Хабр Курсы для всех
РЕКЛАМА
Практикум, Хекслет, SkyPro, авторские курсы — собрали всех и попросили скидки. Осталось выбрать!
Через неделю у микротика перестает ходить трафик по gre. Помогает только ребут микротика. Стабильная ветка.
config vpn ipsec phase1-interface
edit "Dynamic-phase1"
set type dynamicedit "phase2-1st"
set phase1name "Dynamic-phase1"
set protocol 47
set src-addr-type ip
set dst-addr-type ip
set src-start-ip <GRE source IP>
set dst-start-ip <GRE dest IP-1>
next
edit "phase2-2nd"
set phase1name "Dynamic-phase1"
set protocol 47
set src-addr-type ip
set dst-addr-type ip
set src-start-ip <GRE source IP>
set dst-start-ip <GRE dest IP-2>
next/interface bridge
add name=Lo-GRE2-src
/ip address
add address=172.31.0.229 interface=Lo-GRE2-src network=172.31.0.229
/ip ipsec peer
add address=X.X.X.X/32 local-address=172.31.0.229 name=gre2-fgt profile=fgt-aes256-sha256
/ip ipsec policy
add dst-address=172.31.0.239/32 peer=gre2-fgt proposal=fgt-aes256-sha256-ph2 protocol=gre sa-dst-address=\
X.X.X.X sa-src-address=172.31.0.229 src-address=172.31.0.229/32 tunnel=yes
/interface gre
add !keepalive local-address=172.31.0.229 name=GRE2-to-FGT remote-address=172.31.0.239
/ip route
add comment=WAN2-Table distance=1 gateway=z.z.z.z routing-mark=WAN2
/ip route rule
add action=lookup-only-in-table src-address=172.31.0.229/32 table=WAN2
/ip firewall mangle
add action=mark-connection chain=prerouting comment=WAN2 connection-mark=no-mark in-interface=ether5 new-connection-mark=con-WAN2 passthrough=yes
add action=mark-routing chain=prerouting comment=WAN2 connection-mark=con-WAN2 in-interface-list=!WAN new-routing-mark=WAN2 passthrough=yes
add action=mark-routing chain=output comment=con-WAN2 connection-mark=con-WAN2 new-routing-mark=WAN2 passthrough=yes
Настройка IPsec GRE туннель между FortiOS 6.4.5 и RouterOS 6.48.1