Community discussions

MikroTik App
 
migrax
just joined
Topic Author
Posts: 2
Joined: Sun Jun 24, 2018 5:40 pm

Source IP address is the MikroTik IP instead of remote IP over IPSec VPN

Sun Jun 24, 2018 6:04 pm

Hi,

I have a problem that is a bit annoying for me. I will say I am new to MikroTik so I am properly missing something.

The problem I have is that we uses four VPN-tunnels to different sites and on each site there a phones counting to the central IPPBX over the IPSec tunnel. The problem I have now is that then you look at the packages that is send to the PBX the IP Source IP is the MikroTik router instead of the phones IP address. This corses a problem as we filter on source IP adress on the PBX to secure each extension. So now all extension comes form the same ip subnet, that is 192.168.1.0/24 instead of from each uniq subnet.
All other routers I have been working with earlier has not changed the source IP address on an IPSec tunnel.
The idea with a IPSec tunnel is that the complete IP package is encapsulated before encrypted and then transmit over the network.
Is there setting I am missing to correct this issue?
 
nescafe2002
Forum Veteran
Forum Veteran
Posts: 897
Joined: Tue Aug 11, 2015 12:46 pm
Location: Netherlands

Re: Source IP address is the MikroTik IP instead of remote IP over IPSec VPN

Sun Jun 24, 2018 6:50 pm

Have you excluded IPSEC traffic from NAT?

https://wiki.mikrotik.com/wiki/Manual:I ... ack_Bypass
 
migrax
just joined
Topic Author
Posts: 2
Joined: Sun Jun 24, 2018 5:40 pm

Re: Source IP address is the MikroTik IP instead of remote IP over IPSec VPN

Mon Jun 25, 2018 9:32 pm

Thanks for the help.

That solved it. I had added the srcnat rule but not the firewall raw rule.

Who is online

Users browsing this forum: Amazon [Bot] and 46 guests