Community discussions

MikroTik App
 
esisas
just joined
Topic Author
Posts: 3
Joined: Tue Sep 11, 2018 1:15 pm

IPsec, mode config and xauth users

Tue Sep 11, 2018 1:22 pm

Hello,
is it possible to have multiple ipsec mode configs with different networks to route to the ipsec clients, based on what xauth user is connecting without knowing their public IP?
The end goal is to have some road warriors that can access certain networks and others that can not using ipsec + mode config + xauth.

Thanks in advance
 
User avatar
emils
Forum Veteran
Forum Veteran
Posts: 906
Joined: Thu Dec 11, 2014 8:53 am

Re: IPsec, mode config and xauth users

Tue Sep 11, 2018 1:28 pm

Currently it is not possible, but we have plans to implement such feature in near future, maybe even in 6.44.
 
esisas
just joined
Topic Author
Posts: 3
Joined: Tue Sep 11, 2018 1:15 pm

Re: IPsec, mode config and xauth users

Tue Sep 11, 2018 1:47 pm

Currently it is not possible, but we have plans to implement such feature in near future, maybe even in 6.44.
What's my option for the time being? Use the firewall?
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7054
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: IPsec, mode config and xauth users

Tue Sep 11, 2018 2:05 pm

Yes you can assign static IP address by modeconf and use firewall to limit/route traffic for specific IP.
 
esisas
just joined
Topic Author
Posts: 3
Joined: Tue Sep 11, 2018 1:15 pm

Re: IPsec, mode config and xauth users

Tue Sep 11, 2018 2:27 pm

Yes you can assign static IP address by modeconf and use firewall to limit/route traffic for specific IP.
Thank you for the insight, there's another thing related to this:
I would like to email the ipsec user connection and disconnection logs. I did it with l2tp using the logging email setting, but ipsec logs a lot of things under ipsec,info category including the connection string.
Is there a way to get only the connection log without all the rest of the ipsec data?

Please let me know if i have to open a new topic of this.
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7054
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: IPsec, mode config and xauth users

Tue Sep 11, 2018 5:16 pm

Not possible directly. Solution is to use remote syslog server or by scripts on the router, filter needed log entries and then email.

Who is online

Users browsing this forum: josser and 133 guests