Community discussions

MikroTik App
 
surajs
just joined
Topic Author
Posts: 4
Joined: Tue Dec 22, 2020 9:53 am

Maximum number of vpn clients supported to RB1100Ahx4

Wed Dec 23, 2020 4:13 pm

Hi Everyone, If anyone knows about the below information regarding RB1100Ahx4 please help.

I need some information regarding below points for RB1100Ahx4

1. How many maximum number of l2tp clients are supported ?
2. How many maximum number of IPSec tunnels are supported ?
3. How many maximum number of IPsec policies are supported ?

Currently I am using 400 l2tp vpn clients at same time without any problem.
I want to move on l2tp over IPsec setup. For which I will need to create 400 tunnels. Each client router will going to have 5 routes which will create 400*5=2000 ipsec policies in ahx4.

Please confirm whether RB1100Ahx4 can handle 400 vpn client and 400 ipsec tunnels(2000 ipsec policies) at same time or not. Thank you in advance.
 
User avatar
tomaskir
Trainer
Trainer
Posts: 1162
Joined: Sat Sep 24, 2011 2:32 pm
Location: Slovakia

Re: Maximum number of vpn clients supported to RB1100Ahx4  [SOLVED]

Wed Dec 23, 2020 4:33 pm

If you are planning to use L2TP/IPSec (L2TP over IPSec), then you will be using IPSec in transport mode, not in tunnel mode.
Using L2TP/IPSec the clients should create a single dynamic policy per client (generate-policy=port-strict).

This means there will be only 1 policy per client, and you will be using the routing table to route.

The RB1100Ahx4 will have no problems at all handling 400 L2TP clients, with the necessary IPSec policies and 2.000 routes.
 
frzgtrgb
just joined
Posts: 2
Joined: Wed Dec 23, 2020 5:09 pm

Re: Maximum number of vpn clients supported to RB1100Ahx4

Wed Dec 23, 2020 5:31 pm

there will be only 1 policy per client, and you will be using the routing table to route.
 
surajs
just joined
Topic Author
Posts: 4
Joined: Tue Dec 22, 2020 9:53 am

Re: Maximum number of vpn clients supported to RB1100Ahx4

Thu Dec 24, 2020 10:27 am

If you are planning to use L2TP/IPSec (L2TP over IPSec), then you will be using IPSec in transport mode, not in tunnel mode.
Using L2TP/IPSec the clients should create a single dynamic policy per client (generate-policy=port-strict).

This means there will be only 1 policy per client, and you will be using the routing table to route.

The RB1100Ahx4 will have no problems at all handling 400 L2TP clients, with the necessary IPSec policies and 2.000 routes.
Thanks so much for your response.
Can you please tell me which mode I should use If I want to configure IPsec over L2tp ? Will RB1100Ahx4 support the same (400 l2tp client and 2000 ipsec policies) ?

Who is online

Users browsing this forum: Google [Bot], unhuzpt, zalciukaz and 116 guests