Answer the question
In order to leave comments, you need to log in
Mikrotik ipsec routing?
Good afternoon.
Tell me how to properly configure routing so that when accessing from 3 subnets, you can get to the first one without doing another ipsec, but simply forward it through Mikrotik with 2 subnets.
If you write in IP-Routes that when you request network 1.0, go to 2.0, it says that it does not see network 2.0.
Thank you!
Answer the question
In order to leave comments, you need to log in
IPSec in Mikrotik (and also in Linux) does not work at the routing level, but next to it and independently of it (you can make sure by the fabulous scheme, which is _very understandable_ wiki.mikrotik.com/wiki/Manual:Packet_Flow - the last two pictures) t .e. routing traffic inside the tunnel is not possible - it is only possible to establish a tunnel for the desired traffic.
You will be saved (from the need for a direct link) by working in transport mode + GRE, into which the necessary traffic will already be routed.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question