Answer the question
In order to leave comments, you need to log in
L2tp + ipsec tunnel between mikrotik-mikrotik, how to make friends with Fasttrack connection?
We have a working L2tp+ipsec channel between 2 (5!) Mikrotiks. When setting up a Fasttrack connection, according to the manuals on the Internet, there is Internet access, but the traffic stops running through the tunnel. It feels like the rout list of Mikrotik just breaks, and all the traffic that should be wrapped in the tunnel flies to the Internet.
I tried to exclude ipsec traffic with mangle rules and set !ipsec in the Fasttrack connection settings - it does not help.
Rested on 100% CPU, and changing the piece of iron is not yet practical.
Could you tell me what information to give to be able to resolve the issue?
Answer the question
In order to leave comments, you need to log in
Yes. Fasttrack allows traffic past the firewall and the traffic does not fall under IPsec.
In your case, you need to change the FastTrack rule so that it does not affect traffic that should fall under IPsec.
The CPU is 100% loaded due to the fact that a lot of resources are spent on encryption. FastTrack will not solve this problem. You need a piece of hardware that supports hardware encryption.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question