Buongiorno ragazzi,
sto cercando di configurare una vpn lan to lan tra un 951 e una rb1100.
Vi inserisco le configurazioni:
RB951
/ip address
add address=82.a.b.3/29 comment=WAN interface=ether2 network=82.a.b.0
add address=172.16.20.1/24 comment=LAN interface=ether5 network=172.16.20.0
/ip firewall filter
add chain=forward protocol=ipsec-esp
add chain=forward protocol=ipsec-ah
add chain=forward dst-port=500 protocol=udp
add chain=forward dst-port=4500 protocol=udp
/ip firewall nat
add chain=srcnat dst-address=172.16.30.0/24 src-address=172.16.20.0/24
add action=masquerade chain=srcnat out-interface=ether2
/ip ipsec proposal
set [ find default=yes ] enc-algorithms=aes-128-cbc,aes-256-cbc lifetime=8h
add enc-algorithms=3des name=proposal1 pfs-group=none
/ip ipsec peer
add address=89.a.b.214/32 lifetime=8h nat-traversal=yes secret=test
/ip ipsec policy
add dst-address=172.16.30.0/24 src-address=172.16.20.0/24 template=yes
RB1100
/ip address
add address=82.a.b.4/29 disabled=no interface=ether1 network=82.a.b.0
add address=172.16.30.1/24 disabled=no interface=ether2 network=172.16.30.0
/ip firewall connection tracking
set enabled=yes generic-timeout=10m icmp-timeout=10s tcp-close-timeout=10s \
tcp-close-wait-timeout=10s tcp-established-timeout=1d tcp-fin-wait-timeout=\
10s tcp-last-ack-timeout=10s tcp-syn-received-timeout=5s \
tcp-syn-sent-timeout=5s tcp-syncookie=no tcp-time-wait-timeout=10s \
udp-stream-timeout=3m udp-timeout=10s
/ip firewall filter
add action=accept chain=forward disabled=no protocol=ipsec-esp
add action=accept chain=forward disabled=no protocol=ipsec-ah
add action=accept chain=forward disabled=no dst-port=4500 protocol=udp
add action=accept chain=forward disabled=no dst-port=500 protocol=udp
/ip firewall nat
add action=accept chain=srcnat disabled=no dst-address=172.16.20.0/24 \
src-address=172.16.30.0/24
add action=masquerade chain=srcnat disabled=no out-interface=ether1
/ip firewall service-port
set ftp disabled=no ports=21
set tftp disabled=no ports=69
set irc disabled=no ports=6667
set h323 disabled=no
set sip disabled=no ports=5060,5061 sip-direct-media=yes
set pptp disabled=no
/ip ipsec proposal
set [ find default=yes ] auth-algorithms=sha1 disabled=no enc-algorithms=\
3des,aes-128,aes-256 lifetime=30m name=default pfs-group=modp1024
/ip ipsec peer
add address=89.a.b.213/32 auth-method=pre-shared-key dh-group=modp1024 \
disabled=no dpd-interval=2m dpd-maximum-failures=5 enc-algorithm=aes-128 \
exchange-mode=main generate-policy=no hash-algorithm=sha1 lifebytes=0 \
lifetime=1d my-id-user-fqdn="" nat-traversal=yes port=500 proposal-check=\
obey secret=test send-initial-contact=yes
/ip ipsec policy
add action=encrypt disabled=no dst-address=172.16.20.0/24 dst-port=any \
ipsec-protocols=esp level=require priority=0 proposal=default protocol=all \
sa-dst-address=89.a.b.213 sa-src-address=89.a.b.214 src-address=\
172.16.30.0/24 src-port=any tunnel=yes
Vi ringrazio in anticipo
Nicola