E
E
Eugene2019-10-22 09:16:15
VPN
Eugene, 2019-10-22 09:16:15

IPSec VPN breaks between Mikrotik and vCloud Edge. Where to dig?

Good afternoon.
We have a virtual server in the data center running vCloud
At the other end is an enterprise network with two internal subnets. Managed via Mikrotik
To access virtual machines in the data center, you need to configure IPsec site-to-site VPN with Mikrotik
After raising the connection, 2 problems appeared
When using IKEv1
1. When establishing a connection, packets from the enterprise network do not go to the data center until packets from DPC.
Sounds stupid, but true. Until I launch a ping from the data center towards the enterprise network, nothing goes towards the data center.
Politicians hang in the PH2="no phase2" status.
When using IKEv2, the situation is slightly different. The connection rises by itself. Without crutches with ping. However, policies only work for one enterprise subnet. The tunnel for the second network does not rise and always hangs in the PH2="no phase2" status.
2. After a certain period of inactivity, the lifted tunnel is terminated. (when using IKEv1. Behavior with IKEv2 cannot be tested yet)
What could be the reason for this behavior?
I can't figure out the problem on the vCloud or Mikrotik side?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
R
RomanMRB, 2019-11-29
@RomanMRB

there is a problem in Mikrotik, look at the logs and ipsec

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question