<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title>Mikrotik.moscow [тема: Проблема с IPSec-соединением [Mikrotik&lt;-&gt;FortGate]]</title>
		<link>http://mikrotik.moscow</link>
		<description>Новое в теме Проблема с IPSec-соединением [Mikrotik&lt;-&gt;FortGate] форума RouterOS на сайте Mikrotik.moscow [mikrotik.moscow]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Thu, 13 Aug 2026 23:30:58 -0400</pubDate>
		<item>
			<title>Проблема с IPSec-соединением [Mikrotik&lt;-&gt;FortGate]</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233642">Проблема с IPSec-соединением [Mikrotik&lt;-&gt;FortGate]</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Извини, я не совсем понимаю. Твоя политика IPsec будет определять трафик для шифрования (адреса источника и назначения, в твоей первоначальной политике — один хост на MikroTik и небольшая подсеть на FortiGate). Когда ты говоришь, что не можешь получить доступ из WAN, я думаю, что это сделано намеренно. Можешь привести пример того, что ты пытаешься получить доступ и откуда? <br />
			<i>10.05.2015 01:50:00, rjickity.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233642</link>
			<guid>http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233642</guid>
			<pubDate>Sun, 10 May 2015 01:50:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Проблема с IPSec-соединением [Mikrotik&lt;-&gt;FortGate]</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233641">Проблема с IPSec-соединением [Mikrotik&lt;-&gt;FortGate]</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Привет, rjickity! Спасибо за отзыв. Проблема с VPN-соединением с моей локальной сети (LAN) у меня устранена, но с глобальной сетью (WAN) я все еще мучаюсь. После того, как прочитал твой комментарий, могу подключиться к Mikrotik с LAN, но WAN не дает подключиться, и даже в логе нет никаких ошибок. Не мог бы ты подсказать, что делать? Спасибо! #mikrotik #vpn #troubleshooting <br />
			<i>17.04.2015 06:25:00, bluemoon.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233641</link>
			<guid>http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233641</guid>
			<pubDate>Fri, 17 Apr 2015 06:25:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Проблема с IPSec-соединением [Mikrotik&lt;-&gt;FortGate]</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233640">Проблема с IPSec-соединением [Mikrotik&lt;-&gt;FortGate]</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Перепроверь свои секреты. Если секрет сложный, попробуй простой пароль вроде 'abc123' и посмотри, что произойдет. Если все еще возникает проблема, отлади оба и посмотри, что они видят. Отправлено с моего GT-I9100 через Tapatalk 2 <br />
			<i>28.07.2012 10:54:00, rjickity.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233640</link>
			<guid>http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233640</guid>
			<pubDate>Sat, 28 Jul 2012 10:54:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Проблема с IPSec-соединением [Mikrotik&lt;-&gt;FortGate]</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233639">Проблема с IPSec-соединением [Mikrotik&lt;-&gt;FortGate]</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Попробуйте убрать nat-traversal из настроек пира. <br />
			<i>27.07.2012 22:07:00, Poki.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233639</link>
			<guid>http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233639</guid>
			<pubDate>Fri, 27 Jul 2012 22:07:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Проблема с IPSec-соединением [Mikrotik&lt;-&gt;FortGate]</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233638">Проблема с IPSec-соединением [Mikrotik&lt;-&gt;FortGate]</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Привет всем! У меня возникла проблема с настройкой IPSec VPN между RB1100 (v4.12) и FortGate 331B (v4.0, build0342, 120227). Я уже искал информацию на форумах поддержки, но пока безуспешно. Прилагаю логи и конфигурации обоих устройств к этому посту. Все "падает" с ошибкой "invalid length of payload / malformed or expired". Я совершенно в тупике, не понимаю, что не так.<br /><br />jul/18 16:48:39 ipsec respond new phase 1 negotiation: *MIKROTIK-IP*[500]&lt;=&gt;*FORTGATE-IP*[500]<br />jul/18 16:48:39 ipsec begin Identity Protection mode.<br />jul/18 16:48:39 ipsec received Vendor ID: RFC 3947<br />jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-03<br />jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-02<br />jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-02<br />jul/18 16:48:39 ipsec<br />jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-01<br />jul/18 16:48:39 ipsec received Vendor ID: draft-ietf-ipsec-nat-t-ike-00<br />jul/18 16:48:39 ipsec received Vendor ID: DPD<br />jul/18 16:48:39 ipsec Selected NAT-T version: RFC 3947<br />jul/18 16:48:39 ipsec Hashing *MIKROTIK-IP*[500] with algo #1<br />jul/18 16:48:39 ipsec NAT-D payload #0 verified<br />jul/18 16:48:39 ipsec Hashing *FORTGATE-IP*[500] with algo #1<br />jul/18 16:48:39 ipsec NAT-D payload #1 verified<br />jul/18 16:48:39 ipsec NAT not detected<br />jul/18 16:48:39 ipsec Hashing *REMOTE-IP*[500] with algo #1<br />jul/18 16:48:39 ipsec Hashing *FORTGATE-IP*[500] with algo #1<br />jul/18 16:48:39 ipsec Adding remote and local NAT-D payloads.<br />jul/18 16:48:39 ipsec phase1 negotiation failed due to time up. f3910b0466248ffb:db0f570033e05fba<br />jul/18 16:48:39 ipsec invalid length of payload<br /><br />Буду очень признателен за любую помощь! Спасибо большое!<br /><br />fortgate_log.txt (3.8 KB)<br />fortgate_config.txt (3.93 KB)<br />mikrotik_config.txt (941 Bytes) <br />
			<i>27.07.2012 15:40:00, Geoffb.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233638</link>
			<guid>http://mikrotik.moscow/forum/forum57/61162-problema-s-ipsec_soedineniem-_mikrotik_fortgate/message233638</guid>
			<pubDate>Fri, 27 Jul 2012 15:40:00 -0400</pubDate>
			<category>RouterOS</category>
		</item>
	</channel>
</rss>
