IPSec Strongswan mit Linux Beispiel: Unterschied zwischen den Versionen

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen
 
(2 dazwischenliegende Versionen desselben Benutzers werden nicht angezeigt)
Zeile 12: Zeile 12:
 
| '''VPN-GW-IP Address''' || 192.168.4.213 || 192.168.4.214
 
| '''VPN-GW-IP Address''' || 192.168.4.213 || 192.168.4.214
 
|-
 
|-
−
| '''Internes Netz''' || 172.26.213.0/24, 10.213.1.0/24 || 172.26.214.0/24, 10.214.1.0/24
+
| '''Internes Netz''' || 172.26.213.0/24|| 172.26.214.0/24
 
|-
 
|-
 
| '''Pre-Shared Key (PSK)''' || colspan="2" | 123Start$
 
| '''Pre-Shared Key (PSK)''' || colspan="2" | 123Start$
Zeile 26: Zeile 26:
 
connections {
 
connections {
 
   site-to-site {
 
   site-to-site {
−
     local_addrs  = 192.168.5.193
+
     local_addrs  = 192.168.4.213
−
     remote_addrs = 192.168.5.194
+
     remote_addrs = 192.168.4.214
 
     mobike = no
 
     mobike = no
 
     local {
 
     local {
 
       auth = psk
 
       auth = psk
−
       id = 192.168.5.193
+
       id = 192.168.4.213
 
     }
 
     }
 
     remote {
 
     remote {
 
       auth = psk
 
       auth = psk
−
       id = 192.168.5.194
+
       id = 192.168.4.214
 
     }
 
     }
 
     children {
 
     children {
 
       net {
 
       net {
−
         local_ts  = 172.26.193.0/24
+
         local_ts  = 172.26.213.0/24
−
         remote_ts = 172.26.194.0/24
+
         remote_ts = 172.26.214.0/24
 
         esp_proposals = aes256-sha256-modp4096
 
         esp_proposals = aes256-sha256-modp4096
 
         start_action = start
 
         start_action = start
Zeile 54: Zeile 54:
 
secrets {
 
secrets {
 
   ike-1 {
 
   ike-1 {
−
     id-1 = 192.168.5.193
+
     id-1 = 192.168.4.213
−
     id-2 = 192.168.5.194
+
     id-2 = 192.168.4.214
 
     secret = "123Start$"
 
     secret = "123Start$"
 
   }
 
   }
 
}
 
}
 +
 
</pre>
 
</pre>
 +
 
=Die rechte Seite=
 
=Die rechte Seite=
 
*cat /etc/swanctl/conf.d/site-to-site.conf  
 
*cat /etc/swanctl/conf.d/site-to-site.conf  
Zeile 65: Zeile 67:
 
connections {
 
connections {
 
   site-to-site {
 
   site-to-site {
−
     local_addrs  = 192.168.5.194
+
     local_addrs  = 192.168.4.214
−
     remote_addrs = 192.168.5.193
+
     remote_addrs = 192.168.4.213
 
     mobike = no
 
     mobike = no
 
     local {
 
     local {
 
       auth = psk
 
       auth = psk
−
       id = 192.168.5.194
+
       id = 192.168.4.214
 
     }
 
     }
 
     remote {
 
     remote {
 
       auth = psk
 
       auth = psk
−
       id = 192.168.5.193
+
       id = 192.168.4.213
 
     }
 
     }
 
     children {
 
     children {
 
       net {
 
       net {
−
         local_ts  = 172.26.194.0/24
+
         local_ts  = 172.26.214.0/24
−
         remote_ts = 172.26.193.0/24
+
         remote_ts = 172.26.213.0/24
 
         esp_proposals = aes256-sha256-modp4096
 
         esp_proposals = aes256-sha256-modp4096
 
         start_action = start
 
         start_action = start
Zeile 93: Zeile 95:
 
secrets {
 
secrets {
 
   ike-1 {
 
   ike-1 {
−
     id-1 = 192.168.5.194
+
     id-1 = 192.168.4.214
−
     id-2 = 192.168.5.193
+
     id-2 = 192.168.4.213
 
     secret = "123Start$"
 
     secret = "123Start$"
 
   }
 
   }
 
}
 
}
 +
 
</pre>
 
</pre>

Aktuelle Version vom 28. September 2026, 12:55 Uhr

Installation

  • apt update
  • apt install strongswan strongswan-swanctl

Voraussetzungen

  • Beide Systeme: Linux mit strongSwan und VICI-Unterstützung (swanctl)
  • Nur VICI (swanctl), keine ipsec.conf oder ipsec.secrets
  • XX eigene Seite, gegenüberliegende Seite YY

Szenario

Einstellung links rechts
VPN-GW-IP Address 192.168.4.213 192.168.4.214
Internes Netz 172.26.213.0/24 172.26.214.0/24
Pre-Shared Key (PSK) 123Start$
Phase 1 AES256 – SHA256 – DH16(modp4096)
Phase 2 (esp) AES256 – SHA256 – DH16(modp4096)

Die linke Seite

  • cat /etc/swanctl/conf.d/site-to-site.conf
connections {
  site-to-site {
    local_addrs  = 192.168.4.213
    remote_addrs = 192.168.4.214
    mobike = no
    local {
      auth = psk
      id = 192.168.4.213
    }
    remote {
      auth = psk
      id = 192.168.4.214
    }
    children {
      net {
        local_ts  = 172.26.213.0/24
        remote_ts = 172.26.214.0/24
        esp_proposals = aes256-sha256-modp4096
        start_action = start
        close_action = none
        dpd_action = restart
        mode = tunnel
      }
    }
    version = 2
    proposals = aes256-sha256-modp4096
  }
}
secrets {
  ike-1 {
    id-1 = 192.168.4.213
    id-2 = 192.168.4.214
    secret = "123Start$"
  }
}

Die rechte Seite

  • cat /etc/swanctl/conf.d/site-to-site.conf
connections {
  site-to-site {
    local_addrs  = 192.168.4.214
    remote_addrs = 192.168.4.213
    mobike = no
    local {
      auth = psk
      id = 192.168.4.214
    }
    remote {
      auth = psk
      id = 192.168.4.213
    }
    children {
      net {
        local_ts  = 172.26.214.0/24
        remote_ts = 172.26.213.0/24
        esp_proposals = aes256-sha256-modp4096
        start_action = start
        close_action = none
        dpd_action = restart
        mode = tunnel
      }
    }
    version = 2
    proposals = aes256-sha256-modp4096
  }
}
secrets {
  ike-1 {
    id-1 = 192.168.4.214
    id-2 = 192.168.4.213
    secret = "123Start$"
  }
}