Page 1 of 1

Mikrotik RB2011 and many ipsec tunnels

Posted: Tue Jan 10, 2017 5:36 pm
by arizafal
This is my first post, please be patient. I would like connect over a dozen location to central ruter via ipsec. Unfortunately lot of location is behind NAT. Is it possible to do this using mikrotik hardware?
I thought about RB 2011 series. If not do you have any suggestions? I will be grateful for any advice.

Thank you in advance!

Re: Mikrotik RB2011 and many ipsec tunnels

Posted: Tue Jan 10, 2017 5:44 pm
by mrz
Need more info. Is it pure ipsec or some sort of l2tp/ipsec? Will there be multiple clients behind same NAT?

Re: Mikrotik RB2011 and many ipsec tunnels

Posted: Tue Jan 10, 2017 6:36 pm
by erlinden
Everything is possible with Mikrotik. Are you talking about a dozen site-to-site connections? What bandwidth do you need per connection? What is your knowledge on this topic?

Re: Mikrotik RB2011 and many ipsec tunnels

Posted: Tue Jan 10, 2017 9:45 pm
by arizafal
Thank you for your answer. I have 30 location connected by ipsec with Junipers SRX. I can configure it. Unfortunately because of unstable power supply in location i have problems with juniper hardware and I would like replace it on Mikrotik. I'm beginner in RouterOS, but I have some experience in ipsec. All locations have your own internet access and own nat and router is behind this nat. I have two RB 2011UiAS for test but first i would like to know if it is possible to make 30 ipsec tunnels to central router from locations behind nat. Trafiic is not big, ipsec is rather for manage ruter and devices connected to router. We have no multiple tunel behind the same nat. Central router have static and public internet access. I thought about pure ipsec but it is only plan for know. Any suggestions will be nice! :)

Re: Mikrotik RB2011 and many ipsec tunnels

Posted: Tue Jan 10, 2017 10:06 pm
by pe1chl
When you want good performance IPsec I recommend to use hEX r3 (RB750Gr3) instead of RB2011. It is cheaper as well.

In MikroTik there are no small limits on number of tunnels you can setup, but of course the CPU has its limitations,
and the hEX r3 has hardware accelerated crypto. It is a hot little router!

Re: Mikrotik RB2011 and many ipsec tunnels

Posted: Tue Jan 10, 2017 11:01 pm
by Dude2048
I have build a sstp tunnel over the internet with eoip in it. Eoip connects to a management bridge. I have a central management machine with tentacles to the other sites. The internet traffic itself brakes out at the local connection. So yes, what you want is possible and it is in production at my site.

Re: Mikrotik RB2011 and many ipsec tunnels

Posted: Tue Jan 10, 2017 11:09 pm
by arizafal
Thank you for your time and answers! Now I have to start my tests. Have a good time!