B
B
brar2016-05-22 15:27:41
Debian
brar, 2016-05-22 15:27:41

What would you recommend to use: strongswan or openvpn, etc?

Hello.
VDS on Debian 8 stable - static white IP.
Mikrotik 951: - dynamic IP behind two NAT Provo:

traceroute to 8.8.8.8 (8.8.8.8), 30 hops max, 60 byte packets
 1  192.168.77.1 (192.168.77.1)  0.292 ms  0.327 ms  0.374 ms
 2  172.16.16.10 (172.16.16.10)  1.052 ms  1.063 ms  1.103 ms
 3  10.142.255.20 (10.142.255.20)  1.391 ms  1.536 ms  1.537 ms
...

You need to raise the tunnel. Advise, please.

Answer the question

In order to leave comments, you need to log in

3 answer(s)
A
Alexander Karabanov, 2016-05-22
@brar

Once Mikrotik, then strongswan without options.

E
EckS, 2016-05-22
@EckS

It seems to me that OpenVPN will work more correctly behind two nats, although it’s worth trying
L2TP, theoretically it will also push through. Raise ipsec inside L2TP.

A
athacker, 2016-07-11
@athacker

It does not follow from the trace that you have exactly two NATs there :-) Routers in the provider's network may well use gray addresses, while routing Internet traffic with white IPs.
I will support the speaker above - it is better to build an L2TP tunnel, inside which IPsec is already running.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question