*) sstp - improve initial handshake to better handle many new connections;
*) sstp - fixed connection idle time reporting;
*) sstp - made it working on Pentium 4 again;
certificate validation problems for some programs (VPN, SSTP etc)
*) sstp - added RC4 cipher support to fix interoperability issues
*) sstp client - added an option to skip
*) sstp - when server certificate verification is enabled for sstp client,
*) sstp - fix problems on multicore systems;
*) sstp - fixed memory leak;
*) fixed sstp memory leak;
*) sstp - fixed memory leak;
*) sstp - made it work with Windows 7;
*) sstp server - client reconnects did not work;
*) fixed sstp on x86;
*) added support for SSTP protocol (PPP over TLS);
Early we had Netscreen NS50 with IPSec setup to our RB1200, but we changed it to RB433UAH and RB1200 to RB1100AH.
Now is: RB433UAH – SSTP – RB1100AH.
When I drop VPN all seems to be ok. I will try to setup IPSec VPN instead of SSTP.
Reply from 192.168.13.1: bytes=32 time=170ms TTL=63
Reply from 192.168.13.1: bytes=32 time=170ms TTL=63
Reply from 192.168.13.1: bytes=32 time=168ms TTL=63
Reply from 192.168.13.1: bytes=32 time=168ms TTL=63
Reply from 192.168.13.1: bytes=32 time=169ms TTL=63
Reply from 192.168.13.1: bytes=32 time=167ms TTL=63
Reply from 192.168.13.1: bytes=32 time=170ms TTL=63
Reply from 192.168.13.1: bytes=32 time=169ms TTL=63
Reply from 192.168.13.1: bytes=32 time=169ms TTL=63
Reply from 192.168.13.1: bytes=32 time=168ms TTL=63
Reply from 192.168.13.1: bytes=32 time=170ms TTL=63
Reply from 192.168.13.1: bytes=32 time=170ms TTL=63
Reply from 192.168.13.1: bytes=32 time=168ms TTL=63
Reply from 192.168.13.1: bytes=32 time=169ms TTL=63
Reply from 192.168.13.1: bytes=32 time=167ms TTL=63
Reply from 192.168.13.1: bytes=32 time=168ms TTL=63
Reply from 192.168.13.1: bytes=32 time=171ms TTL=63
Reply from 192.168.13.1: bytes=32 time=172ms TTL=63
Reply from 192.168.13.1: bytes=32 time=171ms TTL=63
Reply from 192.168.13.1: bytes=32 time=187ms TTL=63
Reply from 192.168.13.1: bytes=32 time=170ms TTL=63
Reply from 192.168.13.1: bytes=32 time=169ms TTL=63
Reply from 192.168.13.1: bytes=32 time=169ms TTL=63
Reply from 192.168.13.1: bytes=32 time=168ms TTL=63
Reply from 192.168.13.1: bytes=32 time=167ms TTL=63
Reply from 192.168.13.1: bytes=32 time=168ms TTL=63
Reply from 192.168.13.1: bytes=32 time=345ms TTL=63
Ping statistics for 192.168.13.1:
Packets: Sent = 59, Received = 59, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = > 167ms> , Maximum = > 531ms> , Average = > 202ms
Doesn’t helped.
I disabled all UDP traffic in forward chain between offices.
Without success.
Only when I disable routes from each office to another issue disappeared, because then Skype doesn’t have route to another office via VPN.
After downgrade to ROS 5.14 certificate disappeared from ROS and I can’t import it again:
# certificate import file-name=vpn.domain.com.key
passphrase: ***************
action timed out - try again, if error continues contact MikroTik support and send a supout file (13)
Ticket#2012071166000339
Can’t import the certificate in ROS 5.14, ROS 5.15, ROS 5.16.
ROS 5.17 - works. Will see what is happening in ROS 5.17 with Skype in SSTP VPN.