D
D
Dmitry Lebedev2016-08-21 19:14:08
VPN
Dmitry Lebedev, 2016-08-21 19:14:08

How to set up IPSec VPN (Site-to-Site) between Mikrotik and Zyxel Zywall?

Hello.
The other day there was such a problem to organize IPSec VPN (Site-to-Site) between Mikrotik and Zywall.
Initial data:
Zywall
external IP - xxx.xxx.xxx.xxx
Local network - 192.168.91.0/24
VPN settings
Phase 1
Phase 2
Routing
Mikrotik
external IP - yyy.yyy.yyy.yyy
Local network - 192.168.88.0/24
VPN settings >
IPSec
Firewall
VPN installed successfully. Both from the side of Mikrotik and from the side of Zywall.
But this is not a problem, packets from the local network (192.168.91.0/24) Zywall go to the Local network (192.168.88.0/24) Mikrotik, but they don’t want to go back.
I haven’t re-read how many articles I just didn’t do, but Mikrotik doesn’t want to see the local network behind Zywall.
The problem is clearly in routing, but I don’t know how to fix it, so I’m asking for help.

Answer the question

In order to leave comments, you need to log in

3 answer(s)
C
CityCat4, 2016-08-22
@k3NGuru

Where are the politicians? Separate routing - well, at least on Mikrotik - is not needed . Mikrotik will figure out where to send it. But naturally, firewall rules are needed that allow traffic to pass after it is decrypted.
It is the politicians who link the virtual subnets and the tunnel.
That is, if on the fingers, what happens after the connection is there.
1. Incoming package.
Mikrotik received an ESP package. If the firewall rules missed it (input / output chains, not forward!), then Mikrotik looks for security associations (SA) - is there an association with this ID? If there is, then the packet is decrypted and re- passes the firewall - this time the forward chain - and goes to the desired interface.
2. Outgoing packet
Mikrotik received a packet from the internal network. If the rules of the forward chain missed it, then it looks at the security policies (SP) - whether this packet needs to be encrypted. If necessary, the addresses of the beginning and end of the tunnel are taken from the policy, SA is searched for them, the key is taken from SA, the packet is encrypted and again passes through the firewall - in encrypted form. If they missed him, he went.
There is no routing anywhere here, here ESP instead of it. Zukhel accurately decrypts packets from Mikrotik? If you use SHA256 - refuse, Mikrotik has some kind of its own implementation, compatible only with Mikrotik, set SHA1.

G
Gregory, 2016-08-21
@Maxlinus

on mikrotik in / IP / Routes did you add a route to the network 192.168.91.0/24 ?
https://habrahabr.ru/post/216215/
does zyxel have access via ssh/telnet or how to use the command line to see the list of routes there?

F
frjonatan, 2018-03-13
@frjonatan

There was a similar problem, it was solved by setting the route on Mikrotik (Dst-Remote sub Gate-LAN) and allowing packets from the local subnet to the remote one in the Zywall firewall

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question