S
Size: a a a
S
S
S
D
S
RK
RK
S
RK
S
RK
RK
RK
S
RK
RK
RK
D
/ip ipsec mode-config
add address-pool=pool1-ppp address-prefix-length=32 name=ikev2-conf split-include=172.16.0.0/16 static-dns=172.16.0.1 system-dns=no
/ip ipsec policy group
add name=ikev2-policies
/ip ipsec profile
add dh-group=modp2048,modp1536,modp1024 enc-algorithm=aes-256,aes-192,aes-128 hash-algorithm=sha256 name=ikev2
/ip ipsec peer
add exchange-mode=ike2 name=ikev2-server passive=yes profile=ikev2 send-initial-contact=no
/ip ipsec proposal
add auth-algorithms=sha256,sha1 lifetime=4h name=ikev2 pfs-group=none
/ip ipsec identity
add auth-method=eap-radius certificate=fullchain_le_202102,fullchain_le_ca_1 generate-policy=port-strict mode-config=ikev2-conf peer=ikev2-server policy-template-group=ikev2-policies
/ip ipsec policy
add dst-address=0.0.0.0/0 group=ikev2-policies proposal=ikev2 src-address=0.0.0.0/0 template=yes
S
S
/ip ipsec mode-config
add address-pool=pool1-ppp address-prefix-length=32 name=ikev2-conf split-include=172.16.0.0/16 static-dns=172.16.0.1 system-dns=no
/ip ipsec policy group
add name=ikev2-policies
/ip ipsec profile
add dh-group=modp2048,modp1536,modp1024 enc-algorithm=aes-256,aes-192,aes-128 hash-algorithm=sha256 name=ikev2
/ip ipsec peer
add exchange-mode=ike2 name=ikev2-server passive=yes profile=ikev2 send-initial-contact=no
/ip ipsec proposal
add auth-algorithms=sha256,sha1 lifetime=4h name=ikev2 pfs-group=none
/ip ipsec identity
add auth-method=eap-radius certificate=fullchain_le_202102,fullchain_le_ca_1 generate-policy=port-strict mode-config=ikev2-conf peer=ikev2-server policy-template-group=ikev2-policies
/ip ipsec policy
add dst-address=0.0.0.0/0 group=ikev2-policies proposal=ikev2 src-address=0.0.0.0/0 template=yes