Site to Site VPN with Private and Public - Mikrotik

0

I've set up the tunnels exactly as per the instructions (although their instructions for the Mikrotik are out of date).

Both tunnels are up. I can ping the other side of each tunnel's interior 169 IP Address.

I spin up an EC2 instance in a private network on a /24. Lets use 10.55.0.2/24. I create a security group allowing SSH and ICMP from 0.0.0.0/0. It does not have a public ip.

I make sure my side (Mikrotik) has the route to that 10.55.0.0/24 via the other end tunnel ip address. So from my Mikrotik router I should be able to ping from my exterior ip address. It does not ping.

I don't have NAT on that IP address at the Mikrotik so no firewall rules necessary. However just to rule that out I set up a rule to accept input from ipsec/ike from the other side.

Static routes on the Site to Site on the AWS side for the Virtual Private Gateway are all the subnets on the Mikrotik side that would be contacting it.

It just seems that from the interior AWS 169.x.x.x ip address to the EC2 instance can't communicate or will not route back through the tunnel.

Desperate for help on this one. I know I've followed all of the instructions to the letter and have tried multiple approaches without luck.

已提問 3 年前檢視次數 926 次
1 個回答
0

Figured it out on my end.

已回答 3 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南