Community discussions

MikroTik App
 
ronylove
newbie
Topic Author
Posts: 28
Joined: Fri Aug 10, 2018 6:33 pm

VPN ( IPSec ) packet loss

Thu Feb 27, 2020 8:02 pm

Dear:
I would like to ask for help.
I have a VPN (IPSec) between the city of cbba. and the city of Oruro de mi Pais.
- Cbba.
RB 750Gr3
- Oruro
RB3011uias-RM
..................................................
The detail is that when it begins to have traffic, I have lost packages.
.................................................. ..
Test.
* Cbba equipment: IP = 192.168.20.3
* Oruro equipment: IP = 192.168.9.1

I attach an image
Note.-
Both are connected directly to the ISP Modem.
The bandwidth is 2: 1 of 100 Mb each.
You do not have the required permissions to view the files attached to this post.
 
angriukas
Member Candidate
Member Candidate
Posts: 103
Joined: Fri Nov 22, 2013 9:20 am
Contact:

Re: VPN ( IPSec ) packet loss

Fri Feb 28, 2020 1:14 pm

What I would do in your case is:
include ipsec and debug in to logging rules, analyze log to reveal what's going on.
Also: I see the bridge in your config, add Admin MAC to the bridge, because sometimes bridge could change his MAC address, it depends from running/inactive ports. That could have influence to the ping.
 
ronylove
newbie
Topic Author
Posts: 28
Joined: Fri Aug 10, 2018 6:33 pm

Re: VPN ( IPSec ) packet loss

Sat Feb 29, 2020 1:14 am

Dear angriukas.

Could you tell me how do I add the admin MAC in the bridge.
 
angriukas
Member Candidate
Member Candidate
Posts: 103
Joined: Fri Nov 22, 2013 9:20 am
Contact:

Re: VPN ( IPSec ) packet loss

Mon Mar 02, 2020 2:38 pm

Here it is.
You do not have the required permissions to view the files attached to this post.
 
ronylove
newbie
Topic Author
Posts: 28
Joined: Fri Aug 10, 2018 6:33 pm

Re: VPN ( IPSec ) packet loss

Sat Apr 04, 2020 10:54 pm

Dear angriukas:
Thanks for the reply. I have a doubt. The administrator MAC, is the MAC of my computer or PC from which I manage the RB ??
Please excuse me for the question.
 
angriukas
Member Candidate
Member Candidate
Posts: 103
Joined: Fri Nov 22, 2013 9:20 am
Contact:

Re: VPN ( IPSec ) packet loss

Mon Apr 06, 2020 1:43 pm

Set same value from field "MAC Addess".
 
sindy
Forum Guru
Forum Guru
Posts: 10205
Joined: Mon Dec 04, 2017 9:19 pm

Re: VPN ( IPSec ) packet loss

Mon Apr 06, 2020 7:32 pm

In automatic MAC mode, the bridge normally inherits the MAC address from the port made a member of it, until that port eventually goes away from the bridge. After a reboot, the ports may be added in a different order, hence the MAC address of the bridge may change. During runtime, the address should not change unless the "donor" member port is removed from the bridge.

So by copying the dynamically assigned MAC address to the "admin mac" field, you prevent further changes (or you may assign some completely different MAC address). Do not assign an address of anything external that is connected to the bridge. Any MAC address of any of the own interfaces of the 'Tik which is a member port of the bridge is a safe choice.

But I don't think the MAC change is the reason of packet loss. IPsec doesn't touch L2 at all (except indirectly, if you'd use EoIP over IPsec, which is not the case).

Hence please describe your problem in deeper detail:
  • as at least one of the two 'Tiks must have a public IP. What happens if you ping that public IP from the other 'Tik? Do you also see some losses or not? (Responding to icmp ping must be permitted in the input chain of the firewall on the responding 'Tik)
  • when you ping inside the IPsec tunnel, do the losses appear only when you start pinging and later on there are none, or is there a certain share of lost pings all the time? From your wording ("when it begins to have traffic, I have lost packets.") this is not 100 % clear.
 
ronylove
newbie
Topic Author
Posts: 28
Joined: Fri Aug 10, 2018 6:33 pm

Re: VPN ( IPSec ) packet loss

Wed Jul 29, 2020 7:34 pm

Dear Sindy
Thanks for the reply.
- Both RB's (RB1 & RB2) have public IP.
- When I ping from one RB to the other, it has a response.
- We have an internal system through http that is in RB1. When accessed from the network behind RB2, for example 5 users (which is normal). No problem, communication is smooth.
- But in certain times more users need to connect, for example 10 or more, and they make massive use of the system, that is where it shows: slowness, and even hang up the system.

- But when the network behind RB1 (internal network), they are connected in mass. Nothing like that happens. There is slowness, but it is not too much, for example 5 sec. in processing some data.

That's my doubt.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10194
Joined: Mon Jun 08, 2015 12:09 pm

Re: VPN ( IPSec ) packet loss

Wed Jul 29, 2020 8:44 pm

It can be caused by certain filters in the ISP modem, e.g. rate limiting of UDP traffic "to solve gaming problems" or "to alleviate DDoS".
Look for settings like that in the ISP modem and disable those options.

Who is online

Users browsing this forum: Bing [Bot], Google [Bot], GoogleOther [Bot], onnyloh, RobertsN, TheCat12 and 90 guests