Nakonfigurovani IPsecu se povedlo a spojeni bylo OK. Po par dnech se IPsec odpojil a neni mozne znova navazat spojeni.
Po par hodinach se IPsec navaze, ale neni mozne prochazet siti.
V logu se ukazuje ze IPsec se snazi smerovat provoz na port 500 misto 4500.
02:26:37 ipsec,debug,packet 760 bytes from 10.1.1.12[500] to xx.xx.xx.xx[4500]
02:26:37 ipsec,debug,packet sockname 10.1.1.12[500]
02:26:37 ipsec,debug,packet send packet from 10.1.1.12[500]
02:26:37 ipsec,debug,packet send packet to xx.xx.xx.xx[4500]
02:26:37 ipsec,debug,packet src4 10.1.1.12[500]
02:26:37 ipsec,debug,packet dst4 xx.xx.xx.xx[4500]
02:26:37 ipsec,debug,packet 1 times of 760 bytes message will be sent to xx.xx.xx.xx[4500]
02:26:37 ipsec,debug,packet 0ee713a3 cbaecfd3 00000000 00000000 01100400 00000000 000002f8 04000040
02:26:37 ipsec,debug,packet 00000001 00000001 00000034 01010001 0000002c 01010000 800b0001 000c0004
02:26:37 ipsec,debug,packet 00015180 800b0002 800c003c 80010005 80030001 80020002 8004000f 0a000184
02:26:37 ipsec,debug,packet 81d52d6d dfcb41fe 9e4da2ac af5a94e2 6000c84d aaf9f204 663a1bf7 2796f167
02:26:37 ipsec,debug,packet 20f0342e 0047b3e5 ef533d21 2b39fd61 4c40de9c 8c5a7b09 1edb8095 b196b678
02:26:37 ipsec,debug,packet c23e2848 822d0826 4cf5d45e 188b67db cbac9cd4 fb0a162b d2cb3a5e 3d173e0d
02:26:37 ipsec,debug,packet abd51be9 134581bf 6f6e8cb3 d1ef8d41 6ac28301 28fc2cbc 052bef5e 21371550
02:26:37 ipsec,debug,packet fbd65484 d5565a50 efc6472e d8813188 5c3e5f12 f6484db4 241c123f 5fd53d80
02:26:37 ipsec,debug,packet 8923cb1f 8a8c014d 673afa8d 7c56b037 9fc8dd05 c254641c 83e1bb63 9465fabd
02:26:37 ipsec,debug,packet 8f85779c 562efad7 e471c456 7ff03b14 626f37ef def43c6f 85fbf098 8e3a5e91
02:26:37 ipsec,debug,packet d886bca0 11ef9308 d973de87 11997661 9044d016 1ddcad04 6567044f 1360b4cc
02:26:37 ipsec,debug,packet 4ed53866 f100f87d fbb76888 f7a493e4 0b7e67b5 09d683eb a5494b28 a6bbf0c4
02:26:37 ipsec,debug,packet 02c7d568 8aaf8343 9c158ed1 e89bfcc8 c5eb87cc 77ce38f1 ea81e2fe 1d4ce7c9
02:26:37 ipsec,debug,packet c7cf0ab0 695323eb 26adafb2 335ecb8e 31766da0 518ffa04 bcf53619 a75d5f9d
02:26:37 ipsec,debug,packet a86bac0a 9f23de3b f2d01ced b5ed220f 99a641da 6ff4e155 22405661 55c31795
02:26:37 ipsec,debug,packet 0500001c d004d797 54ef7872 ea44be6c 652537b6 da68e153 4ca602c5 0d00000c
02:26:37 ipsec,debug,packet 011101f4 0a01010c 0d000014 4a131c81 07035845 5c5728f2 0e95452f 0d000014
02:26:37 ipsec,debug,packet 8f8d8382 6d246b6f c7a8a6a4 28c11de8 0d000014 439b59f8 ba676c4c 7737ae22
02:26:37 ipsec,debug,packet eab8f582 0d000014 4d1e0e13 6deafa34 c4f3ea9f 02ec7285 0d000014 80d0bb3d
02:26:37 ipsec,debug,packet ef54565e e84645d4 c85ce3ee 0d000014 9909b64e ed937c65 73de52ac e952fa6b
02:26:37 ipsec,debug,packet 0d000014 7d9419a6 5310ca6f 2c179d92 15529d56 0d000014 cd604643 35df21f8
02:26:37 ipsec,debug,packet 7cfdb2fc 68b6a448 0d000014 90cb8091 3ebb696e 086381b5 ec427b1f 0d000014
02:26:37 ipsec,debug,packet 16f6ca16 e4a4066d 83821a0f 0aeaa862 0d000014 4485152d 18b6bbcd 0be8a846
02:26:37 ipsec,debug,packet 9579ddcc 00000014 afcad713 68a1f1c9 6b8696fc 77570100
02:26:37 ipsec,debug,packet resend phase1 packet 0ee713a3cbaecfd3:0000000000000000
02:26:46 ipsec,debug phase2 negotiation failed due to time up waiting for phase1. ESP xx.xx.xx.xx[4500]->10.1.1.12[500]
02:26:47 ipsec,debug delete phase 2 handler.
02:26:47 ipsec,debug phase1 negotiation failed due to time up. 0ee713a3cbaecfd3:0000000000000000
Prikladam konfiguraci IPsecu pro oba MK.
Router A
/ip ipsec policy
src-address=192.168.1.0/24 src-port=any dst-address=192.168.2.0/24
dst-port=any protocol=all action=encrypt level=require ipsec-protocols=esp
tunnel=yes sa-src-address=10.3.56.50 sa-dst-address=xx.xx.xx.xx
proposal=IPsecP priority=1
IP 10.3.56.50 prirazena DHCP serveur od providera (NAT 1:1)
/ip ipsec peer
address=xx.xx.xx.xx/32 port=4500 auth-method=pre-shared-key
secret="Heslo123*/" generate-policy=no exchange-mode=aggressive
send-initial-contact=no nat-traversal=yes my-id-user-fqdn=""
proposal-check=exact hash-algorithm=sha1 enc-algorithm=3des
dh-group=modp3072 lifetime=1d lifebytes=60 dpd-interval=disable-dpd
dpd-maximum-failures=1
/ip ipsec proposal
name="IPsecHome" auth-algorithms=sha1 enc-algorithms=3des lifetime=1d
pfs-group=modp1536
Router B
/ip ipsec policy
src-address=192.168.2.0/24 src-port=any dst-address=192.168.1.0/24
dst-port=any protocol=all action=encrypt level=require
ipsec-protocols=esp tunnel=yes sa-src-address=10.1.1.12
sa-dst-address=xx.xx.xx.xx proposal=IPsecHome priority=1
IP 10.1.1.12 prirazena DHCP serveru od providera presmerovane jenom porty 4500-4510
/ip ipsec peer
address=xx.xx.xx.xx/32 port=4500 auth-method=pre-shared-key
secret="Heslo123*/" generate-policy=no exchange-mode=aggressive
send-initial-contact=yes nat-traversal=yes my-id-user-fqdn=""
proposal-check=exact hash-algorithm=sha1 enc-algorithm=3des
dh-group=modp3072 lifetime=1d lifebytes=60 dpd-interval=disable-dpd
dpd-maximum-failures=1
/ip ipsec proposal
name="IPsecP" auth-algorithms=sha1 enc-algorithms=3des lifetime=1d
pfs-group=modp1536