Community discussions

Search found 29 matches

by iluvar
Sat Jul 19, 2014 9:25 am
Forum: General
Topic: Feature request for v7.x
Replies: 269
Views: 63544

Re: Feature request for v7.x

MSTP
by iluvar
Mon Jul 14, 2014 9:45 am
Forum: General
Topic: Help with IPSec NAT-Traversal
Replies: 16
Views: 17875

Re: Help with IPSec NAT-Traversal

Hey guys!

У меня подобная ситуация:
Привет. Понимаю, что уже прошло больше полугода, но может еще нужен ответ? Или разобрался?
by iluvar
Mon Jul 14, 2014 9:42 am
Forum: General
Topic: lost all vrrp interfaces
Replies: 8
Views: 1718

Re: lost all vrrp interfaces

I have the same problem on RB 1100AHx2 ROS 6.15 (two times).
by iluvar
Sat Sep 28, 2013 11:08 am
Forum: Beginner Basics
Topic: DHCP discover on mesh interface
Replies: 0
Views: 883

DHCP discover on mesh interface

Hi! I have a problem in getting the dhcp-address on the mesh interface. DHCP clients: -mikrotik dhcp client on interface "mesh2" of the same router -laptop, connected to "wlan2" over wi-fi DHCP server on windows server 2012 If I change the interface to bridge, the address gets normally. And also I g...
by iluvar
Thu Jul 11, 2013 10:08 pm
Forum: Beginner Basics
Topic: routing failure with vrrp interface
Replies: 7
Views: 2708

Re: routing failure with vrrp interface

I couldn't get a solution for this problem. I am changing routes with scripts when the interface VRRP changes its status.
On ROS 6.1 all work fine
by iluvar
Sat Mar 30, 2013 1:55 pm
Forum: Beginner Basics
Topic: routing failure with vrrp interface
Replies: 7
Views: 2708

Re: routing failure with vrrp interface

Hi! I have a similar problem.

Does anyone know a solution??
by iluvar
Sat Mar 09, 2013 11:11 pm
Forum: General
Topic: Help with IPSec NAT-Traversal
Replies: 16
Views: 17875

Re: Help with IPSec NAT-Traversal

Вообще-то (теоретически) инициатором выступает устройство MT1, т.е. пользователи из сети 192.168.1.0 (внутренней сети МТ1) подключаются к серверу который в сети 192.168.0.0 (внутренней сети МТ2), так что я чуток в неудомении :) (или я не понимаю правильно концепт "инициализации"?? :D ) МТ1 не может...
by iluvar
Thu Mar 07, 2013 6:29 am
Forum: General
Topic: Help with IPSec NAT-Traversal
Replies: 16
Views: 17875

Re: Help with IPSec NAT-Traversal

А все таки почему не обязательно открывать порт 4500 на Д-Линке? Достаточно, что бы udp4500 был открыт с внешки (не был запрещен в файрволе на wan-интерфейсе), а, поскольку инициатором выступает устройство за натом (MT2), ответные пакеты от MT1 будут так же пересылаться назад к MT2 И на счет netwat...
by iluvar
Tue Mar 05, 2013 9:10 pm
Forum: General
Topic: Help with IPSec NAT-Traversal
Replies: 16
Views: 17875

Re: Help with IPSec NAT-Traversal

Can you please explain shortly why do I need the port 4500
IpSec works through Udp500, but IpSec Nat-T works through Udp4500

and what does the netwatch command do?
Ping remote subnet - run keys generation and creates a tunnel.


Sorry for my english, i`m from Russia :)
by iluvar
Mon Mar 04, 2013 9:26 pm
Forum: General
Topic: Help with IPSec NAT-Traversal
Replies: 16
Views: 17875

Re: Help with IPSec NAT-Traversal

All other settings remain the same?
yes



And should I forward the 4500 port on D-Link?
no
by iluvar
Mon Mar 04, 2013 8:01 pm
Forum: General
Topic: Help with IPSec NAT-Traversal
Replies: 16
Views: 17875

Re: Help with IPSec NAT-Traversal

Hi! I try help. Add to MT1: /ip firewall filter add chain=input comment="Ip-Sec-NatT-UDP 4500" dst-port=4500 protocol=udp Add to MT2: /ip firewall filter add chain=input comment="Ip-Sec-NatT-UDP 4500" dst-port=4500 protocol=udp /ip ipsec peer send-initial-contact=yes /ip ipsec policy sa-src-address=...
by iluvar
Mon Nov 12, 2012 5:53 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Re: Understanding IPSec VPN. Send initial contact or no?

But all works with real MT AH1100x2 with Nat-T

Big thx!
by iluvar
Mon Nov 12, 2012 1:45 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Re: Understanding IPSec VPN. Send initial contact or no?

Does it work for you?
still not working
by iluvar
Mon Nov 12, 2012 5:13 am
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Re: Understanding IPSec VPN. Send initial contact or no?

One more thing you need. You are getting network unreachable ICMP from the routers. How to solve this: as I mentioned before, you dont need routes to oposite side subnets, however, you do need a default route. According to the packet flow diagram, a routing decision is before the IPSec Policy looku...
by iluvar
Sun Nov 11, 2012 10:03 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Re: Understanding IPSec VPN. Send initial contact or no?

Turn OFF proxy-arp and NAT traversal. I would reccomend restarting the routers after turning off those, to clear all caches (arp table, SAs, etc) Nothing has changed [admin@MT1] > export compact file hide-sensitive [admin@MT1] > export compact # nov/11/2012 20:01:52 by RouterOS 5.21 # software id =...
by iluvar
Sun Nov 11, 2012 9:16 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Re: Understanding IPSec VPN. Send initial contact or no?

Please post whole "/export compact" from both Mikrotiks. [admin@MT1] > export compact # nov/11/2012 19:14:40 by RouterOS 5.21 # software id = LNA6-2PWP # /interface ethernet set 0 name="ether1 lan1" set 1 arp=proxy-arp name="ether2 wan" /tool user-manager customer add backup-allowed=yes disabled=no...
by iluvar
Sun Nov 11, 2012 6:54 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Re: Understanding IPSec VPN. Send initial contact or no?

I have created two host machine in subnets [PC1] 192.168.1.11 [PC2] 192.168.2.22 a ping from them [PC2] > tool traceroute 192.168.1.1 # ADDRESS RT1 RT2 RT3 STATUS 1 192.168.2.2 1ms 1ms 1ms network unreach... 2 192.168.2.2 1ms 1ms 0ms network unreach... [PC2] > ping 192.168.1.1 HOST SIZE TTL TIME STA...
by iluvar
Sun Nov 11, 2012 5:50 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Re: Understanding IPSec VPN. Send initial contact or no?

You said it worked in the first post. What have you done since then?
In first post i ping from wan interface (directly connected to second router) and ping working.

Have you tried disabling policy and peer on both routers and then enabling them again?
Yes, i do it
by iluvar
Sun Nov 11, 2012 5:06 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Re: Understanding IPSec VPN. Send initial contact or no?

[MT1] > ip firewall connection print # PROTOCOL SRC-ADDRESS DST-ADDRESS TCP-STATE TIMEOUT 0 icmp 192.168.2.2 192.168.1.1 7m47s 1 SA tcp 10.0.0.100:1033 10.0.0.1:8291 established 23h52m3s 2 S ipsec... 10.0.0.2 10.0.0.1 2m3s 3 SA udp 10.0.0.1:500 10.0.0.2:500 5m1s
by iluvar
Sun Nov 11, 2012 5:01 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Re: Understanding IPSec VPN. Send initial contact or no?

new SAs get negotiated and ping doesnt work, or did it not negotiate new SAs? New SAs get negotiated and ping doesnt work But in firewall connection i see unreplied icmp-packets [MT2] > ip firewall connection print # PR.. SRC-ADDRESS DST-ADDRESS TCP-STATE TIMEOUT 0 SA udp 10.0.0.1:500 10.0.0.2:500 ...
by iluvar
Sun Nov 11, 2012 3:41 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Re: Understanding IPSec VPN. Send initial contact or no?

Delete the SAs on both sides, see if it re-negotiates properly again and works after that.

Also, turning on DPD with reasonable values will help this. Like 5 sec and 2 failures.
I do it, but nothing.

May be need create routes to 192.168.1.0/24 and 192.168.2.0/24? Then through which gateway?
by iluvar
Sun Nov 11, 2012 3:25 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Re: Understanding IPSec VPN. Send initial contact or no?

I was wrong, sorry [admin@MT2] > ping address=192.168.1.1 interface="ether1 lan2" HOST SIZE TTL TIME STATUS 192.168.1.1 timeout 192.168.1.1 timeout Now i see peers and installed SA`s, but cant ping other subnet
by iluvar
Sun Nov 11, 2012 1:55 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Re: Understanding IPSec VPN. Send initial contact or no?

The tunnels wont establist unless there is traffic flowing which needs the tunnels. For example, do a ping from MK2 like this: ping address=192.168.1.1 interface=LAN Send initial contact means if the mikrotik is to establish a tunnel if its not established yet. Basicly it controls which side of the...
by iluvar
Sun Nov 11, 2012 1:25 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Re: Understanding IPSec VPN. Send initial contact or no?

P. S. All interfaces in virtual box are internal (private "wan", "lan1", "lan2")
by iluvar
Sun Nov 11, 2012 1:20 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 6678

Understanding IPSec VPN. Send initial contact or no?

Hi! I try create IPSec Tunnel between two Mikrotik 5.21 (MT1 and MT2) in test lab Oracle VirtualBox, but i cant see any udp500 or ipsec-esp traffic (I try this on two MT AH1100AHx2 with no result) [both MT] > ip ipsec statistics print in-errors: 0 in-buffer-errors: 0 in-header-errors: 0 in-no-states...
by iluvar
Thu Aug 16, 2012 7:37 am
Forum: General
Topic: IPSec NAT-N
Replies: 3
Views: 577

Re: IPSec NAT-N

All works, tnx!
by iluvar
Wed Aug 15, 2012 7:50 pm
Forum: General
Topic: IPSec NAT-N
Replies: 3
Views: 577

Re: IPSec NAT-N

The following may work: RB1: /ip ipsec peer add address=8.8.1.1/32 secret="test" nat-traversal=yes send-initial-contact=no /ip ipsec policy add sa-dst-address=8.8.1.1 sa-src-address=8.8.0.1 src-address=192.168.0.0/24 dst-address=192.168.1.0/24 tunnel=yes /ip firewall nat add chain=srcnat action=acc...
by iluvar
Sat Aug 04, 2012 10:32 am
Forum: General
Topic: Help with IPSec NAT-Traversal
Replies: 16
Views: 17875

Help with IPSec NAT-Traversal

Hi! Help me please with create IPSec throuht alien NAT-router Sheme: MY OFFICE: My RB1 ether1 LAN 192.168.0.1/24 My RB1 ether2 WAN 8.8.0.1/32 REMOTE OFFICE: My RB2 ether1 1LAN 192.168.1.1/24 Alien RB3 ether1 LAN 192.168.1.2/24 Alien RB3 ether2 WAN 8.8.1.1/32 Alien RB3 give me NAT in remote office Ho...
by iluvar
Sat Aug 04, 2012 10:26 am
Forum: General
Topic: IPSec NAT-N
Replies: 3
Views: 577

IPSec NAT-N

Hi! Help me please with create IPSec throuht alien NAT-router Sheme: MY OFFICE: My RB1 ether1 LAN 192.168.0.1/24 My RB1 ether2 WAN 8.8.0.1/32 REMOTE OFFICE: My RB2 ether1 1LAN 192.168.1.1/24 Alien RB3 ether1 LAN 192.168.1.2/24 Alien RB3 ether2 WAN 8.8.1.1/32 Alien RB3 give me NAT in remote office Ho...