如果更换MikroTik router, 之前IKEv2 certificates怎样处理?
1、把/system/certificates里的certificates export出来到Files folder(MikroTik里面的Files folder)
2、Drag client, server, certifcates,ca.crt 到 desktop
3、把上的files搬到新的MikroTik router,用winbox certificates,或者 terminal 都可以把certificates import到MikroTik系统。
4、到/system/certifictes里需要修改一下,就是在export过程中,前后都多了些text都要删掉。
5、从新set IPSec settings- /ip ipsec profile
- add name=ike2
- /ip ipsec proposal
- add name=ike2 pfs-group=none
- /ip pool
- add name=ike2-pool ranges=192.168.77.2-192.168.77.254
- /ip ipsec mode-config
- add address-pool=ike2-pool address-prefix-length=32 name=ike2-conf
- /ip ipsec policy group
- add name=ike2-policies
- /ip ipsec policy
- add dst-address=192.168.77.0/24 group=ike2-policies proposal=ike2 src-address=0.0.0.0/0 template=yes
- /ip ipsec peer
- add exchange-mode=ike2 name=ike2 passive=yes profile=ike2
- /ip ipsec identity
- add auth-method=digital-signature certificate=jb.server generate-policy=port-strict mode-config=ike2-conf peer=ike2 policy-template-group=ike2-policies
複製代碼 6、在/IP/IPSec/Profile里,aes256 打勾(主要系统安装了strongSwan which requires aes256. |