GRE over IPsec using MikroTik

Published:

Updated:

Author:

GRE tunnel MikroTik

 

Mikrotik-1GRE Tunnel and IP Address Configuration:

MikroTik1> ip address add address=10.10.10.2/30 interface=ether1

MikroTik1> ip address add address=192.168.1.1/24 interface=ether5

MikroTik1> interface gre add name= gre-tunnel1 local-address=10.10.10.2 remote-address=10.10.10.6

MikroTik1> ip address add address=172.16.1.1/30 interface= gre-tunnel1

 

Mikrotik-1 Router IPSec VPN Configuration: 

MikroTik-1>ip ipsec peer>add address=10.10.10.6/32:500 auth-method=pre-shared-key secret=”password”

generate-policy=no exchange-mode=main send-initial-contact=yes

nat-traversal=no proposal-check=obey hash-algorithm=sha1

enc-algorithm=3des dh-group=modp1024 lifetime=1d lifebytes=0

dpd-interval=disable-dpd dpd-maximum-failures=1

MikroTik-1> ip ipsec policy>add src-address=10.10.10.2/32:any dst-address=10.10.10.6/32:any

protocol=all action=encrypt level=require ipsec-protocols=esp tunnel=yes

sa-src-address=10.10.10.2 sa-dst-address=10.10.10.6 proposal=default

priority=0

MikroTik-1 >ip ipsec proposal>add name=”default” auth-algorithms=sha1 enc-algorithms=3des lifetime=30m  pfs-group=modp1024

 

Mikroitk-1 Router OSPF Configuration:

MikroTik-1> routing ospf> network add network=192.168.1.0/24 area=backbone

MikroTik-1> routing ospf> network add network=172.16.1.0/30  area=backbone

 

Mikrotik-2 GRE Tunnel and IP Address Configuration:

MikroTik2# ip address add address=10.10.10.6/30 interface=ether1

MikroTik2# ip address add address=192.168.2.1/24 interface=ether5

MikroTik2# interface gre add name= gre-tunnel1 local-address=10.10.10.6 remote-address=10.10.10.2

MikroTik2# ip address add address=172.16.1.2/30 interface= gre-tunnel1

 

Mikrotik-2 Router IPSec VPN Configuration: 

MikroTik-2#ip ipsec peer>add address=10.10.10.2/32:500 auth-method=pre-shared-key secret=”password”

generate-policy=no exchange-mode=main send-initial-contact=yes

nat-traversal=no proposal-check=obey hash-algorithm=sha1

enc-algorithm=3des dh-group=modp1024 lifetime=1d lifebytes=0

dpd-interval=disable-dpd dpd-maximum-failures=1

MikroTik-2#ip ipsec policy>add src-address=10.10.10.6/32:any dst-address=10.10.10.2/32:any

protocol=all action=encrypt level=require ipsec-protocols=esp tunnel=yes

sa-src-address=10.10.10.6 sa-dst-address=10.10.10.2 proposal=default

priority=0

MikroTik-2#ip ipsec proposal>add name=”default” auth-algorithms=sha1 enc-algorithms=3des lifetime=30m  pfs-group=modp1024

 

Mikroitk-2 Router OSPF Configuration:

MikroTik-2#routing ospf> network add network=192.168.2.0/24 area=backbone

MikroTik-2#routing ospf> network add network=172.16.1.0/30  area=backbone




Leave a Reply

Blog Posts

  • How to disable WiFi on Spectrum Router

    How to Disable WiFi on Your Spectrum Router: A Step-by-Step Guide Recommended Product: Reyee Whole Home Mesh WiFi System, AX3200 Smart WiFi 6 Router RG-R6 (1-Pack), Cover 3000Sq. Ft, Connect up to 110 Devices, Replaces Wireless WiFi Routers and Extenders Need a digital detox? Want to temporarily secure your network? Knowing how to disable your

    Read more

  • 5 Top Best Wi-Fi Extender For Verizon Fios Reviews

    5 Top Best Wi-Fi Extender For Verizon Fios Reviews

    Verizon Fios provides blazing-fast internet, but sometimes your signal doesn’t reach every corner of your home. That’s where a Wi-Fi extender comes in handy. Finding the best Wi-Fi extender for Verizon Fios can be tricky, so we’ve reviewed five top contenders to help you choose the perfect one. TP-Link AC1900 WiFi Range Extender RE550 |

    Read more

  • 5 Top Best Wi Fi Extender For Telus Internet Reviews

    5 Top Best Wi Fi Extender For Telus Internet Reviews

    Finding the best Wi-Fi extender for your Telus internet can be tricky. A weak signal can ruin your streaming, gaming, and overall online experience. This guide reviews five top contenders to help you choose the perfect solution. Fastest WiFi Extender Signal Booster – Coverage Up Check it out on Amazon This extender promises speed and

    Read more