Community discussions

MikroTik App
 
User avatar
zeeh1975
just joined
Topic Author
Posts: 7
Joined: Mon Apr 19, 2021 8:17 pm

Public IP instead of private IP as Peer ID in IPSEC tunnel

Thu Sep 30, 2021 7:17 pm

Image

I have a IPSec tunnel labeled as "Movistar" whose peer ip is xxx.xxx.240.1 when tunnel is established it shows as local IP the private IP "10.20.30.2", which results to be the Peer Id. Because they were especting public IP as Peer Id our counterpart made an exception to allow a connection with private IP as Peer Id.
I want to know how I can make router to use public router IP "xxx.xxx.57.231" as default Peer ID, I tryed to set Local address value in "IPsec Peer" but that makes tunnel to drop. So asume that's need more configuration that I don't know by now.

Image
You do not have the required permissions to view the files attached to this post.
Last edited by zeeh1975 on Thu Sep 30, 2021 10:07 pm, edited 1 time in total.
 
sindy
Forum Guru
Forum Guru
Posts: 10206
Joined: Mon Dec 04, 2017 9:19 pm

Re: Public IP instead of private IP as Peer ID in IPSEC tunnel

Thu Sep 30, 2021 9:57 pm

Unless you've obfuscated them manually, delete your config export immediately and post it without the secret values on /ip ipsec identity rows.
 
sindy
Forum Guru
Forum Guru
Posts: 10206
Joined: Mon Dec 04, 2017 9:19 pm

Re: Public IP instead of private IP as Peer ID in IPSEC tunnel

Thu Sep 30, 2021 10:01 pm

By default, RouterOS generates the ID automatically, depending on the authentication type and other circumstances.

To set your public IP rather than the private one as your ID, set my-id=address:the.pub.lic.ip on the respective /ip ipsec identity row.
 
User avatar
zeeh1975
just joined
Topic Author
Posts: 7
Joined: Mon Apr 19, 2021 8:17 pm

Re: Public IP instead of private IP as Peer ID in IPSEC tunnel

Fri Oct 01, 2021 5:47 pm

By default, RouterOS generates the ID automatically, depending on the authentication type and other circumstances.

To set your public IP rather than the private one as your ID, set my-id=address:the.pub.lic.ip on the respective /ip ipsec identity row.
Thank you for your help.

Who is online

Users browsing this forum: adwlodaro, Bing [Bot], gigabyte091, Google [Bot], vagrik, vk2mpj and 218 guests