Community discussions

MikroTik App
 
User avatar
etcnix
just joined
Topic Author
Posts: 16
Joined: Mon Sep 15, 2014 1:08 pm
Location: Kiev, Ukraine

IPsec doesn't work after upgrade from 6.43.16 to 6.44 and high

Tue Jul 16, 2019 5:36 pm

Hello.
I used routeros-mipsbe-6.43.16 on my 951G-2HnD.
After upgrade to
6.44 by hands
or to
6.44.5 long-term,
6.45.1 latest stable,
6.46beta9 latest testing
by webfig (yes, I've tried all this versions)
IPsec doesn't work and uses CPU 60-70%:
> /ip ipsec
/ip ipsec> settings print
action timed out - try again, if error continues contact MikroTik support and send a supout file (13)

/ip ipsec> profile print
Ctrl+C because there is like hung and no output
Image

So I have to downgrade routeros to the latest long-term 6.43.16 (latest working version for my case) and after this everything is ok.
Please help me.
 
sindy
Forum Guru
Forum Guru
Posts: 10206
Joined: Mon Dec 04, 2017 9:19 pm

Re: IPsec doesn't work after upgrade from 6.43.16 to 6.44 and high

Tue Jul 16, 2019 6:00 pm

I've seen here on the forum a case like this, the solution was to export the ipsec configuration into an external text file, remove it on the machine, upgrade the machine and create the ipsec configuration manually again. There was a significant change in the IPsec configuration structure either between 6.42 an 6.43 or between 6.43 and 6.44 so it may be a bit challenging if the latter is true.
 
User avatar
etcnix
just joined
Topic Author
Posts: 16
Joined: Mon Sep 15, 2014 1:08 pm
Location: Kiev, Ukraine

Re: IPsec doesn't work after upgrade from 6.43.16 to 6.44 and high

Wed Jul 17, 2019 10:18 am

I've seen here on the forum a case like this, the solution was to export the ipsec configuration into an external text file, remove it on the machine, upgrade the machine and create the ipsec configuration manually again. There was a significant change in the IPsec configuration structure either between 6.42 an 6.43 or between 6.43 and 6.44 so it may be a bit challenging if the latter is true.
I don't have any custom settings in the IPsec, only default.
My IPsec export:
# jul/17/2019 10:04:55 by RouterOS 6.43.16
# software id = F99Z-3LAY
#
# model = 951G-2HnD
# serial number = 4184023718B6
/ip ipsec peer profile
add dh-group=modp1024 enc-algorithm=3des name=profile_1
add dh-group=modp1024 enc-algorithm=3des name=profile_2 nat-traversal=no
/ip ipsec proposal
set [ find default=yes ] enc-algorithms=3des
/ip ipsec policy
set 0 dst-address=0.0.0.0/0 src-address=0.0.0.0/0
Could you please explain me how can I delete IPsec from routeros?
 
nostromog
Member Candidate
Member Candidate
Posts: 226
Joined: Wed Jul 18, 2018 3:39 pm

Re: IPsec doesn't work after upgrade from 6.43.16 to 6.44 and high

Wed Jul 17, 2019 10:26 am

I've seen here on the forum a case like this, the solution was to export the ipsec configuration into an external text file, remove it on the machine, upgrade the machine and create the ipsec configuration manually again. There was a significant change in the IPsec configuration structure either between 6.42 an 6.43 or between 6.43 and 6.44 so it may be a bit challenging if the latter is true.
Try first what sindy suggests, but it didn't work for me (I'm one of the cases, the one that was able to solve it without netinstalling). Even after having empty ipsec configuration the same CPU loop and not being able to even finish /ip ipsec export would happen after upgrade.

Also, having a backup in the long term version, resetting to default and restoring the backup didn't work, same results.

What worked for me was to export whole configuration, reset the router to default configuration, upgrade RouterOS and then reconstruct it by hand with from the export script. (I don't remember if I resetted it under the old or the new version, probably better to do it in both versions). Notice that the ipsec commands change between 6.43.16 and 6.44.5, as the commands have changed... user -> identity, etc. So your export needs to be patched by hand to work under 6.44+. Also notice that keys and certificates need also to be taken care in the process.
 
sindy
Forum Guru
Forum Guru
Posts: 10206
Joined: Mon Dec 04, 2017 9:19 pm

Re: IPsec doesn't work after upgrade from 6.43.16 to 6.44 and high

Wed Jul 17, 2019 11:39 am

Could you please explain me how can I delete IPsec from routeros?
Could you please show me where have you stated in the OP that there is no manual IPsec configuration :) ?

But if the question was serious, you have to disable the complete secutity package and reboot; but this disables everything related to security - ssh, certificates etc., and it will not necessarily cleanup the ipsec configuration part so once you re-enable the security package and reboot again, you may find yourself still in the same trouble.

The rest has already said @nostromog above.

Who is online

Users browsing this forum: Bing [Bot], suszi and 93 guests