MikroTik IPSec IKEv2 VPN between routers (site-to-site): easy step-by-step guide

preview_player
Показать описание
Рекомендации по теме
Комментарии
Автор

Excellent presentation Nikita, and thanks for sharing your knowledge and for the clarity of the explanation.

danielspeltini
Автор

Nikita, thank you so much for this! Using this video and your presentation in Malaysia, I successfully set up IKEv2 IPSec site-to-site VPNs to 4 external offices today as well as a few Windows 10 laptops. Having the PDF to follow along was exceptionally helpful. You're a great teacher and I have no idea how I would have figured this out without you! Thanks again!

nickholt
Автор

Thanks Nikita, it has worked perfectly for me in production. of course, I first did it in a virtual laboratory :)

marcoantoniogonzalez
Автор

The most useful guide how to enable Site-to-Site VPN. I like the part from 01:01:06

asqarsakenov
Автор

Nice one Nikita, great presentation. I've got a question regarding the topic of "adjusting TCP MSS". I studied your previous video/presentation from Malaysia's MUM and I'm concern about a possible mistake in this presentation, for last slides when you speak about MSS. When you adjust MSS between head office and branch office, and the other way around, should't you be used ipsec-policy=out, ipsec, rather than ipsec-policy=in, ipsec? According to the direction of the traffic, it seems to be traffic from "local lan" network to "remote lan" network, and my head turns this in "out, ipsec" policy.

I tried with your setup for MSS, and no traffic is generated in the mangle rule, but if I use "ipsec-policy=out, ipsec", the packet counter starts flowing.

Thanks again!

javierhorrillo
Автор

I'm going to have to go through the PDF. The Mikrotik device that has my public IP is port forwarding all TCP/UDP and ESP traffic to the Mikrotik in my office. Still no joy. I have created the relevant DNS records on my DNS server. Will re-look at the configs later. Lots of information to understand. Thanks for the great tutorial nonetheless.

Stephenvr
Автор

How mode config for the client router should look like? Couldn't find it in the pdf.

jiricech
Автор

OpenVPN can work in TCP433 port (open in any firewall) but can also work in UDP mode

vrgpy
Автор

what about wireguard compare to this now ?

liamxin
Автор

Thanks for the tutorial. I have followed the tutorial step by step using a Router RB4011 (Server) and a CRS109 (Client) both in version 6.47.4 Both establish the connection with Ipsec with Ike2, but when I try to ping the server from the client there is no response to unless I set a route in the Route list. When I try to ping the client from the server side I also don't get a reply if I create a route it doesn't work either. All this testing is trying to ping the address range of my lan on both ends. The only way it answers is if I ping the 10.0.88.0/24 range on both sides. Am I missing something in my configuration? I have turned off the firewall and it does not work either. Any firewall rule that I need to create? Thanks with any answer.

abrahamrosa
Автор

Nikita, thank you very much, but выучи английский нормально плиз :-)

PaulCherepnin
Автор

Dear Nikita, stay home and enjoy vodka.... You don't have a

eniszulufepustampasic