I attach an IPsec log file where 46.61.18.28 is an external Mikrotik address, 185.3.34.7 is my Android mobile that tries to connect to. It also has a 172.29.30.88 which goes from inside a cellular carrier’s NAT. Another IP 77.66.234.235 that is seen in the log is an IP of my second site with another Mikrotik, and the two sites have a site-to-site IPsec link which works just fine.
It seems that ISAKMP stage gets established but then everything just dies out. I even downgraded the OS version to v6.7 from v6.12 which is what it was when I bought the router.
Can anyone help, please? I sent this question to Mikrotik support but do not get any response. ipsec_v67.log (129 KB)
This is rather strange. I have found this place in the logs and found that it does not change whatever I do in the IPsec peer settings!! How come? I attach a screenshot of winbox. These settings are also confirmed in the command line:
Peer settings are phase1.
Proposal settings are phase2
Most likely these errors are for phase2, so check if you have correct settings in ./ip ipsec proposal.