如何在MikroTik/RouterOS上配置IPSec Xauth RSA客户端?
Absolutely feasible! Your RouterBOARD 750G r3 running firmware 6.41.1 fully supports IPSec Xauth RSA client mode — perfect, since you already have this setup working on Android. The authentication method you'll use here is Xauth with RSA certificates (hybrid mode); this combines certificate-based IKE authentication for device validation with Xauth username/password checks for an extra layer of user-level security, which aligns exactly with your existing setup.
Below is a step-by-step configuration guide tailored to your device and firmware version:
Step 1: Import Required Certificates
First, you need to import your CA certificate, client certificate, and client private key into the MikroTik. Use the CLI commands below (replace the file names and passphrases with your actual credentials):
# Import CA certificate (leave passphrase empty if unencrypted) /certificate import file-name=ca.crt passphrase="" # Import client certificate /certificate import file-name=client.crt passphrase="" # Import client private key (use your actual passphrase if the key is encrypted) /certificate import file-name=client.key passphrase="your-key-passphrase"
Verify the imports worked correctly with:
/certificate print
Ensure the CA certificate is marked as trusted and your client certificate shows a matching private key.
Step 2: Configure IKE Peer (Phase 1)
Set up the IKE phase 1 parameters to match your VPN server's configuration. Adjust the address, certificate, and remote-certificate values to match your server details:
/ip ipsec peer add address=your-vpn-server-ip/32 port=500 auth-method=rsa-signature certificate=your-client-cert-name remote-certificate=your-server-cert-name exchange-mode=aggressive send-initial-contact=yes proposal-check=obey nat-traversal=yes
Note: If your server uses main exchange mode instead of aggressive, swap that value — Android typically works with either, so match whatever your server is configured to use.
Step 3: Tune IKE Phase 1 Proposals
Make sure your phase 1 encryption/hash algorithms match the server's supported list. Here's a common compatible setup:
/ip ipsec proposal set [find default=yes] encryption-algorithms=aes-256-cbc,aes-128-cbc hash-algorithms=sha256,sha1 dh-group=modp2048,modp1024
Step 4: Enable Xauth and Set User Credentials
Since you're using Xauth alongside RSA, enable it on the peer and input your username/password:
/ip ipsec peer set [find address=your-vpn-server-ip/32] xauth-enabled=yes xauth-mode=client xauth-username="your-xauth-username" xauth-password="your-xauth-password"
Step 5: Configure IPSec Policy (Phase 2)
Define which traffic will be routed through the VPN. Replace your-local-subnet and remote-vpn-subnet with your actual network ranges (use 0.0.0.0/0 for both if you want all traffic to go through the VPN):
/ip ipsec policy add src-address=your-local-subnet/24 dst-address=remote-vpn-subnet/24 protocol=all template=no proposal=default peer=your-vpn-server-ip
Step 6: Adjust IPSec Phase 2 Proposals
Ensure phase 2 algorithms match the server's settings. A standard compatible configuration looks like this:
/ip ipsec proposal set [find name=default] encryption-algorithms=aes-256-cbc,aes-128-cbc,3des hash-algorithms=sha256,sha1 pfs-group=modp2048,modp1024
Step 7: Verify the Connection
Check if the tunnel is active and working with these commands:
# View active IPSec peers /ip ipsec active-peers print # Check policy traffic stats /ip ipsec policy print stats
You should see an active peer entry, and the traffic counters will increment if data is flowing through the tunnel.
内容的提问来源于stack exchange,提问作者Anton Krouglov

