Community discussions

MikroTik App
 
moep
newbie
Topic Author
Posts: 48
Joined: Mon Jul 02, 2012 2:12 pm

IPSec mode-config site to site problem

Sun Feb 18, 2018 10:51 pm

Hello,

reading the changelogs I found out, that currently Phase1 is killed and not rekeyed if mode-config is used
from changelogs of 6.40:
*) ike1 - kill phase1 instead of rekey if "mode-config" is used;
this is bad when you use mode-config for site-to-site tunnels like I do, as it is torn down for a noticeable amount of time every 18 hours (or whatever is set as phase 1 lifetime).
this is especially bad if you want to connect to a dyndns peer, which is thankfully now possible via DNS named peer and mode-config, but has the aforementioned drawback.
previously I used a script to make dyndns peers work, but i wanted to change to a "scriptless" version.

Would it be possible to make this setting "editable", so the user can decide if he wants to kill or rekey phase1 after expiry (soft-/hard timeout).

That would be great.

Who is online

Users browsing this forum: dervomsee, djvabe, infabo, Mr47 and 140 guests