{"id":840,"date":"2016-03-18T12:31:53","date_gmt":"2016-03-18T10:31:53","guid":{"rendered":"http:\/\/dety.net.ua\/?p=840"},"modified":"2016-03-18T12:31:53","modified_gmt":"2016-03-18T10:31:53","slug":"ipsec-between-pfsence-and-mikrotik-nat-like-remote-host-is-in-the-lan","status":"publish","type":"post","link":"https:\/\/dety.net.ua\/?p=840","title":{"rendered":"IPSEC between PFSence and Mikrotik + NAT like remote host is in the LAN"},"content":{"rendered":"<p>The PFSence side:<\/p>\n<p>Allow all traffic from the remote host.<\/p>\n<p>Create the IPSEC connection.<\/p>\n<p><a href=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf3.png\" rel=\"attachment wp-att-844\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-844\" src=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf3-209x300.png\" alt=\"pf3\" width=\"209\" height=\"300\" srcset=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf3-209x300.png 209w, https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf3.png 569w\" sizes=\"auto, (max-width: 209px) 100vw, 209px\" \/><\/a><a href=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf4.png\" rel=\"attachment wp-att-845\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-845\" src=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf4-196x300.png\" alt=\"pf4\" width=\"196\" height=\"300\" srcset=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf4-196x300.png 196w, https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf4.png 558w\" sizes=\"auto, (max-width: 196px) 100vw, 196px\" \/><\/a><\/p>\n<p>Allow all traffic on the IPSEC interface.<\/p>\n<p><a href=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf5.png\" rel=\"attachment wp-att-841\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-841\" src=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf5-300x67.png\" alt=\"pf5\" width=\"300\" height=\"67\" srcset=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf5-300x67.png 300w, https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf5.png 652w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Create a Virtual IP for internal host (it is remote host now).<\/p>\n<p><a href=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf2.png\" rel=\"attachment wp-att-843\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-843\" src=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf2-300x85.png\" alt=\"pf2\" width=\"300\" height=\"85\" srcset=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf2-300x85.png 300w, https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf2.png 494w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>Create the NAT rule for this host.<\/p>\n<p><a href=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf1.png\" rel=\"attachment wp-att-842\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-842\" src=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf1-300x71.png\" alt=\"pf1\" width=\"300\" height=\"71\" srcset=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf1-300x71.png 300w, https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/pf1.png 693w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>The Mikrotik side:<\/p>\n<p>Allow all traffic from the remote host.<\/p>\n<p><a href=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr1.png\" rel=\"attachment wp-att-846\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-846\" src=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr1-300x42.png\" alt=\"micr1\" width=\"300\" height=\"42\" srcset=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr1-300x42.png 300w, https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr1.png 750w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Create the IPSEC connection.<\/p>\n<p><a href=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr5.png\" rel=\"attachment wp-att-850\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-850\" src=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr5-300x262.png\" alt=\"micr5\" width=\"300\" height=\"262\" srcset=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr5-300x262.png 300w, https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr5.png 746w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><a href=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr7.png\" rel=\"attachment wp-att-852\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-852\" src=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr7-300x143.png\" alt=\"micr7\" width=\"300\" height=\"143\" srcset=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr7-300x143.png 300w, https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr7.png 718w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><a href=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr6.png\" rel=\"attachment wp-att-851\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-851\" src=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr6-300x155.png\" alt=\"micr6\" width=\"300\" height=\"155\" srcset=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr6-300x155.png 300w, https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr6.png 577w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><a href=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr4.png\" rel=\"attachment wp-att-849\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-849\" src=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr4-300x227.png\" alt=\"micr4\" width=\"300\" height=\"227\" srcset=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr4-300x227.png 300w, https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr4.png 551w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><a href=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr3.png\" rel=\"attachment wp-att-848\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-848\" src=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr3-300x231.png\" alt=\"micr3\" width=\"300\" height=\"231\" srcset=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr3-300x231.png 300w, https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr3.png 552w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Create the skip-NAT rule for the remote network.<\/p>\n<p><a href=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr2.png\" rel=\"attachment wp-att-847\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-847\" src=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr2-300x43.png\" alt=\"micr2\" width=\"300\" height=\"43\" srcset=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr2-300x43.png 300w, https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr2.png 752w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>Create and schedule a script to monitor IPSEC and flush all the proposals<\/p>\n<p><a href=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr8.png\" rel=\"attachment wp-att-853\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-853\" src=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr8-226x300.png\" alt=\"micr8\" width=\"226\" height=\"300\" srcset=\"https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr8-226x300.png 226w, https:\/\/dety.net.ua\/wp-content\/uploads\/2016\/03\/micr8.png 328w\" sizes=\"auto, (max-width: 226px) 100vw, 226px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The PFSence side: Allow all traffic from the remote host. Create the IPSEC connection. Allow all traffic on the IPSEC interface. Create a Virtual IP for internal host (it is remote host now). Create the NAT rule for this host. The Mikrotik side: Allow all traffic from the remote host. Create the IPSEC connection. Create [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":844,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7,13],"tags":[],"class_list":["post-840","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mikrotik","category-novosti"],"_links":{"self":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/840","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=840"}],"version-history":[{"count":1,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/840\/revisions"}],"predecessor-version":[{"id":854,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/840\/revisions\/854"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/media\/844"}],"wp:attachment":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}