Vous êtes sur la page 1sur 5

How to add IPsec

Adding a NAT Rule

Add
o

o
o

General >Chain>secant
Src.Address>10.42.42.0/24
Dst.Address>MGT IP/X
Action>accept
General >Chain>secant
Src.Address> MGT IP/X
Dst.Address>10.42.42.0/24
Action>accept

IP>IPsec
o Copy and paste this script with changing the secret and sa-src-address with
publicIp
/ip ipsec proposal
set [ find default=yes ] enc-algorithms=aes-256-c
add enc-algorithms=aes-256-cbc lifetime=8h name=dhi_cloud
/ip ipsec peer
add address=185.27.249.2/32 comment="|| DHI Cloud ||" dpd-maximum-failures=20
enc-algorithm=aes-256 exchange-mode=aggressive local-address=0.0.0.0 nattraversal=no secret="XXXXXXXXXXXXXXXXXXXXXXXXX"
/ip ipsec policy
set 0 disabled=yes
add comment="|| DHI Coud : Aradail ||" dst-address=10.42.42.18/32 level=unique
proposal=dhi_cloud sa-dst-address=185.27.249.2 sa-src-address=XXXXXXXXXXX srcaddress=10.100.24.0/22 tunnel=yes
add comment="|| DHI Coud : NTP Server ||" dst-address=10.42.42.52/32
level=unique proposal=dhi_cloud sa-dst-address=185.27.249.2 sa-srcaddress=XXXXXXXXXXXXXXXXX src-address=10.100.24.0/22 tunnel=yes
add comment="|| DHI Coud : Clear Pass ||" dst-address=10.42.42.17/32 level=unique
proposal=dhi_cloud sa-dst-address=185.27.249.2 sa-srcaddress=XXXXXXXXXXXXXXXXX src-address=10.100.24.0/22 tunnel=yes
add comment="|| DHI Coud : Syslog Server ||" dst-address=10.42.42.22/32
level=unique proposal=dhi_cloud sa-dst-address=185.27.249.2 sa-srcaddress=XXXXXXXXXXXXXXXXX src-address=10.100.24.0/22 tunnel=yes
add comment="|| DHI Coud : Mapper ||" dst-address=10.42.42.11/32 level=unique
proposal=dhi_cloud sa-dst-address=185.27.249.2 sa-srcaddress=XXXXXXXXXXXXXXXXX src-address=10.100.24.0/22 tunnel=yes
add comment="|| DHI Coud : RANCID ||" dst-address=10.42.42.20/32 level=unique
proposal=dhi_cloud sa-dst-address=185.27.249.2 sa-srcaddress=XXXXXXXXXXXXXXXXX src-address=10.100.24.0/22 tunnel=yes

Firewall
o Up corner on the left
Wizard
VPN wizard
o Site-to-site-VPN

Make sure you ping is running between your RB-01 with Ser MGT
10.42.42.18
10.42.42.17
10.42.42.52
10.42.42.22
10.42.42.11
10.42.42.20

Vous aimerez peut-être aussi