Best way to test MIKROTIK IPsec Modes with ShrewClient

Hi Mikrotik owners ,

The best way to test your MIKROTIK IPSEC connection in router using debug IPSEC is the ShrewClient on Windows machine it has all modes beside IKEV2 to test out and see what fits in your scenarios,you will know exactly what to expect and how IPSEC packets 2 phase works,

I hope Normis would agree on that

One thing to mention is that some protocol are not supported and i will list all of them

1)L2TP/IPSEC PSK ord RSA only one connection behind NAT same IP
2)OPENVPN not UDP protocol ,LZO compression
3)Cannot use Radius in mikrotik for EAP protocol you must use external
4)Ikev2 not use xauth protocol
5)No hydbrid RSA on Ikev2
6)you cannot use Ikev1 agressive mode when 2 same config peers are defined

You cannot define mix peers with preshared keys and RSA keys you must use one policy on 1 one router unit or use other RSA layers tunnel protocol like SSTP and OPENVPN

One thing to mention is that IPSEC would not benefit if you have low speed asymetric Internet is better to use optic and have bigger upload speed if you want best encryption speed when using ROAD WARRIORS,

all units support up to 256 AES encryption if you want more or bigger encryption and better routers use X86 and Hardware Cloud routers series,

Dont be fooled that on small budget router you will have fantastic speed if you have 10 Road Warriors using VPN it all depends from your hardware and ISP speed

If there is some other limitations please write it here explicit

Thanks

Icko