I have a number of Mikrotik devices connected via IPSEC/IKEv2. This works just fine in general, but looks like I have a wired issue with NAT. First devices behind NAT connects without any issues. If I connect a second device behind the same NAT the connection is established, but mode-config address is assigned to a wrong (random?) interface:
Code: Select all
[admin@milkrotik] > / ip address print
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK INTERFACE
0 10.1.1.1/24 10.1.1.0 br-intern
1 192.168.1.1/24 192.168.1.0 br-guest
2 D 10.1.2.18/24 10.1.2.0 en
3 D 172.31.255.250/24 172.31.255.0 wl-intern
[admin@mikrotik] > / ip route print where dst-address=0.0.0.0/0 dynamic
Flags: X - disabled, A - active, D - dynamic, C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme, B - blackhole, U - unreachable, P - prohibit
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 ADS 0.0.0.0/0 10.1.2.1 1