M
M
modcode2022-04-04 11:56:43
VPN
modcode, 2022-04-04 11:56:43

Why not connect ikev2 to mikrotik?

My version of routeros is 6.48 but I can update or update if necessary
I followed step by step in this instruction
https://support.surfshark.com/hc/en-us/articles/36...

But vpn doesn't connect, internet works

You can can you help me find out where my mistake is?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
A
AlexVWill, 2022-04-04
@AlexVWill

I don’t know what’s wrong in your case (you didn’t give the logs, and what you did yourself so that you didn’t write the error, and the telepaths are all on vacation), but most often people make mistakes in the settings of authorization mechanisms and encryption protocols.
Let's say you imported the certificate correctly, the IP and login-password also started correctly (check just in case) ...
Then give the command on the server
sudo cat /etc/ipsec.conf
and look at the last lines, they will be something like this:


eap_identity=%identity
ike=chacha20poly1305-sha512-curve25519-prfsha512,aes256gcm16-sha384-prfsha384-ecp384,aes256-sha1-modp1024,aes128-sha1-modp1024,3des-sha1-modp1024!
esp=chacha20poly1305-sha512,aes256gcm16-ecp384,aes256-sha256,aes256-sha1,3des-sha1!

Go to Winbox and in IP->IPSec->Proposals compare if there are any encryption methods that are not supported by the server, leave some minimum that the server supports, for example:
sha1, sha256, aes-128, cbc, aes-192 cbc , aes-256 cbc, modp1024.
IP->IPSec->Peers check what IKE2 costs.
IP->IPSec->Identities, check MS-Chap 2.0, and eap authentication method
IP->IPSec->Profiles, check 3des

C
CityCat4, 2022-04-04
@CityCat4

Telepaths on vacation, where are the logs, Zin? On Mikrotik, IPSec logs differ in downright senile details ...

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question