Strongswan zu strongswan ikev2 IPv6 transport

Aus xinux.net
Zur Navigation springen Zur Suche springen

Auf debian12-1 und debian12-2

  • cat /etc/ipsec.conf
conn h2h
     authby=secret
     keyexchange=ikev2
     left=2001:db8:3333:4444::1
     mobike=no
     right=2001:db8:3333:4444::2
     ike=aes256-sha256-modp4096!
     esp=aes256-sha256-modp4096!
     auto=start
  • cat /etc/ipsec.conf
2001:db8:3333:4444::1 2001:db8:3333:4444::2  : PSK "suxer"

Starten

  • ipsec restart

Status

  • ipsec status
Security Associations (1 up, 0 connecting):
        h2h[1]: ESTABLISHED 39 minutes ago, 2001:db8:3333:4444::1[2001:db8:3333:4444::1]...2001:db8:3333:4444::2[2001:db8:3333:4444::2]
        h2h{1}:  INSTALLED, TUNNEL, reqid 1, ESP SPIs: c504c16b_i c1ca19e1_o
        h2h{1}:   2001:db8:3333:4444::1/128 === 2001:db8:3333:4444::2/128