I purchashed a MikroTik firewall to hopefully start replacing the ASA 5505’s that we have been using. I got the IPSEC vpn up between the two firewalls. I can ping everything in both directions. The issue is that nothing else besides ICMP works. SMB, HTTP, or HTTPS. I’ve got roughly 8 IPSEC VPN’s working on the ASA, so I’m fairly sure my config for this one is good also (Well it works for ASA’s, lol). I added the NAT exempt rule on the MikroTik, but do I need to add any access rules? Seems like something simple I’m missing. I am using this at my house and had it with NAT-T, but even tried it with a direct internet connection and still nothing. Sorry for no config, I’ll get that ASAP but just hoping for the DUH moment.
You need to accept UDP 500/4500 and AH/ESP protocols in input chain.
You should accept in forward chain traffic in both directions. Currently you allow only incoming traffic and those accept rules must be before default fasttrack rule.
I’m experiencing same problem after replacing a Cisco 1720 with CCR1009.
Running an IPSEC aes-128 tunnel, I’m able to ping hosts in booth directions, but I’m not able to pass other traffic. To me, it looks like a TCP MSS issue and I have tried to change that using mangle to 1350 and 1300 but without success.
I’m not sure for the mangle rule…perhaps should be done in another way?