined
Topic Author
Posts: 3
Joined: Thu Feb 22, 2024 9:21 am

Re: IPsec identities keep getting disabled

Mon Mar 11, 2024 9:24 am

Can somebody help us ? Thank you.
 
rplant
Member
Member
Posts: 314
Joined: Fri Sep 29, 2017 11:42 am

Re: IPsec identities keep getting disabled

Mon Mar 11, 2024 9:50 am

Hi,
Sorry I don't know what the problem might be, apart from that I don't think you shouldn't be attempting this in the first place.

The CPU isn't very powerful, has no ipsec hardware offload and when you overload it, the switching management functionality will likely suffer.

You could try wireguard (at least cpu usage will be less for same amount of VPN traffic).
Or maybe get a different product for the vpn.

The following all have IPSec hardware and all have more processing power than the switch.
They are somewhat in price and performance order.
(I would still use Wireguard rather than ipsec)

Note: HapAX3 has Level 6 license if that is useful.

Hex,
HapAC2
HapAX2
HapAX3
RB4011
RB5009
 
rplant
Member
Member
Posts: 314
Joined: Fri Sep 29, 2017 11:42 am

Re: IPsec identities keep getting disabled

Tue Mar 12, 2024 12:22 am

Hi,
I thought about it some more, perhaps the following might be useful.
  1. Make a backup, and export of your current config.
  2. Trawl through the export from 1, and make sure there are no dubious scripting entries (system scripts, system scheduler, perhaps dhcp/pppoe scripts) either unknown or (now) incorrect.
  3. Early versions of Ros7 had many many bugs, probably worth upgrading to something recent if not already.
  4. Perhaps some flash corruption/bad blocks, A netinstall apparently helps with this (maps out bad blocks)
    ** Ideally install new config from the export rather than from the backup, (take care, easy to lock yourself out)
  5. Power supply issues can cause many problems, (but likely would be much more visible than just this)
 
fermorite
just joined
Topic Author
Posts: 3
Joined: Thu Feb 22, 2024 9:21 am

Re: IPsec identities keep getting disabled

Tue Mar 12, 2024 9:19 am

Hi,
I thought about it some more, perhaps the following might be useful.
  1. Make a backup, and export of your current config.
  2. Trawl through the export from 1, and make sure there are no dubious scripting entries (system scripts, system scheduler, perhaps dhcp/pppoe scripts) either unknown or (now) incorrect.
  3. Early versions of Ros7 had many many bugs, probably worth upgrading to something recent if not already.
  4. Perhaps some flash corruption/bad blocks, A netinstall apparently helps with this (maps out bad blocks)
    ** Ideally install new config from the export rather than from the backup, (take care, easy to lock yourself out)
  5. Power supply issues can cause many problems, (but likely would be much more visible than just this)
Thank you so much for your reply. I will follow the above steps and will inform you with the result. Thank you.

Who is online

Users browsing this forum: Ahrefs [Bot], Bing [Bot], CHUPAPEE and 39 guests