<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title>Mikrotik.moscow [тема: Проблема маршрутизации через VPN &quot;site to site&quot;.]</title>
		<link>http://mikrotik.moscow</link>
		<description>Новое в теме Проблема маршрутизации через VPN &quot;site to site&quot;. форума RouterOS на сайте Mikrotik.moscow [mikrotik.moscow]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Fri, 31 Jul 2026 17:27:58 -0400</pubDate>
		<item>
			<title>Проблема маршрутизации через VPN &quot;site to site&quot;.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422087">Проблема маршрутизации через VPN &quot;site to site&quot;.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я не вижу маршрут 0.0.0.0/0 через 172.10.0.2 или 172.10.0.1 — удалённый адрес? <br />
			<i>31.05.2024 04:42:00, JohnTRIVOLTA.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422087</link>
			<guid>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422087</guid>
			<pubDate>Fri, 31 May 2024 04:42:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Проблема маршрутизации через VPN &quot;site to site&quot;.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422086">Проблема маршрутизации через VPN &quot;site to site&quot;.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Порядок правил файервола имеет значение, а ты показал только одно из них. Значит, то, что ты опубликовал — это первое правило, а за ним (ниже) идёт оригинальное правило action=masquerade без дополнительных условий (как ты и говорил, что вставил). Первое (вставленное) правило ничего не делает, поэтому второе (оригинальное) правило работает так же, как и раньше. Всё, что идёт с приватного адреса в интернет через WAN, должно быть src-nated (masquerade — это src-nat с дополнительной обработкой для динамически меняющихся WAN-адресов). <br />
			<i>30.05.2024 19:30:00, sindy.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422086</link>
			<guid>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422086</guid>
			<pubDate>Thu, 30 May 2024 19:30:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Проблема маршрутизации через VPN &quot;site to site&quot;.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422085">Проблема маршрутизации через VPN &quot;site to site&quot;.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Мне удалось, очевидно, в зале B никакого маскарада не было. Большое спасибо за ценный совет. <br />
			<i>30.05.2024 19:29:00, abbio90.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422085</link>
			<guid>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422085</guid>
			<pubDate>Thu, 30 May 2024 19:29:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Проблема маршрутизации через VPN &quot;site to site&quot;.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422084">Проблема маршрутизации через VPN &quot;site to site&quot;.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Если я добавляю это правило, интернет не работает:<br />/ip firewall nat add src-address=10.246.159.0/24 ipsec-policy=out,none out-interface=pppoe1 action=masquerade<br />Нужно ли для локальной сети 10.246.159.0/24 в офисе B делать masquerade? <br />
			<i>30.05.2024 19:23:00, abbio90.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422084</link>
			<guid>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422084</guid>
			<pubDate>Thu, 30 May 2024 19:23:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Проблема маршрутизации через VPN &quot;site to site&quot;.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422083">Проблема маршрутизации через VPN &quot;site to site&quot;.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			IPsec ищет свою добычу на предпоследнем этапе обработки пакета, то есть прямо перед тем, как пакет будет отправлен через выбранный интерфейс, уже после того, как src-nat выполнил свою работу. Так что, если вы не исключили трафик из сети 10.246.159.0/24 → интернет из-под действия правила action=srcnat или action=masquerade, например, добавив к этому правилу условие совпадения ipsec-policy=out,none, то пакеты будут пронатированы на WAN-адрес и, соответственно, станут невидимыми для селектора трафика политики. <br />
			<i>30.05.2024 19:02:00, sindy.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422083</link>
			<guid>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422083</guid>
			<pubDate>Thu, 30 May 2024 19:02:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Проблема маршрутизации через VPN &quot;site to site&quot;.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422082">Проблема маршрутизации через VPN &quot;site to site&quot;.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я написал это неверно, но на самом деле всё настроено так, как я исправил в коде. Тем не менее, я всё ещё выхожу в интернет через шлюз местоположения A вместо B по IPsec. <br />
			<i>30.05.2024 18:56:00, abbio90.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422082</link>
			<guid>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422082</guid>
			<pubDate>Thu, 30 May 2024 18:56:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Проблема маршрутизации через VPN &quot;site to site&quot;.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422081">Проблема маршрутизации через VPN &quot;site to site&quot;.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я бы сказал, что ты забыл поставить tunnel в положение yes в политиках с действием action=encrypt. После исправления снова сделай экспорт, чтобы проверить, не вызвало ли это упущение каких-то других изменений, и при необходимости исправь их вручную. <br />
			<i>30.05.2024 18:53:00, sindy.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422081</link>
			<guid>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422081</guid>
			<pubDate>Thu, 30 May 2024 18:53:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Проблема маршрутизации через VPN &quot;site to site&quot;.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422080">Проблема маршрутизации через VPN &quot;site to site&quot;.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			@Sindy, я пытаюсь это смоделировать. С сайта A хочу выйти через IPsec сайта 2. То есть моя локальная сеть сайта A (10.246.159.0/24) использует IPsec как шлюз. На сайте A следующая конфигурация: &nbsp;<br />/ip ipsec policy &nbsp;<br />add action=none dst-address=10.246.159.0/24 src-address=10.246.159.0/24 tunnel=no &nbsp;<br /><br />add action=encrypt dst-address=0.0.0.0/0 src-address=10.246.159.0/24 peer=ikev2-mik proposal=proposal-ikev2-mik tunnel=yes &nbsp;<br /><br />На сайте B такая конфигурация: &nbsp;<br />/ip ipsec policy &nbsp;<br />add action=encrypt dst-address=10.246.159.0/24 src-address=0.0.0.0/0 peer=ikev2-mik proposal=proposal-ikev2-mik tunnel=yes &nbsp;<br /><br />Фаза вторая поднимается на обоих, но трафик, направляемый в интернет, всегда выходит через PPPoE-шлюз офиса A, вместо того чтобы идти через IPsec в офис B. Где я ошибаюсь? Надо ли мне ещё что-то менять в маршрутах? <br />
			<i>30.05.2024 18:30:00, abbio90.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422080</link>
			<guid>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422080</guid>
			<pubDate>Thu, 30 May 2024 18:30:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Проблема маршрутизации через VPN &quot;site to site&quot;.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422079">Проблема маршрутизации через VPN &quot;site to site&quot;.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Всем привет! У меня есть 2 локации: 1 хаб и 1 спок. Хочу, чтобы весь трафик шел через VPN. Site-to-site IPsec VPN настроен, всё вроде работает, но не могу пропинговать Mikrotik в локальной сети на стороне спока, хотя на стороне хаба всё нормально. Как решить эту проблему?<br /><br />/interface bridge add admin-mac=XX:XX:XX:XX:XX:XX arp=proxy-arp auto-mac=no comment=defconf name=bridge &nbsp;<br />/interface pppoe-client add add-default-route=yes disabled=no interface=ether1 name=pppoe-out1 use-peer-dns=yes user=xxx@xxx &nbsp;<br />/interface list add comment=defconf name=WAN &nbsp;<br />add comment=defconf name=LAN &nbsp;<br />/ip ipsec profile add dh-group=modp1024 dpd-maximum-failures=50 enc-algorithm=3des hash-algorithm=md5 lifetime=8h name=bld nat-traversal=no &nbsp;<br />/ip ipsec peer add address=172.10.0.1/32 local-address=172.10.0.2 name=bld profile=bld &nbsp;<br />/ip ipsec proposal add auth-algorithms=sha1,md5 enc-algorithms=aes-128-cbc,aes-128-ctr,3des name=bld &nbsp;<br />/interface bridge port add bridge=bridge comment=defconf interface=ether2 &nbsp;<br />add bridge=bridge interface=ether3 &nbsp;<br />add bridge=bridge interface=ether4 &nbsp;<br />add bridge=bridge interface=ether5 &nbsp;<br />/ip neighbor discovery-settings set discover-interface-list=LAN &nbsp;<br />/interface list member add comment=defconf interface=bridge list=LAN &nbsp;<br />add comment=defconf interface=ether1 list=WAN &nbsp;<br />add interface=pppoe-out1 list=WAN &nbsp;<br />/ip address add address=192.168.14.3/26 comment=defconf interface=bridge network=192.168.14.0 &nbsp;<br />/ip dhcp-client add comment=defconf interface=ether1 &nbsp;<br />/ip dhcp-relay add dhcp-server=192.168.0.10 disabled=no interface=bridge name=relay1 &nbsp;<br />/ip dns set allow-remote-requests=yes servers=8.8.8.8 &nbsp;<br />/ip dns static add address=192.168.14.3 comment=defconf name=router.lan &nbsp;<br />/ip firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked &nbsp;<br />add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid &nbsp;<br />add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp &nbsp;<br />add action=accept chain=input src-address=192.168.14.0/26 &nbsp;<br />add action=accept chain=input src-address=192.168.0.0/22 &nbsp;<br />add action=accept chain=input src-address=172.10.0.1 &nbsp;<br />add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1 &nbsp;<br />add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec &nbsp;<br />add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec &nbsp;<br />add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related hw-offload=yes &nbsp;<br />add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked &nbsp;<br />add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN &nbsp;<br />add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid &nbsp;<br />add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN &nbsp;<br />/ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN &nbsp;<br />/ip ipsec identity add my-id=address:172.10.0.2 peer=bld &nbsp;<br />/ip ipsec policy set 0 disabled=yes &nbsp;<br />add dst-address=0.0.0.0/0 peer=bld proposal=bld src-address=192.168.14.0/26 tunnel=yes &nbsp;<br />/system routerboard settings set auto-upgrade=yes &nbsp;<br />/tool mac-server set allowed-interface-list=LAN &nbsp;<br />/tool mac-server mac-winbox set allowed-interface-list=LAN <br />
			<i>08.05.2024 17:01:00, bap.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422079</link>
			<guid>http://mikrotik.moscow/forum/forum57/87963-problema-marshrutizatsii-cherez-vpn-_site-to-site_./message422079</guid>
			<pubDate>Wed, 08 May 2024 17:01:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
	</channel>
</rss>
