Community discussions

MikroTik App
Fuzzaqqq
just joined
Topic Author
Posts: 1
Joined: Wed Nov 02, 2016 2:27 pm

Route traffic for another subnet to ipsec tunnel

Wed Nov 02, 2016 2:45 pm

Hello!

We have following configuration:

Site1 (Mikrotik) Site2 (Juniper)
LAN 192.168.10.0/24 LAN 192.168.11.0/24
LAN2 172.16.1.0/24

There is policy based ipsec tunnel between Site1 and Site2 with src and dst LANs 192.168.10.0 and 192.168.11.0. Recently LAN2 on Site2 was added.

Is it possible to configure Mikrotik to access Site2's LAN2 from Site1 through ipsec tunnel?

Thank you.
Top
andriys
Forum Guru
Forum Guru
Posts: 1480
Joined: Thu Nov 24, 2011 1:59 pm
Location:Kharkiv, Ukraine

再保险:路线交通ipsec tunn另一个子网el

Wed Nov 02, 2016 4:33 pm

Is it possible to configure Mikrotik to access Site2's LAN2 from Site1 through ipsec tunnel?
It is, but you will need to update the configuration on both Mikrotik and Juniper.
You need to add another policy to cover communication between 192.168.10.0/24 (site 1 if I understood you correctly) and 172.16.1.0/24 (lan2 on site 2) networks.
Top
User avatar
BlackVS
Member Candidate
Member Candidate
Posts: 171
Joined: Mon Feb 04, 2013 7:00 pm
Contact:

再保险:路线交通ipsec tunn另一个子网el

Thu Nov 03, 2016 6:49 pm

I see 2 variants:
A) separate policy for each pair of source and destination networks as wrote above. I had this long time ago and stopped to use when a number of remote offices exceded three and a number of networks exceed ten %)
B) use IPSEC over another tunnel. For example GRE+IPSEC. In such case you can use usual routing. Much easier for maintenace. And possibility to run OSPF like protocols over such tunnels.
Top

Who is online

Users browsing this forum:Bing [Bot],DanMos79,ilhami,Semrush [Bot],vshaev60and 28 guests