Community discussions

MikroTik App
 
Paxy91
just joined
Topic Author
Posts: 3
Joined: Fri May 22, 2015 2:35 am

One way traffic over IPSec tunnel

Tue Jun 22, 2021 7:51 pm

Bit of a strange issue here. I've created a tunnel with a PFSense firewall, but am unable to ping anything on the PFSense (remote) side of the firewall. They can ping myside, however. Obviously, the tunnel is showing as online. I have four other tunnels setup on this Mikrotik and there are no issues with any of these. They all use the same NAT and Filter rules. Anything come to mind as to what might be causing this? Here are the troubleshooting steps I've done so far:
1. Reviewed the documentation found at https://help.mikrotik.com/docs/display/ROS/IPsec
2. Created individual NAT and RAW/Filter rules for this specific tunnel instance. I can see activity on these rules when trying to ping
3. Triple checked the networks found in IPSec policy. They are correct. Same networks found in the NAT rule as well. They are using the generic 172.16.0.0/24 network. Not too happy about that, but it is unchangeable
4. I've checked for that address range in other NAT rules, routes, and address lists. I can't find that range in the NAT or routes. It is defined as a WAN in the address list. I've tried toggling enabled/disabled but no satisfaction.
5. Ran a packet capture at both ends. I show the packet being sent to the internal LAN interface, but they don't show it hitting their end.

Any other troubleshooting ideas? Running Mikrotik version 6.45.8
 
Paxy91
just joined
Topic Author
Posts: 3
Joined: Fri May 22, 2015 2:35 am

Re: One way traffic over IPSec tunnel

Wed Jun 23, 2021 8:41 pm

Issue resolved. Turned out to be an improper firewall config on the remote end.

Who is online

Users browsing this forum: loloski, vingjfg and 48 guests