vpn:mikrotik_ikev2
Различия
Показаны различия между двумя версиями страницы.
| Предыдущая версия справа и слеваПредыдущая версияСледующая версия | Предыдущая версия | ||
| vpn:mikrotik_ikev2 [2019/09/19 14:04] – bers | vpn:mikrotik_ikev2 [2019/09/19 17:17] (текущий) – bers | ||
|---|---|---|---|
| Строка 1: | Строка 1: | ||
| - | ===== Configure KeepSolid | + | ===== Configure KeepSolid |
| Go to KeepSolid cabinet and generate config IKEv2 for Windows. | Go to KeepSolid cabinet and generate config IKEv2 for Windows. | ||
| Строка 15: | Строка 15: | ||
| {{: | {{: | ||
| - | Import your certificate: | + | Import your certificate: |
| {{: | {{: | ||
| - | Next open Ipsec - Profiles - Add New | + | Next open **Ipsec - Profiles - Add New** |
| {{: | {{: | ||
| - | Next create proposal: Ipsec - Proposals - Add New | + | Next create proposal: |
| {{: | {{: | ||
| - | Create new group: Ipsec - Groups - Add New | + | Create new group: |
| {{: | {{: | ||
| - | Create ipsec policie: Ipsec - Policies - Add New | + | Create ipsec policie: |
| {{: | {{: | ||
| - | Add mode-config: | + | Add mode-config: |
| {{: | {{: | ||
| - | Create ipsec peer: Ipsec - Peers - Add New | + | Create ipsec peer: **Ipsec - Peers - Add New** |
| {{: | {{: | ||
| - | Add ipsec identity: Ipsec - Identities - Add New | + | Add ipsec identity: |
| {{: | {{: | ||
| - | Established connections see in Ipsec - Active peers and Ipsec - Installed SAs | + | Established connections see in **Ipsec - Active peers and Ipsec - Installed SAs** |
| + | |||
| + | To send all traffic to the tunnel create address-list with your local network: **Firewall - Address Lists** | ||
| + | |||
| + | {{: | ||
| + | |||
| + | Assign this list to your mode-config: | ||
| + | |||
| + | {{: | ||
| + | |||
| + | Don't forget to disable Fasttrack in Firewall. | ||
| + | |||
| + | That's all. | ||
| + | |||
| + | |||
| + | === P.S. Send only needed traffic to the tunnel === | ||
| + | |||
| + | Create connection-mark: | ||
| + | |||
| + | {{: | ||
| + | |||
| + | Add needed ip to address list: **Firewall - Address Lists - Add New** | ||
| + | |||
| + | {{: | ||
| + | |||
| + | You can add different ip with the same Address List name. | ||
| + | |||
| + | Create mangle rule: **Firewall - Mangle - Add New** | ||
| + | |||
| + | {{: | ||
| + | |||
| + | {{: | ||
| + | |||
| + | If you have enabled **Fasttrack** edit the rule | ||
| + | |||
| + | {{: | ||
vpn/mikrotik_ikev2.1568901888.txt.gz · Последнее изменение: — bers
