Микрот hap ac2, os версия 6.47.4. Поднят l2tp+ipsec сервер, и к нему по впн коннектится второй такой же микротик с такой же версией ОС.
1) Почему я не вижу в nignbors мак адреса микротиков? Что с одного не вижу, что с другого не вижу. Сам микротик виден, видно все кроме мака, соответственно и подключиться невозможно. Собстевнно из-за этого же не работает и Romon. В мак сервер все включено, в negnbors тоже. Куда копать?

даже вот это добавил
add action=accept chain=input comment="Winbox MAC" dst-port=20561 \
in-interface-list=!Internet protocol=udp
add action=accept chain=input dst-port=5678 protocol=udp
2)
в фаерволе для ipsec созданы несколько правил, но почему-то через них ничего не ходит..
add action=accept chain=input comment=IPSec protocol=ipsec-esp
add action=accept chain=forward comment=Ipsec ipsec-policy=in,ipsec
add action=accept chain=forward ipsec-policy=out,ipsec
нужны ли они?
Полный фаервол прилагаю:
Код: Выделить всё
/ip firewall raw
add action=drop chain=prerouting comment=\
"Protected - WinBox, ssh, telnet. Drop in RAW" in-interface-list=Internet \
src-address-list=BlackListProtected
/ip firewall filter
add action=fasttrack-connection chain=forward connection-mark=!ipsec \
connection-state=established,related
add action=drop chain=forward comment="Drop invalid Forward" \
connection-state=invalid
add action=drop chain=forward comment="drop all packets for lan, no nat" \
connection-nat-state=!dstnat connection-state=new in-interface-list=\
Internet
add action=accept chain=forward comment=Ipsec ipsec-policy=in,ipsec
add action=accept chain=forward ipsec-policy=out,ipsec
add action=accept chain=forward connection-state=established,related
add action=drop chain=input dst-port=53 in-interface-list=Internet log=yes \
log-prefix=dnsdrop protocol=udp
add action=drop chain=input comment="Drop invalid input" \
connection-nat-state="" connection-state=invalid connection-type=""
add action=accept chain=input dst-port=5678 protocol=udp
add action=accept chain=input comment=dhcp dst-port=67 in-interface-list=\
!Internet protocol=udp
add action=accept chain=input dst-port=68 in-interface-list=!Internet \
protocol=udp
add action=accept chain=input comment="allow sstp" dst-port=443 protocol=tcp
add action=accept chain=input comment="Winbox MAC" dst-port=20561 \
in-interface-list=!Internet protocol=udp
add action=accept chain=input comment=IPSec protocol=ipsec-esp
add action=jump chain=input comment="Protected - WinBox, ssh, telnet chain" \
connection-state=new dst-port=8291,22,23 in-interface-list=Internet \
jump-target=Protected log-prefix=proverka protocol=tcp
add action=accept chain=input comment="Accept Input established related" \
connection-state=established,related protocol=!ipsec-esp
add action=add-src-to-address-list address-list="port scanners" \
address-list-timeout=2d chain=input comment=\
"Port scanners to list ALL/ALL scan" in-interface-list=Internet \
protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg
add action=add-src-to-address-list address-list=BlackListProtected \
address-list-timeout=2d chain=input in-interface-list=Internet protocol=\
tcp psd=21,3s,3,1
add action=add-src-to-address-list address-list=BlackListProtected \
address-list-timeout=2d chain=Protected comment=\
"Protected - WinBox, ssh, telnet. Drop in RAW" connection-state=new \
src-address-list="ListProtected Stage 2"
add action=add-src-to-address-list address-list="ListProtected Stage 2" \
address-list-timeout=2m chain=Protected connection-state=new \
src-address-list="ListProtected Stage 1"
add action=add-src-to-address-list address-list="ListProtected Stage 1" \
address-list-timeout=1m chain=Protected connection-state=new
add action=accept chain=Protected dst-port=8291,22,23 in-interface-list=\
Internet protocol=tcp
add action=accept chain=input comment="allow l2tp, IKE, IPsecNAT" dst-port=\
1701,500,4500 in-interface-list=Internet protocol=udp
add action=accept chain=input comment="Allow IGMP" in-interface=bridge-1 \
protocol=igmp
add action=accept chain=input comment="accept ICMP" protocol=icmp
add action=drop chain=input comment="Drop All Other" in-interface-list=\
Internet log-prefix="drop other"