Re: [Mikrotik] IPsec tunnel drops and requires flush

2016-05-26 Thread Alexander Neilson
Hi Jerry. I hadn't used IPSEC on 5.26 so I can't advise about any bugs back then that may now be fixed. Another thing is to never assume the other end doesn't also have bugs. The only time require vs unique should come into play would be when there were more than one subnet at one end of

Re: [Mikrotik] IPsec tunnel drops and requires flush

2016-05-26 Thread Roy, Jerry
Hi Alexander, Thanks for the quick response. We are running 5.26 on all 750's and the firmware is 3.19. There is an initial tunnel that has been up on these boxes to a Juniper that never goes down. The tunnel to the Cisco was added months later and of course to different subnet. So I see the

Re: [Mikrotik] IPsec tunnel drops and requires flush

2016-05-26 Thread Alexander Neilson
Hi Jerry I don't have specific experience with Cisco at the far end. However are there more that a single subnet at either end of the link? I have found that some other providers default to "unique" for SA's while the Mikrotik defaults to "require". This can mean that it fails to maintain the

[Mikrotik] IPsec tunnel drops and requires flush

2016-05-26 Thread Roy, Jerry
Hey all, Need your expertise. We have MikroTik 750's building IPsec tunnels using aes128 to a Cisco router. Our script initially brings up the tunnel via a ping (runs 3 pings every minute) and tunnel will run until the lifetime expires (I believe) but after it expires, it never rebuilds. We