hwdsl2 / setup-ipsec-vpn

Scripts to build your own IPsec VPN server, with IPsec/L2TP, Cisco IPsec and IKEv2
Other
25.34k stars 6.33k forks source link

ikev2 mikrotik configuration #1034

Closed amirabasalinaghi closed 3 years ago

amirabasalinaghi commented 3 years ago

can you please add client setup (ikev2) for mikrotik routeros ? i dont know how to setup ikev2 methode on mikrotik i tried many configurations but failed thanks

hwdsl2 commented 3 years ago

@amirabasalinaghi Hello! Mikrotik routers as an IKEv2 client is currently not supported.

Unix-User commented 2 years ago

can you please add client setup (ikev2) for mikrotik routeros ? i dont know how to setup ikev2 methode on mikrotik i tried many configurations but failed thanks

In winbox, System > certificates > import. Import the .p12 certificate file twice(yes import the same file two times!!!) Run these in terminal:

/ip ipsec mode-config
add name=ike2-rw responder=no
/ip ipsec policy group
add name=ike2-rw
/ip ipsec profile
add name=ike2-rw
/ip ipsec peer
add address=YOUR_SERVER_ADDRESS_OR_DNS exchange-mode=ike2 name=ike2-rw-client profile=ike2-rw
/ip ipsec proposal
add name=ike2-rw pfs-group=none
/ip ipsec identity
add auth-method=digital-signature certificate=certificate.p12_1 generate-policy=port-strict mode-config=ike2-rw \
    peer=ike2-rw-client policy-template-group=ike2-rw
/ip ipsec policy
add group=ike2-rw proposal=ike2-rw template=yes

tested on mar/02/2022 12:52:57 by RouterOS 6.48 RouterBOARD 941-2nD

kadkin-a commented 1 year ago

RouterOS 7.9 model RB750Gr3 I m trying to setup IKEV2 on mikrotik. But, I couldn't add .p12 certificate I add a file .p12 and nothing certificate appears in the list.

hwdsl2 commented 1 year ago

@kadkin-a Please see: https://github.com/hwdsl2/setup-ipsec-vpn/blob/master/docs/ikev2-howto.md#routeros