FOR TIPS, gUIDES & TUTORIALS

subscribe to our Youtube

GO TO YOUTUBE

14455 questions

17168 answers

28195 comments

0 members

We are migrating to our new platform at https://community.teltonika.lt. Moving forward, you can continue discussions on this new platform. This current platform will be temporarily maintained for reference purposes.
0 votes
1,213 views 1 comments
by anonymous
Hello,

I would like to create a link between a RUT955 router and a Mikrotik router. The VPN is already defined in the Mikrotik (IPsec only).

The RUT955 hasn't a public address.

Nevertheless, by using the IPsec configuration (services > VPN > IPsec), is it possible to create the link ?

If yes, could you help me to fill the fields because I don't understand the wiki !

Thank's by advance,

Note 1:

IKE version: IKEV2

Mode: main ?????

Type: tunnel

identifier type: ?????

on startup: start

my identifier: ?????

Local ip address: 192.168.1.0/24

Force encaps: ?????

Dead peer detection: ?????

Remote VPN endpoint: mymikrotik.com  for example !

Remote ip address: 192.168.1.0/24                As the local IP ! possible ?

Phase 1 and Phase 2 as Mikrotik setting

And what about certificates ???

1 Answer

0 votes
by anonymous

Hello,

Yes, you can establish IPsec between Mikrotik and RUT955 router (which does not have Public IP), since IPsec only requires one tunnel end to have Public IP (which, as I understood, your mikrotik router has).

Regarding the configuration, were you looking at this Teltonika wiki article?:

https://wiki.teltonika.lt/view/IPsec_configuration_examples

   - If yes, could I ask which part of this article about IPsec configuration example was confusing for you? Maybe certain paragraphs needs more detailed description?

   - If no, try checking above wiki link. In it everything is explained from topology aspects to how to check if connection is working. In your case you would simply need to mimic your Mikrotik's IPsec configuration on your RUT955

by anonymous

Yes I looked at this page but i am not a VPN specialist !

What is confusing there are only examples with RUT, with public IP addresses.

Idem for Openvpn: always examples with two instances

When I read "two RUT routers of any type" then I stop my read !

And the notion of certificates is not addressed.

In fact, what I want to do corresponds to the "configuration schema 2" : two sites, independant, with several PC, NAT, with same local lan range(192.168.1.0)

Shall the local IP addresses different ?

Shall I also fill the openvpn tab as client and reference the certificates here ?

Are the certificates in PKCS12 format supported ?