IP GRE tunnel static route

Hi,
I’ve configured a GRE protocol with IPSec successfully but I have two questions:

  1. Is there any way to change AES-128 and 3DES that Mikrotik uses as IPSec peer settings? Can’t find it anywhere. Whenever you configure IPSec secret in GRE settings it dynamically creates an IPSec peer and policy and the only thing I can change is proposal settings.
  2. Why MT is adding a static route to 255.255.255.0 with gateway set to GRE interface and pref.source set to tunnel IP? Can that be disabled somehow?
    Here’s an example:
    9 ADC 255.255.255.0/32 10.22.60.254 tunnel0 0

Thanks for answers.

Hi,

regarding 3DES: You need to change the default proposal. Youl’ll find it in"IP" → IPSec" → Tab “Proposal”. Do it for both sides oft the encrypted GRE tunnel.

Regards,
Ape