IPSec Strongswan mit Linux Beispiel: Unterschied zwischen den Versionen
Zur Navigation springen
Zur Suche springen
| Zeile 67: | Zeile 67: | ||
connections { | connections { | ||
site-to-site { | site-to-site { | ||
| − | local_addrs = 192.168. | + | local_addrs = 192.168.4.214 |
| − | remote_addrs = 192.168. | + | remote_addrs = 192.168.4.213 |
mobike = no | mobike = no | ||
local { | local { | ||
auth = psk | auth = psk | ||
| − | id = 192.168. | + | id = 192.168.4.214 |
} | } | ||
remote { | remote { | ||
auth = psk | auth = psk | ||
| − | id = 192.168. | + | id = 192.168.4.213 |
} | } | ||
children { | children { | ||
net { | net { | ||
| − | local_ts = 172.26. | + | local_ts = 172.26.214.0/24 |
| − | remote_ts = 172.26. | + | remote_ts = 172.26.213.0/24 |
esp_proposals = aes256-sha256-modp4096 | esp_proposals = aes256-sha256-modp4096 | ||
start_action = start | start_action = start | ||
| Zeile 95: | Zeile 95: | ||
secrets { | secrets { | ||
ike-1 { | ike-1 { | ||
| − | id-1 = 192.168. | + | id-1 = 192.168.4.214 |
| − | id-2 = 192.168. | + | id-2 = 192.168.4.213 |
secret = "123Start$" | secret = "123Start$" | ||
} | } | ||
} | } | ||
| + | |||
</pre> | </pre> | ||
Version vom 28. September 2026, 12:46 Uhr
Installation
- apt update
- apt install strongswan strongswan-swanctl
Voraussetzungen
- Beide Systeme: Linux mit strongSwan und VICI-Unterstützung (swanctl)
- Nur VICI (swanctl), keine ipsec.conf oder ipsec.secrets
- XX eigene Seite, gegenüberliegende Seite YY
Szenario
| Einstellung | links | rechts |
|---|---|---|
| VPN-GW-IP Address | 192.168.4.213 | 192.168.4.214 |
| Internes Netz | 172.26.213.0/24, 10.213.1.0/24 | 172.26.214.0/24, 10.214.1.0/24 |
| Pre-Shared Key (PSK) | 123Start$ | |
| Phase 1 | AES256 – SHA256 – DH16(modp4096) | |
| Phase 2 (esp) | AES256 – SHA256 – DH16(modp4096) | |
Die linke Seite
- cat /etc/swanctl/conf.d/site-to-site.conf
connections {
site-to-site {
local_addrs = 192.168.4.213
remote_addrs = 192.168.4.214
mobike = no
local {
auth = psk
id = 192.168.4.213
}
remote {
auth = psk
id = 192.168.4.214
}
children {
net {
local_ts = 172.26.213.0/24
remote_ts = 172.26.214.0/24
esp_proposals = aes256-sha256-modp4096
start_action = start
close_action = none
dpd_action = restart
mode = tunnel
}
}
version = 2
proposals = aes256-sha256-modp4096
}
}
secrets {
ike-1 {
id-1 = 192.168.4.213
id-2 = 192.168.4.214
secret = "123Start$"
}
}
Die rechte Seite
- cat /etc/swanctl/conf.d/site-to-site.conf
connections {
site-to-site {
local_addrs = 192.168.4.214
remote_addrs = 192.168.4.213
mobike = no
local {
auth = psk
id = 192.168.4.214
}
remote {
auth = psk
id = 192.168.4.213
}
children {
net {
local_ts = 172.26.214.0/24
remote_ts = 172.26.213.0/24
esp_proposals = aes256-sha256-modp4096
start_action = start
close_action = none
dpd_action = restart
mode = tunnel
}
}
version = 2
proposals = aes256-sha256-modp4096
}
}
secrets {
ike-1 {
id-1 = 192.168.4.214
id-2 = 192.168.4.213
secret = "123Start$"
}
}