Hi all,
I am new to MK so forgive me for my silly questions.
I need to set up a IPSec VPN between my Mikrotik RB201 with my client's cisco router. I'm having troubles trying to make it run but no luck so far. Please some help appreciated!
For my side the configuration is as follows (fake ip's):
Phase 1
[admin@MikroTik] > ip ipsec peer print
Flags: X - disabled, D - dynamic
0 address=44.222.222.222/32 local-address=:: passive=no port=500
auth-method=pre-shared-key secret="mysecret" generate-policy=no
policy-template-group=default exchange-mode=main
send-initial-contact=yes nat-traversal=no proposal-check=obey
hash-algorithm=sha1 enc-algorithm=3des dh-group=modp1024 lifetime=1d
lifebytes=0 dpd-interval=disable-dpd dpd-maximum-failures=5
[admin@MikroTik] >
Phase 2
[admin@MikroTik] > ip ipsec proposal print
Flags: X - disabled, * - default
0 * name="default" auth-algorithms=sha1 enc-algorithms=3des lifetime=1d
pfs-group=modp1024
1 name="proposal" auth-algorithms=sha1 enc-algorithms=3des lifetime=12h
pfs-group=modp1024
[admin@MikroTik] >
[admin@MikroTik] > ip ipsec policy print
Flags: T - template, X - disabled, D - dynamic, I - inactive, * - default
0 TX* group=default src-address=::/0 dst-address=::/0 protocol=all
proposal=default template=yes
1 src-address=192.168.11.0/24 src-port=any dst-address=192.168.22.0/24
dst-port=any protocol=all action=encrypt level=require
ipsec-protocols=ah-esp tunnel=yes sa-src-address=199.222.222.222
sa-dst-address=44.222.222.222 proposal=proposal priority=0
[admin@MikroTik] >
######### Firewall Filter #############
1 chain=input action=accept protocol=udp in-interface=ether1 dst-port=500
log=no log-prefix=""
2 chain=input action=accept protocol=ipsec-esp in-interface=ether1 log=no
log-prefix="
16 chain=input action=accept protocol=tcp dst-port=1701 log=no log-prefix=">
17 chain=input action=accept protocol=tcp dst-port=1701 log=no log-prefix=">
[admin@MikroTik] >
########## Firewall Nat ###############
[admin@MikroTik] > ip firewall nat print
Flags: X - disabled, I - invalid, D - dynamic
0 chain=srcnat action=accept src-address=192.168.11.0/24
dst-address=192.168.22.0/24 log=no log-prefix=""
1 chain=srcnat action=accept src-address=192.168.22.0/24
dst-address=192.168.11.0/24 log=no log-prefix=""