Community discussions

MikroTik App
 
mikruser
Long time Member
Long time Member
Topic Author
Posts: 578
Joined: Wed Jan 16, 2013 6:28 pm

ipsec established, but gre tunnel not

Thu Jan 02, 2020 9:09 am

Hello,

I created GRE tunnel (with IPsec Sercret) between CCR and CHR. (6.44.6)
1) policy created dynamically successfully (ph2 state established)
2) peer created dynamically successfully
3) identities created dynamically successfully
4) remote peers and installed sa created dynamically successfully

but GRE tunnel is inactive (not running).

how is this possible?
Last edited by mikruser on Fri Jan 10, 2020 2:21 pm, edited 1 time in total.
 
User avatar
BartoszP
Forum Guru
Forum Guru
Posts: 2879
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: ipsec established, but gre tunnel not

Thu Jan 02, 2020 4:00 pm

Have you specified local and remote addresses of GRE on both routers?
Do you allow proper protocols to pass firewall?
 
mikruser
Long time Member
Long time Member
Topic Author
Posts: 578
Joined: Wed Jan 16, 2013 6:28 pm

Re: ipsec established, but gre tunnel not

Thu Jan 02, 2020 4:10 pm

>>Have you specified local and remote addresses of GRE on both routers?
Yes

>>Do you allow proper protocols to pass firewall?
Yes, full access for these addresses (without "IPsec Secret" gre-tunnel link up successfully).

I think this is a bug in ROS...
 
User avatar
BartoszP
Forum Guru
Forum Guru
Posts: 2879
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: ipsec established, but gre tunnel not

Thu Jan 02, 2020 4:41 pm

I doubt that it is a bug. I use GRE-IPSec and IPIP-IPSec ..
 
yeahbunin
just joined
Posts: 1
Joined: Wed Jan 08, 2020 5:35 pm

Re: ipsec established, but gre tunnel not

Wed Jan 08, 2020 5:39 pm

You need to check your FWall rules

accept input traffic from your remote peer over proto 47(gre)

and proto 89(ospf) if you need
Last edited by yeahbunin on Wed Jan 08, 2020 5:40 pm, edited 1 time in total.
 
mikruser
Long time Member
Long time Member
Topic Author
Posts: 578
Joined: Wed Jan 16, 2013 6:28 pm

Re: ipsec established, but gre tunnel not

Thu Jan 09, 2020 1:33 pm

yeahbunin
read my previous message
 
sid5632
Long time Member
Long time Member
Posts: 554
Joined: Fri Feb 17, 2017 6:05 pm

Re: ipsec established, but gre tunnel not

Thu Jan 09, 2020 5:23 pm

Why don't you just provide a config. export of both ends instead of whining?
What do you expect anybody to do without this BASIC information?

Who is online

Users browsing this forum: bananaboy1101, deadpete, Fablos, jaclaz and 92 guests