Goal
Configure a MikroTik router as an IKEv2 VPN server for mobile and remote clients, including Windows, Android, and Apple iOS/iPadOS.
Clients authenticate using X.509 certificates and receive an address from a dedicated VPN address pool.
Why IKEv2?
IKEv2 provides a standards-based IPsec VPN that is well suited to mobile clients. It is supported natively by Windows and Apple operating systems and is widely supported by Android VPN clients.
Compared with older VPN protocols, IKEv2 provides strong cryptography, certificate-based authentication, NAT traversal, and reliable reconnection when a mobile device changes networks.
Configuration Overview
The configuration consists of four basic components:
- Certificates: Create a Certificate Authority, server certificate, and client certificates.
- Client addressing: Create an IP pool and configure DNS and routing information supplied through IKEv2 Mode Config.
- IPsec: Configure the IKEv2 profile, proposal, peer, identity, and policy template.
- Firewall and NAT: Permit IKEv2/IPsec negotiation and control what authenticated VPN clients may access.
Step 1: Certificates
IKEv2 certificate authentication requires three certificate types:
- Certificate Authority (CA)
- IKEv2 server certificate
- IKEv2 client certificate
The CA signs both the server and client certificates, establishing the chain of trust used during IKEv2 authentication.
Create the Certificate Authority
Create the CA certificate that will sign the server and client certificates.
/certificateadd name=Domain_CA common-name=Domain_CA key-usage=key-cert-sign,crl-sign
Configure the Certificate Revocation List
Specify the public address from which the Certificate Revocation List can be retrieved.
/certificateset Domain_CA ca-crl-host=8.x.x.x
Use the router's public IP address or a DNS name reachable by VPN clients.
The CRL location is published through the CA certificate. It does not need to be configured separately on the server or client certificates.
Sign the Certificate Authority
/certificatesign Domain_CA
Create the IKEv2 Server Certificate
Create a certificate identifying the VPN server and sign it with Domain_CA.
The server certificate should contain the VPN server's DNS name in both the Common Name and Subject Alternative Name.
CN: ikev2.example.comSAN: DNS:ikev2.example.com
The certificate should include the tls-server key usage. After creating it, sign it with Domain_CA and mark the CA and server certificates as trusted.
Create Client Certificates
Create an individual certificate for each VPN client or user.
For maximum client compatibility, use the same identity in the Common Name and Subject Alternative Name.
CN: stevenSAN: DNS:steven
The certificate should include the tls-client key usage.
Sign the certificate with Domain_CA, mark it as trusted, and export the certificate and private key as PKCS#12 (.p12) for installation on the client.
Using individual certificates allows a single client to be revoked without affecting every other VPN user.
Step 2: VPN Client Address Pool
Dedicate a subnet or address range to remote VPN clients.
/ip pooladd name=ikev2-pool ranges=10.168.88.100-10.168.88.110
This address space should not overlap existing LAN or remote networks.
The pool may be shared with other remote-access VPN services when appropriate, although separate pools can simplify firewall policy and troubleshooting.
Step 3: Configure IPsec
Mode Config
Mode Config supplies network configuration to connecting VPN clients.
/ip ipsec mode-configadd name=ikev2-modecfg \ address-pool=ikev2-pool \ address-prefix-length=32 \ system-dns=no \ static-dns=192.168.88.10
The client receives an address from ikev2-pool, a /32 client address, and 192.168.88.10 as its DNS server.
For a split-tunnel VPN, internal networks may also be advertised using split-include.
/ip ipsec mode-configset ikev2-modecfg split-include=192.168.88.0/24
Mode Config determines what routes the client is asked to install. Firewall policy still determines what the client is actually permitted to access.
Phase 1 Profile
The IPsec profile defines the cryptographic parameters used during IKE negotiation.
/ip ipsec profileadd name=ikev2-profile \ dh-group=modp2048 \ enc-algorithm=aes-256,aes-128 \ hash-algorithm=sha256
Phase 2 Proposal
Create a dedicated proposal for IKEv2 traffic.
/ip ipsec proposaladd name=ikev2-proposal \ auth-algorithms=sha256 \ enc-algorithms=aes-256-cbc,aes-128-cbc \ pfs-group=none
A dedicated proposal is preferable to modifying the RouterOS default because unrelated IPsec tunnels will not inherit the remote-access VPN configuration.
Policy Group and Template
Create a policy group for dynamically generated IKEv2 client policies.
/ip ipsec policy groupadd name=ikev2-policies
Create the corresponding policy template.
/ip ipsec policyadd group=ikev2-policies \ proposal=ikev2-proposal \ template=yes
RouterOS uses this template to generate IPsec policies dynamically as clients connect.
IKEv2 Peer
Create a passive IKEv2 peer that listens for incoming client connections.
/ip ipsec peeradd name=ikev2-peer \ exchange-mode=ike2 \ passive=yes \ profile=ikev2-profile \ send-initial-contact=no
Because the MikroTik is acting as the VPN server, remote clients initiate the connection.
IKEv2 Identity
Associate certificate authentication, Mode Config, and dynamic policy generation with the IKEv2 peer.
/ip ipsec identityadd peer=ikev2-peer \ auth-method=digital-signature \ certificate=IKEv2_Server \ generate-policy=port-strict \ mode-config=ikev2-modecfg \ policy-template-group=ikev2-policies
The router verifies that each connecting client presents a certificate signed by a trusted CA.
A specific remote-certificate is deliberately not configured. Specifying one would bind the identity to a particular client certificate. Leaving certificate matching generic allows multiple clients signed by the trusted CA to authenticate.
Step 4: Firewall and NAT
The firewall performs two separate functions: permitting establishment of the IKEv2/IPsec tunnel and controlling what authenticated VPN clients may access after the tunnel is established.
Allow IKEv2 and IPsec
At minimum, the router must accept IKE and NAT Traversal from the Internet.
/ip firewall filteradd chain=input action=accept protocol=udp dst-port=500,4500 \ comment="Allow IKEv2 / IPsec NAT-T"
If native ESP must be accepted separately:
/ip firewall filteradd chain=input action=accept protocol=ipsec-esp \ comment="Allow IPsec ESP"
These rules must appear before the router's general WAN input-drop rule.
Allow VPN Clients to Reach the LAN
Access from authenticated VPN clients into internal networks should be explicitly permitted according to policy.
/ip firewall filteradd chain=forward action=accept \ src-address=10.168.88.0/24 \ dst-address=192.168.88.0/24 \ ipsec-policy=in,ipsec \ comment="IKEv2 clients to LAN"
Traffic not specifically authorized should remain blocked by the normal firewall policy.
NAT Considerations
Existing masquerade rules should not accidentally NAT traffic between VPN clients and internal networks.
Where necessary, place an IPsec NAT-bypass rule before the Internet masquerade rule.
/ip firewall natadd chain=srcnat action=accept \ src-address=10.168.88.0/24 \ dst-address=192.168.88.0/24 \ comment="Do not NAT IKEv2 clients to LAN"
The exact firewall and NAT configuration depends on whether the VPN is LAN-only split tunnel, includes multiple internal networks, or provides full-tunnel Internet access through the MikroTik.
Mode Config provides addressing and routing information. The firewall determines authorization.
That's It!

0 Comments:
Post a Comment