hello guys I follow this link to create the site to site https://blogs.technet.microsoft.com/netgeeks/2017/07/11/creating-a-site-to-site-vpn-ipsec-ikev2-with-azure-and-mikrotik-routeros/
I try all but the ping only response from azure to On Prem, can you help me to figure out what its going on. THANKS!!!
My configuration, Mikrotik V6.45.7
/ip firewall filter>
0 ;;; AZURE ACCES TO ROUTER
chain=forward action=accept src-address=192.168.20.0/24 dst-address=10.4.0.0/16 log=no
log-prefix=“” ipsec-policy=in,ipsec
1 ;;; PErmitir conexion IPSEC
chain=input action=accept protocol=ipsec-esp src-address=104.209.191.20 log=no log-prefix=“”
2 chain=forward action=accept src-address=10.4.0.0/16 dst-address=192.168.20.0/24 log=no
log-prefix=“”
/ip firewall nat
1 chain=srcnat action=accept src-address=192.168.20.0/24 dst-address=10.4.0.0/16 log=no
log-prefix=“”
2 chain=srcnat action=accept src-address=10.4.0.0/16 dst-address=192.168.20.0/24 log=no
/ip firewall mangle
;;; AZURE
chain=forward action=change-mss new-mss=1350 passthrough=yes tcp-flags=syn protocol=tcp
dst-address=10.4.0.0/16 log=no log-prefix=“”
/ip ipsec policy
PE TUN SRC-ADDRESS DST-ADDRESS
0 A ZU yes 192.168.20.0/24 10.4.0.0/16
/ip ipsec proposal
name=“AZURE” auth-algorithms=sha1 enc-algorithms=aes-256-cbc,aes-128-cbc lifetime=7h30m
pfs-group=none
/ip ipsec peer
name=“ZURE” address=104.209.191.20/32 profile=AZURE exchange-mode=ike2 send-initial-contact=yes
/ip ipsec profile
name=“AZURE” hash-algorithm=sha1 enc-algorithm=aes-256,aes-128 dh-group=modp1024 lifetime=8h
proposal-check=obey nat-traversal=no dpd-interval=2m dpd-maximum-failures=5