Good day,
I am rather a novice with Mikrotik only having gotten my MTCNA and MTCRE, so I am very open to learning what I am doing wrong and if we are just strictly using the wrong methodology as a whole. For example, I am fine with moving away from IPsec if recommended with good evidence/reasoning as to why.
That being said, the problem is as follows.
I have 3 core sites, each with dual WAN.
Site 1 is our hub.
Site 2 is a spoke.
Site 3 is a spoke.
Currently, all traffic is shaped this way, where no matter the source, it goes to site 1, then onto the destination site.
Our IPsec traffic is rather unusable, and I’ll post that testing below. I will also post the IPsec settings of one of the sites, as all are identical to that.
Please feel free to ask for any supplementary documentation.
IPERF:
IPsec:
Policy:
Proposal:
Peer:
Identity:
Profile:






