Community discussions

MikroTik App
 
sergioser
just joined
Topic Author
Posts: 9
Joined: Wed Feb 20, 2008 12:11 pm

IPSec: several local subnets to one tunnel

Wed Mar 06, 2013 1:45 pm

Hi!
I need to add more that one subnet to IPSec policy.
I've tried something like this
src-address=192.168.50.0/24 src-port=any dst-address=10.6.6.0/24
dst-port=any protocol=all action=encrypt level=require ipsec-protocols=esp
tunnel=yes sa-src-address=my_wan_ip sa-dst-address=remote_ip
proposal=proposal2 priority=0
src-address=192.168.60.0/24 src-port=any dst-address=10.6.6.0/24
dst-port=any protocol=all action=encrypt level=require ipsec-protocols=esp
tunnel=yes sa-src-address=my_wan_ip sa-dst-address=remote_ip
proposal=proposal2 priority=0
But works only one (the first one). From asecond subnet I have no access to remote network. In logs (with ipsec debug) I didnt find ant errors.
Could you please help with it?
thanks.
 
slech
Long time Member
Long time Member
Posts: 537
Joined: Thu Feb 14, 2008 4:03 pm
Location: Moldova, Chisinau

Re: IPSec: several local subnets to one tunnel

Wed Mar 06, 2013 2:45 pm

sergioser, try
level=unique
instead of
level=require
Two IPSec tunnels from the same network
 
simaskkk
just joined
Posts: 8
Joined: Tue Feb 26, 2013 4:48 pm

Re: IPSec: several local subnets to one tunnel

Wed Mar 06, 2013 4:31 pm

It is much easier to create GRE tunnel interface, protect it with IPSec and do all the routing via it instead of creating those complicated IPSec policies.

By the way, is plain IPSec tunnel interfaces are on the feature request list?
 
sergioser
just joined
Topic Author
Posts: 9
Joined: Wed Feb 20, 2008 12:11 pm

Re: IPSec: several local subnets to one tunnel

Wed Mar 06, 2013 6:00 pm

It is much easier to create GRE tunnel interface, protect it with IPSec and do all the routing via it instead of creating those complicated IPSec policies.

By the way, is plain IPSec tunnel interfaces are on the feature request list?
If you can, please provide some details about gre interface (link, doc etc). Can I use it without any changes on remote side?
Thanks.
 
sergioser
just joined
Topic Author
Posts: 9
Joined: Wed Feb 20, 2008 12:11 pm

Re: IPSec: several local subnets to one tunnel

Wed Mar 06, 2013 6:04 pm

sergioser, try
level=unique
instead of
level=require
Two IPSec tunnels from the same network
Thanks. But its not my case :(

Who is online

Users browsing this forum: anav, Bing [Bot], lasaccount and 133 guests