Solved

GRE Trunnel with IPsec Encryption Issue

Posted on 2016-10-19
3
102 Views
Last Modified: 2016-10-20
Currently have a MikroTik switch hosting GRE tunnels with IPSec encryption (Site A).  We have multiple other sites with other MikroTik's directly connected to the internet setup that are working great.

We have this one site (Site B) where the MikroTik switch is behind a Cisco ASA 5505.  However the tunnel is not functioning properly, one side of the GRE tunnel can see the other but not the other way around.

Here's the Cisco ASA Configuration that are relevant, if you need something else let me know.

name 192.168.10.90 MIKROTIK

object-group service MIKROTIK
 service-object gre
 service-object tcp eq 50
 service-object udp eq isakmp
object-group network MIKROTIK_SERVER
 network-object 68.70.xxx.xxx 255.255.255.255

access-list outside_access_in extended permit object-group MIKROTIK object-group MIKROTIK_SERVER host 24.39.xxx.xxx

static (inside,outside) 24.39.xxx.xxx MIKROTIK netmask 255.255.255.255

access-group outside_access_in in interface outside
0
Comment
Question by:Railroad
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 29

Expert Comment

by:masnrock
ID: 41851812
Is the ASA really necessary if you are talking about the other sites not needing one?

I don't want to assume, but I am guessing that site B is seeing the other side fine, but nothing is able to see site B?
0
 
LVL 14

Accepted Solution

by:
SIM50 earned 500 total points
ID: 41852062
We have this one site (Site B) where the MikroTik switch is behind a Cisco ASA 5505.  However the tunnel is not functioning properly, one side of the GRE tunnel can see the other but not the other way around.

Not sure what you mean. Does it mean the tunnel doesn't establish or you can't send data?

object-group service MIKROTIK
 service-object gre
service-object tcp eq 50
 service-object udp eq isakmp

It should be "service-object esp".
0
 

Author Comment

by:Railroad
ID: 41852340
The ASA is required for this site.

Site A can see Site B as a neighbor, but the OSPF it doesn't form a full adjacency and therefor never exchanges routing tables.  Site B never sees Site A as a neighbor.

Adding "service-object esp" to the object-group service corrected the issue.

Thanks!
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question