<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title>Mikrotik.moscow [тема: Маршрутизация трафика с беспроводных клиентов через IPsec]</title>
		<link>http://mikrotik.moscow</link>
		<description>Новое в теме Маршрутизация трафика с беспроводных клиентов через IPsec форума RouterOS на сайте Mikrotik.moscow [mikrotik.moscow]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Tue, 04 Aug 2026 13:36:51 -0400</pubDate>
		<item>
			<title>Маршрутизация трафика с беспроводных клиентов через IPsec</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402953">Маршрутизация трафика с беспроводных клиентов через IPsec</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Отметьте правильный ответ как «Решено», чтобы закрыть этот запрос. Пожалуйста. <br />
			<i>06.07.2021 15:15:00, SiB.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402953</link>
			<guid>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402953</guid>
			<pubDate>Tue, 06 Jul 2021 15:15:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Маршрутизация трафика с беспроводных клиентов через IPsec</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402952">Маршрутизация трафика с беспроводных клиентов через IPsec</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Да, ты прав! Правильная настройка сетей в политике IPSec решила эту проблему.<br /><br />&gt; ip ipsec policy print &nbsp;<br />Flags: T - шаблон, X - отключено, D - динамическое, I - недействительно, A - активно, * - по умолчанию &nbsp;<br /> # &nbsp; &nbsp; PEER &nbsp; &nbsp; &nbsp;TUNNEL SRC-ADDRESS &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;DST-ADDRESS &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;PROTOCOL &nbsp; ACTION &nbsp;LEVEL &nbsp; &nbsp;PH2-COUNT &nbsp;<br /> 0 TX* &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;::/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ::/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; все &nbsp; &nbsp; &nbsp; <br /> 1 TX &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0.0.0.0/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0.0.0.0/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;все &nbsp; &nbsp; &nbsp; <br /> 2 &nbsp;A &nbsp;PROJECT &nbsp; yes &nbsp; &nbsp;10.0.1.0/27 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;10.0.0.0/16 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;все &nbsp; &nbsp; &nbsp; &nbsp;encrypt require &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1 &nbsp;<br /><br />Теперь я могу пинговать с клиента и вижу входящий трафик на центральном сервере с частной сети. Спасибо! <br />
			<i>06.07.2021 07:04:00, Borkoje.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402952</link>
			<guid>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402952</guid>
			<pubDate>Tue, 06 Jul 2021 07:04:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Маршрутизация трафика с беспроводных клиентов через IPsec</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402951">Маршрутизация трафика с беспроводных клиентов через IPsec</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Общее и главное правило в любом VPN — сайты, разные сайты… в ваших политиках сети одинаковые, и это меня просто ломает <img  src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" data-src="http://mikrotik.moscow/upload/main/smiles/2/bx_smile_smile.png" border="0" data-code=":)" data-definition="UHD" alt=":)" style="width:20px;height:20px;" title="С улыбкой" class="lazyload bx-smile" />. Я никогда так не делаю. Откуда вашему главному роутеру знать, что он должен идти к конкретному /27, если все три филиала используют одинаковую сеть 0.0.0.0/16? Когда у меня есть филиалы А, В, С и у всех одинаковая адресация, то первый устанавливает VPN, а остальные — это резервные входы, которые работают как FailOver. По-моему, ваша идея настроить весь трафик с одинаковыми подсетями на обеих сторонах — это первое, что нужно исправить. По поводу вашего IP Sniffer… вы же видите, что трафик идет в одном направлении… обратного пути нет! Вот ваш способ отслеживать это детальнее — через /ip firewall connections: откройте его в WinBox и используйте иконку фильтров. Дважды кликните по правилу и попробуйте проверить первые 4 IP-адреса. Помните, что сниффер можно запустить на обоих устройствах — чтобы один отправлял, а второй видел входящий трафик. <br />
			<i>05.07.2021 13:36:00, SiB.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402951</link>
			<guid>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402951</guid>
			<pubDate>Mon, 05 Jul 2021 13:36:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Маршрутизация трафика с беспроводных клиентов через IPsec</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402950">Маршрутизация трафика с беспроводных клиентов через IPsec</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Привет, SiB! Политика настроена правильно, насколько я понимаю, так как 10.0.0.0/16 — это приватный адрес с обеих сторон. Как думаешь, нужно ли мне задать конкретную сеть партнёра в SRC и DST &gt; /ip ipsec policy &gt; print?<br /><br />Flags: T - шаблон, X - отключено, D - динамическое, I - недействительно, A - активно, * - по умолчанию &nbsp;<br /># &nbsp; &nbsp; PEER &nbsp; &nbsp; TUNNEL SRC-ADDRESS &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; DST-ADDRESS &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; PROTOCOL &nbsp; ACTION &nbsp;LEVEL &nbsp; &nbsp;PH2-COUNT &nbsp;<br />0 T * &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;::/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ::/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; all &nbsp;<br />1 T &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0.0.0.0/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0.0.0.0/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;all &nbsp;<br />2 &nbsp;DA &nbsp;PROJECT yes &nbsp;10.0.0.0/16 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;10.0.0.0/16 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;all &nbsp; &nbsp; &nbsp; encrypt unique &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1 &nbsp;<br /><br />Пинг до 10.0.0.3 с клиентского устройства не проходит. Пинг с MikroTik работает: &nbsp;<br />&gt; /ping src-address=10.0.1.1 10.0.0.3 &nbsp;<br />SEQ HOST &nbsp; &nbsp; &nbsp; SIZE TTL TIME &nbsp;STATUS &nbsp;<br />0 &nbsp; 10.0.0.3 &nbsp; 56 &nbsp; 64 &nbsp;30ms &nbsp;<br />1 &nbsp; 10.0.0.3 &nbsp; 56 &nbsp; 64 &nbsp;14ms &nbsp;<br />2 &nbsp; 10.0.0.3 &nbsp; 56 &nbsp; 64 &nbsp;27ms &nbsp;<br />Отправлено=3, получено=3, потеря пакетов=0%, мин-респ=14ms, ср-респ=23ms, макс-респ=30ms &nbsp;<br /><br />Интересно смотреть на tool sniffer, вот полный лог с клиента — от подключения EAP до пинга 10.0.0.3: &nbsp;<br />&gt; /tool sniffer quick ip-address=10.0.0.3 &nbsp;<br /><br />IN &nbsp; &nbsp; TIME &nbsp; &nbsp;NUM DI SRC-MAC &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; DST-MAC &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; VLAN &nbsp; SRC-ADDRESS &nbsp; &nbsp; &nbsp; &nbsp;DST-ADDRESS &nbsp; &nbsp; &nbsp; &nbsp;PROTOCOL &nbsp; SIZE CPU &nbsp;<br />tm &nbsp; 31.722 &nbsp; &nbsp; &nbsp;8 &lt;- 00:D1:E6:E6:E6:E6 AC:FF:FF:00:00:00 &nbsp;10.0.0.3:1812 (radius) 10.0.1.1:52179 &nbsp;ip:udp &nbsp; &nbsp; &nbsp;191 &nbsp; 0 &nbsp;<br />tm &nbsp; 31.756 &nbsp; &nbsp; &nbsp;9 &lt;- 00:D1:E6:E6:E6:E6 AC:FF:FF:00:00:00 &nbsp;10.0.0.3:1812 (radius) 10.0.1.1:48780 &nbsp;ip:udp &nbsp; &nbsp; &nbsp;143 &nbsp; 0 &nbsp;<br />tm &nbsp; 31.791 &nbsp; &nbsp; 10 &lt;- 00:D1:E6:E6:E6:E6 AC:FF:FF:00:00:00 &nbsp;10.0.0.3:1812 (radius) 10.0.1.1:51324 &nbsp;ip:udp &nbsp; &nbsp; &nbsp;242 &nbsp; 0 &nbsp;<br />tm &nbsp; 31.865 &nbsp; &nbsp; 11 &lt;- 00:D1:E6:E6:E6:E6 AC:FF:FF:00:00:00 &nbsp;10.0.0.3:1813 (radius-acct) 10.0.1.1:46237 ip:udp &nbsp; &nbsp; &nbsp; 62 &nbsp; 0 &nbsp;<br />tm &nbsp; 35.426 &nbsp; &nbsp; 12 &lt;- 00:D1:E6:E6:E6:E6 AC:FF:FF:00:00:00 &nbsp;10.0.0.3:1812 (radius) 10.0.1.1:40309 &nbsp;ip:udp &nbsp; &nbsp; &nbsp; 90 &nbsp; 0 &nbsp;<br />tm &nbsp; 36.986 &nbsp; &nbsp; 13 &lt;- 00:D1:E6:E6:E6:E6 AC:FF:FF:00:00:00 &nbsp;10.0.0.3:1813 (radius-acct) 10.0.1.1:42579 ip:udp &nbsp; &nbsp; &nbsp; 62 &nbsp; 0 &nbsp;<br />LO &nbsp; 54.375 &nbsp; &nbsp; 14 &lt;- E6:92:B3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 &nbsp;<br />LO &nbsp; 54.375 &nbsp; &nbsp; 15 &lt;- E6:92:B3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 &nbsp;<br />LO &nbsp; 55.377 &nbsp; &nbsp; 16 &lt;- E6:92:B3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 &nbsp;<br />LO &nbsp; 55.377 &nbsp; &nbsp; 17 &lt;- E6:92:B3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 &nbsp;<br />LO &nbsp; 56.389 &nbsp; &nbsp; 18 &lt;- E6:92:B3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 &nbsp;<br />LO &nbsp; 56.389 &nbsp; &nbsp; 19 &lt;- E6:92:D3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 &nbsp;<br />LO &nbsp; 57.376 &nbsp; &nbsp; 20 &lt;- E6:92:B3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 &nbsp;<br />LO &nbsp; 57.376 &nbsp; &nbsp; 21 &lt;- E6:92:B3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 &nbsp;<br />LO &nbsp; 58.377 &nbsp; &nbsp; 22 &lt;- E6:92:B3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 &nbsp;<br />LO &nbsp; 58.377 &nbsp; &nbsp; 23 &lt;- E6:92:B3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 &nbsp;<br />LO &nbsp; 59.371 &nbsp; &nbsp; 24 &lt;- E6:92:B3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 &nbsp;<br />LO &nbsp; 59.371 &nbsp; &nbsp; 25 &lt;- E6:92:B3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 &nbsp;<br />LO &nbsp; 60.376 &nbsp; &nbsp; 26 &lt;- E6:92:B3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 &nbsp;<br />LO &nbsp; 60.376 &nbsp; &nbsp; 27 &lt;- E6:92:B3:D2:52:26 4A:8F:5A:AC:C1:54 &nbsp;10.0.1.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip:icmp &nbsp; &nbsp; &nbsp;98 &nbsp; 0 <br />
			<i>05.07.2021 12:18:00, Borkoje.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402950</link>
			<guid>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402950</guid>
			<pubDate>Mon, 05 Jul 2021 12:18:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Маршрутизация трафика с беспроводных клиентов через IPsec</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402949">Маршрутизация трафика с беспроводных клиентов через IPsec</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Для меня странно это: /ip ipsec policy add dst-address=0.0.0.0/0 group=PROJECT proposal=PROJECT src-address=0.0.0.0/0 template=yes. Кто сказал, что любой VPN-клиент из любой сети имеет доступ к любой сети? Я никогда не использую такое общее правило. Хмм, у тебя динамические пользователи, и они подключаются с любого Peer IP, но для твоего Encryption Domain нужно это регулировать. Все мои IPSec настроены для Site2Site, без каких-либо RoadWarriors пользователей.<br /><br />Если твоя IPSec Policy выглядит примерно так: Partner A) 10.0.1.1/27 &lt;=&gt; 10.0.0.3, тогда все пользователи должны получать IP из диапазона 10.0.1.2-30 и начинать общение, если твой файрвол не блокирует трафик. Весь NAT делается RouterOS, при условии, что политика на каждом сайте настроена корректно.<br /><br />С IPSec важно проверить:<br />*) соединение в файрволе;<br />*) попробуй пропинговать с клиента адрес 10.0.0.3;<br />*) попробуй пропинговать с Mtk Part.A: /ping src-address=10.0.1.1 10.0.0.3;<br />*) мониторинг трафика: /tools sniffer quick ip-address=10.0.0.3.<br /><br />Я пишу это на ходу, возможны ошибки в синтаксисе, но это способ диагностировать проблему. <br />
			<i>04.07.2021 14:33:00, SiB.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402949</link>
			<guid>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402949</guid>
			<pubDate>Sun, 04 Jul 2021 14:33:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Маршрутизация трафика с беспроводных клиентов через IPsec</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402948">Маршрутизация трафика с беспроводных клиентов через IPsec</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Спасибо, SiB! Наверное. Я предполагаю, что где-то не хватает политики IPSec или правила NAT, но с MikroTik я не слишком знаком. Вот упрощённая схема (только частные сети, без WAN-адреса центрального сервера). <br />
			<i>03.07.2021 19:57:00, Borkoje.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402948</link>
			<guid>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402948</guid>
			<pubDate>Sat, 03 Jul 2021 19:57:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Маршрутизация трафика с беспроводных клиентов через IPsec</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402947">Маршрутизация трафика с беспроводных клиентов через IPsec</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я не проверял твою конфигурацию тщательно, но вижу, что в /ip firewall nat у тебя только правило MASQ… Если я правильно понял твой трафик, тебе нужно сделать нормальное правило NAT для клиентов IPSec. Пожалуйста, создай какую-нибудь сетевую схему на draw.io или glify.com, или в mspaint и так далее. <br />
			<i>03.07.2021 16:06:00, SiB.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402947</link>
			<guid>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402947</guid>
			<pubDate>Sat, 03 Jul 2021 16:06:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Маршрутизация трафика с беспроводных клиентов через IPsec</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402946">Маршрутизация трафика с беспроводных клиентов через IPsec</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			У меня настроена следующая схема: IPSec-соединение от MikroTik к Linux-серверу, EAP/PEAP беспроводная сеть (RADIUS-запросы по IPSec к Linux-серверу), DHCP-сервер (RADIUS-запросы по IPSec к Linux-серверу, возвращает Framed-IP-Address). Мои беспроводные клиенты успешно подключаются, получают IP-адрес и выход в интернет. Но я не могу настроить доступ беспроводных клиентов к Linux-серверу (10.0.0.3) по приватному адресу через IPSec. С MikroTik я могу пинговать Linux-сервер, а с беспроводных клиентов — нет. Адрес Linux-сервера 10.0.0.3, сеть MikroTik IPSec — 10.0.0.0/27 (адреса 10.0.0.3-10.0.0.30 выделены для беспроводных клиентов).<br /><br />Ниже мой конфиг MikroTik. Если кто-то может дать совет, буду признателен.<br /><br />/interface bridge &nbsp;<br />add name="PROJECT Bridge" &nbsp;<br />add admin-mac=48:8F:5A:AC:C1:53 auto-mac=no comment=defconf name=bridge &nbsp;<br /><br />/interface wireless &nbsp;<br />set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-XX disabled=no distance=indoors frequency=auto installation=outdoor mode=ap-bridge ssid=MikroTik-ACC154 wireless-protocol=802.11  <br /><br />/interface list &nbsp;<br />add comment=defconf name=WAN &nbsp;<br />add comment=defconf name=LAN &nbsp;<br /><br />/interface lte apn &nbsp;<br />add apn=mobile4g authentication=pap default-route-distance=1 user=XXXXX &nbsp;<br /><br />/interface lte &nbsp;<br />set [ find ] apn-profiles=mobile4g mac-address=AC:FF:FF:00:00:00 name=mobile4g  <br /><br />/interface wireless security-profiles &nbsp;<br />set [ find default=yes ] supplicant-identity=MikroTik  <br />add authentication-types=wpa2-eap mode=dynamic-keys name=PROJECT radius-eap-accounting=yes supplicant-identity=PROJECT tls-mode=dont-verify-certificate &nbsp;<br /><br />/interface wireless &nbsp;<br />add disabled=no mac-address=4A:8F:5A:AC:C1:54 master-interface=wlan1 name=PROJECT security-profile=PROJECT ssid=PROJECT wds-default-bridge=bridge wps-mode=disabled &nbsp;<br /><br />/ip dhcp-server &nbsp;<br />add disabled=no interface="PROJECT Bridge" name="PROJECT DHCP" use-radius=yes &nbsp;<br /><br />/ip hotspot profile &nbsp;<br />set [ find default=yes ] html-directory=flash/hotspot  <br /><br />/ip ipsec mode-config &nbsp;<br />add name=PROJECT responder=no &nbsp;<br /><br />/ip ipsec policy group &nbsp;<br />add name=PROJECT &nbsp;<br /><br />/ip ipsec profile &nbsp;<br />add dh-group=modp1024 enc-algorithm=aes-256 name=PROJECT &nbsp;<br /><br />/ip ipsec peer &nbsp;<br />add address=1.1.1.1/32 exchange-mode=ike2 name=PROJECT profile=PROJECT &nbsp;<br /><br />/ip ipsec proposal &nbsp;<br />add name=PROJECT pfs-group=none &nbsp;<br /><br />/ip pool &nbsp;<br />add name=default-dhcp ranges=192.168.88.10-192.168.88.254 &nbsp;<br /><br />/ip dhcp-server &nbsp;<br />add address-pool=default-dhcp disabled=no interface=bridge name=defconf &nbsp;<br /><br />/interface bridge port &nbsp;<br />add bridge=bridge comment=defconf interface=ether1 &nbsp;<br />add bridge=bridge interface=wlan1 &nbsp;<br />add bridge="PROJECT Bridge" interface=PROJECT &nbsp;<br /><br />/ip neighbor discovery-settings &nbsp;<br />set discover-interface-list=LAN &nbsp;<br /><br />/interface list member &nbsp;<br />add comment=defconf interface=bridge list=LAN &nbsp;<br />add interface=mobile4g list=WAN &nbsp;<br />add interface="PROJECT Bridge" list=LAN &nbsp;<br /><br />/ip address &nbsp;<br />add address=192.168.88.1/24 comment=defconf interface=bridge network=192.168.88.0 &nbsp;<br />add address=10.0.1.1/27 comment="network /27 assigned to partner/location" interface="PROJECT Bridge" network=10.0.1.0 &nbsp;<br /><br />/ip dhcp-server network &nbsp;<br />add address=10.0.1.0/27 gateway=10.0.1.1 &nbsp;<br />add address=192.168.88.0/24 comment=defconf gateway=192.168.88.1 &nbsp;<br /><br />/ip dns &nbsp;<br />set allow-remote-requests=yes &nbsp;<br /><br />/ip dns static &nbsp;<br />add address=192.168.88.1 comment=defconf name=router.lan &nbsp;<br /><br />/ip firewall filter &nbsp;<br />add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked &nbsp;<br />add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid &nbsp;<br />add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp &nbsp;<br />add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1 &nbsp;<br />add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN &nbsp;<br />add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec &nbsp;<br />add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec &nbsp;<br />add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related &nbsp;<br />add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked &nbsp;<br />add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid &nbsp;<br />add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN &nbsp;<br /><br />/ip firewall nat &nbsp;<br />add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN &nbsp;<br /><br />/ip ipsec identity &nbsp;<br />add auth-method=eap certificate="" eap-methods=eap-peap generate-policy=port-strict mode-config=PROJECT peer=PROJECT policy-template-group=PROJECT username=partner00001 &nbsp;<br /><br />/ip ipsec policy &nbsp;<br />add dst-address=0.0.0.0/0 group=PROJECT proposal=PROJECT src-address=0.0.0.0/0 template=yes &nbsp;<br /><br />/radius &nbsp;<br />add address=10.0.0.3 service=wireless,dhcp &nbsp;<br /><br />/tool mac-server &nbsp;<br />set allowed-interface-list=LAN &nbsp;<br /><br />/tool mac-server mac-winbox &nbsp;<br />set allowed-interface-list=LAN <br />
			<i>19.06.2021 12:37:00, Borkoje.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402946</link>
			<guid>http://mikrotik.moscow/forum/forum57/86082-marshrutizatsiya-trafika-s-besprovodnykh-klientov-cherez-ipsec/message402946</guid>
			<pubDate>Sat, 19 Jun 2021 12:37:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
	</channel>
</rss>
