How to use the IPSec in Windows 7?

Hi,
I want to use the IPSec protocol in the Windows 7, How to I do it?

Setting of IPSec in the WinBox:

Setting of IPSec in the VPN Connection:

Finally, I get this error:

Basically, you have to get it 100% exact on both sides, or it will fail. IPSec is VERY unforgiving. Follow the wiki exactly and it should work.

Here is a IPsec windows tutorial, maybe some useful info there:
http://wiki.mikrotik.com/wiki/MikroTik_RouterOS_and_Windows_XP_IPSec/L2TP

@normis,

the guide didn’t work on windows 7.

I’ve followed the guide, but simply didn’t work.

Please, can anyone share a working Mk ↔ W7 configuration for l2tp/ipsec

thanks

A.

Hello,

I have same problem, Im trying to configure L2TP/IPSec client (Win7) to server (ROS). Client is behind NAT (in almost all scenarios), server is with public IP.

I have tryied this guide http://wiki.mikrotik.com/wiki/MikroTik_RouterOS_and_Windows_XP_IPSec/L2TP but it didnt work

When I try to connect to server I can see that client touches server, it is wisible in “Remote peers”. But in logs I have error “no suitable proposal found” and “failed to get valid proposal”.

please anybody for help :slight_smile:

thank you

so for now it started working :confused: for some reason I dont understand.

hello again :slight_smile:

I think last question about this kind of VPN. For now I have working L2TP/IPSec VPN. Last think I want do do is to set diferent IP range to VPN clients and diferent range to LAN.

Here is what I think about…

My LAN is 192.168.1.0/24
I want VPN client to take address from ROS pool (192.168.222.10-192.168.222.254) so I set VPN profile to give clients this addresses, and also to set address from this pool to the VPN server.
When I connect I will have (on client side) eg. 192.168.222.253 (server) and 192.168.222.252 (client)

My question is, how can client on VPN with address from range 192.168.222.0/24 access LAN range 192.168.1.0/24. I must say I have tryed everything I know. Turned off firewall, add src and dstnat from one network to another, etc etc.

please anybody :slight_smile:

thank you

Have you tried to set proxy-arp?