<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de">
	<id>https://wiki.ixheim.de/index.php?action=history&amp;feed=atom&amp;title=Racoon_howto</id>
	<title>Racoon howto - Versionsgeschichte</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.ixheim.de/index.php?action=history&amp;feed=atom&amp;title=Racoon_howto"/>
	<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Racoon_howto&amp;action=history"/>
	<updated>2026-06-28T21:08:07Z</updated>
	<subtitle>Versionsgeschichte dieser Seite in Xinux Wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=Racoon_howto&amp;diff=5469&amp;oldid=prev</id>
		<title>Thomas: /* /etc/setkey.conf */</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Racoon_howto&amp;diff=5469&amp;oldid=prev"/>
		<updated>2014-10-17T09:23:52Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;/etc/setkey.conf&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 17. Oktober 2014, 09:23 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l2&quot; &gt;Zeile 2:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 2:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;apt-get install ipsec-tools racoon&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;apt-get install ipsec-tools racoon&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==/etc/&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;setkey&lt;/del&gt;.conf==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==/etc/&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;ipsec-tools&lt;/ins&gt;.conf==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  #!/usr/sbin/setkey -f&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  #!/usr/sbin/setkey -f&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  flush;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  flush;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Thomas</name></author>
	</entry>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=Racoon_howto&amp;diff=5468&amp;oldid=prev</id>
		<title>Thomas: /* installation */</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Racoon_howto&amp;diff=5468&amp;oldid=prev"/>
		<updated>2014-10-17T08:32:05Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;installation&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 17. Oktober 2014, 08:32 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Zeile 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==installation==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==installation==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;apt-get install ipsec-tools&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;apt-get install ipsec-tools &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;racoon&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==/etc/setkey.conf==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==/etc/setkey.conf==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  #!/usr/sbin/setkey -f&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  #!/usr/sbin/setkey -f&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Thomas</name></author>
	</entry>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=Racoon_howto&amp;diff=5467&amp;oldid=prev</id>
		<title>Thomas: /* /etc/setkey.conf */</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Racoon_howto&amp;diff=5467&amp;oldid=prev"/>
		<updated>2014-10-17T08:28:55Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;/etc/setkey.conf&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 17. Oktober 2014, 08:28 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Zeile 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;==installation==&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;apt-get install ipsec-tools&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==/etc/setkey.conf==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==/etc/setkey.conf==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  #!/usr/sbin/setkey -f&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  #!/usr/sbin/setkey -f&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Thomas</name></author>
	</entry>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=Racoon_howto&amp;diff=4926&amp;oldid=prev</id>
		<title>Thomas: Die Seite wurde neu angelegt: „==/etc/setkey.conf==  #!/usr/sbin/setkey -f  flush;  spdflush;  spdadd 192.168.254.0/24 192.168.200.0/21 any -P out ipsec         esp/tunnel/217.91.41.188-217.…“</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Racoon_howto&amp;diff=4926&amp;oldid=prev"/>
		<updated>2014-08-06T14:27:16Z</updated>

		<summary type="html">&lt;p&gt;Die Seite wurde neu angelegt: „==/etc/setkey.conf==  #!/usr/sbin/setkey -f  flush;  spdflush;  spdadd 192.168.254.0/24 192.168.200.0/21 any -P out ipsec         esp/tunnel/217.91.41.188-217.…“&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==/etc/setkey.conf==&lt;br /&gt;
 #!/usr/sbin/setkey -f&lt;br /&gt;
 flush;&lt;br /&gt;
 spdflush;&lt;br /&gt;
 spdadd 192.168.254.0/24 192.168.200.0/21 any -P out ipsec&lt;br /&gt;
        esp/tunnel/217.91.41.188-217.89.52.3/require;&lt;br /&gt;
 &lt;br /&gt;
 spdadd 192.168.200.0/21 192.168.254.0/24 any -P in ipsec&lt;br /&gt;
        esp/tunnel/217.89.52.3-217.89.52.3/require;&lt;br /&gt;
&lt;br /&gt;
==starten von setkey==&lt;br /&gt;
 setkey -f /etc/setkey.conf&lt;br /&gt;
&lt;br /&gt;
==/etc/racoon.conf==&lt;br /&gt;
 path pre_shared_key &amp;quot;/etc/psk.txt&amp;quot;;&lt;br /&gt;
 remote 217.89.52.3 {&lt;br /&gt;
   exchange_mode main;&lt;br /&gt;
   proposal {&lt;br /&gt;
   encryption_algorithm 3des;&lt;br /&gt;
   hash_algorithm md5;&lt;br /&gt;
   authentication_method pre_shared_key;&lt;br /&gt;
   dh_group modp1536;&lt;br /&gt;
   }&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 sainfo address 192.168.254.0/24 any address 192.168.200.0/21 any {&lt;br /&gt;
        pfs_group  modp1536;&lt;br /&gt;
        encryption_algorithm 3des;&lt;br /&gt;
        authentication_algorithm hmac_md5;&lt;br /&gt;
        compression_algorithm deflate;&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
==/etc/psk.txt==&lt;br /&gt;
 217.89.52.3     schmeich-daneich-gleich&lt;br /&gt;
&lt;br /&gt;
==starten von racoon==&lt;br /&gt;
 racoon -Ff /etc/racoon.conf&lt;br /&gt;
&lt;br /&gt;
==optionen==&lt;br /&gt;
&lt;br /&gt;
*-D:&lt;br /&gt;
Diese Option gibt sämtliche Optionen der SAD aus (Dump). Wenn zusätzlich die&lt;br /&gt;
Option -P angegeben wird. so werden die Einträge der SPD ausgegebn&lt;br /&gt;
&lt;br /&gt;
*-F&lt;br /&gt;
löscht sämtliche Einträge der SAD (Flush). mit der Option -P die der SPD.&lt;br /&gt;
&lt;br /&gt;
*-P&lt;br /&gt;
Die Befehle beziehen sich auf die SPD anstelle der SAD&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*-a&lt;br /&gt;
Üblicherweise werden &amp;gt;&amp;gt;tote&amp;lt;&amp;lt; Einträge der SAD nicht angezeigt &amp;gt;&amp;gt;Tote&amp;gt;&amp;gt; Einträge sind in ihrere Gültigkeit abgelaufen, werden aber noch von der SPD referenziert. Die Option zeigt die auch diese Einträge an.&lt;br /&gt;
&lt;br /&gt;
*-d&lt;br /&gt;
Debugging&lt;br /&gt;
&lt;br /&gt;
*-x&lt;br /&gt;
Die Ausgabe von PF_KEY Nachrichten&lt;br /&gt;
&lt;br /&gt;
*-h&lt;br /&gt;
Die Ausgabe von PF_KEY Nachrichten (-x) erfolgt hexadezimal.&lt;br /&gt;
&lt;br /&gt;
*-l&lt;br /&gt;
Diese Option kann mit -D verwendet werden, um eine Endlosschleife zu ermöglichen.&lt;br /&gt;
&lt;br /&gt;
*-v&lt;br /&gt;
Verbose&lt;br /&gt;
&lt;br /&gt;
*-f Datei&lt;br /&gt;
Liest die durchzuführenden Operationen aus der Datei angegebenen Datei&lt;br /&gt;
&lt;br /&gt;
*-c&lt;br /&gt;
Liest die durchzuführenden Operationen von der Standardeingabe&lt;br /&gt;
&lt;br /&gt;
=Setkey=&lt;br /&gt;
==Beispiele==&lt;br /&gt;
===setkey -D===&lt;br /&gt;
Es werden im gegensatz zu freeSwan pro Verbindung beide SA angezeigt&lt;br /&gt;
&lt;br /&gt;
 217.91.41.188 195.126.25.114&lt;br /&gt;
        esp mode=tunnel spi=192052657(0x0b727db1) reqid=0(0x00000000)&lt;br /&gt;
        E: 3des-cbc  406251c5 6af6b591 2b2e0109 ffa2f05f 423744ba 14df0774&lt;br /&gt;
        A: hmac-sha1  0788b440 b2dd469c 93b88012 76664bbb e2cdaa4d&lt;br /&gt;
        seq=0x00000000 replay=4 flags=0x00000000 state=mature&lt;br /&gt;
        created: Mar 10 18:40:34 2005   current: Mar 10 18:56:45 2005&lt;br /&gt;
        diff: 971(s)    hard: 1800(s)   soft: 1440(s)&lt;br /&gt;
        last: Mar 10 18:41:04 2005      hard: 0(s)      soft: 0(s)&lt;br /&gt;
        current: 19056(bytes)   hard: 0(bytes)  soft: 0(bytes)&lt;br /&gt;
        allocated: 111  hard: 0 soft: 0&lt;br /&gt;
        sadb_seq=1 pid=4353 refcnt=0&lt;br /&gt;
 &lt;br /&gt;
 195.126.25.114 217.91.41.188&lt;br /&gt;
        esp mode=tunnel spi=191108491(0x0b64158b) reqid=0(0x00000000)&lt;br /&gt;
        E: 3des-cbc  04885478 40f6b5f8 4007a5ed 7154fb9c 62da3b15 9fd65fba&lt;br /&gt;
        A: hmac-sha1  b7451dd9 d92f96c3 6e969df6 08480060 0a5e1eef&lt;br /&gt;
        seq=0x00000000 replay=4 flags=0x00000000 state=mature&lt;br /&gt;
        created: Mar 10 18:40:34 2005   current: Mar 10 18:56:45 2005&lt;br /&gt;
        diff: 971(s)    hard: 1800(s)   soft: 1440(s)&lt;br /&gt;
        last: Mar 10 18:41:04 2005      hard: 0(s)      soft: 0(s)&lt;br /&gt;
        current: 15821(bytes)   hard: 0(bytes)  soft: 0(bytes)&lt;br /&gt;
        allocated: 122  hard: 0 soft: 0&lt;br /&gt;
        sadb_seq=5 pid=4353 refcnt=0&lt;br /&gt;
&lt;br /&gt;
===setkey -PD===&lt;br /&gt;
Anzeige der SPD&lt;br /&gt;
 10.10.0.0/16[any] 192.168.254.0/24[any] any&lt;br /&gt;
        in ipsec&lt;br /&gt;
        esp/tunnel/62.153.160.226-217.89.52.3/require&lt;br /&gt;
        created: Mar 10 18:18:40 2005  lastused:&lt;br /&gt;
        lifetime: 0(s) validtime: 0(s)&lt;br /&gt;
        spid=152 seq=13 pid=4354&lt;br /&gt;
        refcnt=1&lt;br /&gt;
 &lt;br /&gt;
 10.10.0.0/16[any] 192.168.254.0/24[any] any&lt;br /&gt;
        fwd ipsec&lt;br /&gt;
        esp/tunnel/62.153.160.226-217.89.52.3/require&lt;br /&gt;
        created: Mar 10 18:18:40 2005  lastused: Mar 10 18:25:08 2005&lt;br /&gt;
        lifetime: 0(s) validtime: 0(s)&lt;br /&gt;
        spid=162 seq=7 pid=4354&lt;br /&gt;
        refcnt=1&lt;br /&gt;
&lt;br /&gt;
===setkey -F===&lt;br /&gt;
Löschen der der SAD&lt;br /&gt;
&lt;br /&gt;
===setkey -PF===&lt;br /&gt;
Löschen der der SPD&lt;br /&gt;
&lt;br /&gt;
===setkey -f /etc/setkey.conf===&lt;br /&gt;
Konfigurieren der SAD und der SPD  durch die Datei /etc/setkey.conf&lt;br /&gt;
&lt;br /&gt;
===setkey -x===&lt;br /&gt;
Ausgabe des PK_KEY Kommunikationskanals&lt;br /&gt;
 19:08:59.321550&lt;br /&gt;
 19:08:59.322225&lt;br /&gt;
&lt;br /&gt;
===setkey -xH===&lt;br /&gt;
Ausgabe des PK_KEY Kommunikationskanals Hexadezimal&lt;br /&gt;
 19:10:24.969068&lt;br /&gt;
 00000000: 02 0b 00 01 02 00 00 00 00 00 00 00 19 11 00 00&lt;br /&gt;
 19:10:24.970090&lt;br /&gt;
 00000000: 02 0b 00 01 02 00 00 00 00 00 00 00 19 11 00 00&lt;br /&gt;
&lt;br /&gt;
===setkey -Dl===&lt;br /&gt;
Fortlaufende Anzeige der SAD&lt;br /&gt;
 time p   s spi      ltime   src -&amp;gt; dst&lt;br /&gt;
 1113 esp M 07d5e3c9 209/big 195.126.25.114 -&amp;gt; 217.91.41.188&lt;br /&gt;
 1113 esp M 02e5ee9e big/big 62.153.160.226 -&amp;gt; 217.91.41.188&lt;br /&gt;
 1113 esp M 095be1c4 big/big 217.89.52.3 -&amp;gt; 217.91.41.188&lt;br /&gt;
 1113 esp M 28ffcdfc big/big 217.91.41.188 -&amp;gt; 217.89.52.3&lt;br /&gt;
 1113 esp M 08fb1b4f 209/big 217.91.41.188 -&amp;gt; 195.126.25.114&lt;br /&gt;
&lt;br /&gt;
=Windows Roadwarrior=&lt;br /&gt;
&lt;br /&gt;
*Anlegen eines Verzeichnis /var/ssl&lt;br /&gt;
 mkdir /var/ssl&lt;br /&gt;
 cd /var/ssl&lt;br /&gt;
&lt;br /&gt;
*Erstellen einer root-CA&lt;br /&gt;
 CA.sh -newca&lt;br /&gt;
&lt;br /&gt;
*Erstellen eines Zertifikats&lt;br /&gt;
 CA.sh -newreq&lt;br /&gt;
&lt;br /&gt;
*Signieren des Zertifikats&lt;br /&gt;
 CA.sh -sign&lt;br /&gt;
&lt;br /&gt;
*Umbennnen des Zertifikats&lt;br /&gt;
 mv newcert.pem rechnername.pem&lt;br /&gt;
&lt;br /&gt;
*Umbennnen des Keys&lt;br /&gt;
 mv newreq.pem rechnername.key&lt;br /&gt;
&lt;br /&gt;
*Löscharbeiten&lt;br /&gt;
 Löschen Sie beginnend mit&lt;br /&gt;
 -----BEGIN CERTIFICATE REQUEST----- bis zum Ende&lt;br /&gt;
 alles aus rechnername.key, so daß die Datei mit&lt;br /&gt;
 -----BEGIN RSA PRIVATE KEY----- anfängt und mit&lt;br /&gt;
 -----END RSA PRIVATE KEY------- endet.&lt;br /&gt;
&lt;br /&gt;
*Generieren Sie eine Certificate Revocation List mit&lt;br /&gt;
 openssl ca -gencrl -out crl.pem&lt;br /&gt;
&lt;br /&gt;
*Anlegen eines Verzeichnis /etc/certs&lt;br /&gt;
 mkdir /etc/certs&lt;br /&gt;
&lt;br /&gt;
*Kopieren&lt;br /&gt;
 mkdir /etc/certs&lt;br /&gt;
 cp rechnername.pem /etc/certs&lt;br /&gt;
 cp rechnername.key /etc/certs&lt;br /&gt;
 cp clr.pem /etc/certs&lt;br /&gt;
 cp demoCA/cacert.pem /etc/certs&lt;br /&gt;
&lt;br /&gt;
*Anlegen der Links&lt;br /&gt;
 ln -s cacert.pem $(openssl x509 -noout -hash -in cacert.pem).0&lt;br /&gt;
 ln -s crl.pem $(openssl x509 -noout -hash -in cacert.pem).r0&lt;br /&gt;
&lt;br /&gt;
*Überprüfung&lt;br /&gt;
 ls -F''&lt;br /&gt;
 158606c5.0@  158606c5.r0@  cacert.pem  crl.pem  duras.xinux.com.key  duras.xinux.com.pem&lt;br /&gt;
&lt;br /&gt;
*Entschlüssel des Privaten Schlüssel für Racoon&lt;br /&gt;
 openssl rsa -in rechnername.key -out rechnername.key&lt;br /&gt;
&lt;br /&gt;
*Windows Client auf dem CA host&lt;br /&gt;
&lt;br /&gt;
*Erstellen eines Zertifikats&lt;br /&gt;
 CA.sh -newreq&lt;br /&gt;
&lt;br /&gt;
*Signieren des Zertifikats&lt;br /&gt;
 CA.sh -sign&lt;br /&gt;
&lt;br /&gt;
*Umbennnen des Zertifikats&lt;br /&gt;
 mv newcert.pem windows.pem&lt;br /&gt;
&lt;br /&gt;
*Umbennnen des Keys&lt;br /&gt;
 mv newreq.pem windows.key&lt;br /&gt;
&lt;br /&gt;
*Löscharbeiten&lt;br /&gt;
 Löschen Sie beginnend mit&lt;br /&gt;
 -----BEGIN CERTIFICATE REQUEST----- bis zum Ende&lt;br /&gt;
 alles aus dem windows.key, so daß die Datei mit&lt;br /&gt;
 -----BEGIN RSA PRIVATE KEY----- anfängt und mit&lt;br /&gt;
 -----END RSA PRIVATE KEY------- endet.&lt;br /&gt;
&lt;br /&gt;
*Umwandeln p12 Format&lt;br /&gt;
 openssl pkcs12 -export -in windows.pem -inkey windows.key -certfile demoCA/cacert.pem -out windows.p12&lt;br /&gt;
&lt;br /&gt;
*Der DN der CA&lt;br /&gt;
 openssl x509 -in demoCA/cacert.pem -noout -subject&lt;br /&gt;
&lt;br /&gt;
=Linux Roadwarrior=&lt;br /&gt;
&lt;br /&gt;
*Nach dem Erstellen der Zertifikate wie unter [[X509_ruck_zuck | x509 ruckzuck]] beschrieben müssen die pem, key und die cacert.pem Datei auf den Roadwarrior kopiert werden. Am besten in das Verzeichnis /etc/racoon/certs.&lt;br /&gt;
&lt;br /&gt;
*Als nächstes muss die cacert.pem eine OpenSSL konforme Benennung erhalten.&lt;br /&gt;
 ln -s cacert.pem $(openssl x509 -noout -hash -in cacert.pem).0&lt;br /&gt;
&lt;br /&gt;
*Dann muss das Passowrt aus dem Privaten Schlüssel enfernt werden.&lt;br /&gt;
 openssl rsa -in roadwarrior.key -out-roadwarrior.key&lt;br /&gt;
&lt;br /&gt;
*Dann werden 2 Template Dateien erzeugt&lt;br /&gt;
 #/etc/racoon/racoon.xinux.conf&lt;br /&gt;
 path certificate &amp;quot;/etc/racoon/certs&amp;quot;;&lt;br /&gt;
 remote 217.91.41.188 {&lt;br /&gt;
  exchange_mode main;&lt;br /&gt;
  certificate_type x509 &amp;quot;/etc/racoon/certs/trixie.pem&amp;quot; &amp;quot;/etc/racoon/certs/trixie.key&amp;quot;;&lt;br /&gt;
  verify_cert on;&lt;br /&gt;
  my_identifier asn1dn;&lt;br /&gt;
  peers_identifier asn1dn;&lt;br /&gt;
  proposal {&lt;br /&gt;
    encryption_algorithm 3des;&lt;br /&gt;
    hash_algorithm md5;&lt;br /&gt;
    authentication_method rsasig;&lt;br /&gt;
    dh_group modp1024;&lt;br /&gt;
  }&lt;br /&gt;
 }&lt;br /&gt;
 sainfo address x-x-x any address 192.168.254.0/24 any {&lt;br /&gt;
  pfs_group modp1024;&lt;br /&gt;
  encryption_algorithm 3des;&lt;br /&gt;
  authentication_algorithm hmac_md5;&lt;br /&gt;
  compression_algorithm deflate;&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
 #!/usr/bin/setkey -f&lt;br /&gt;
 #/etc/raccon/setkey.xinux.key&lt;br /&gt;
 flush;&lt;br /&gt;
 spdflush;&lt;br /&gt;
 spdadd x-x-x 192.168.254.0/24 any -P out ipsec esp/tunnel/x-x-x-217.91.41.188/require;&lt;br /&gt;
 spdadd 192.168.254.0/24 x-x-x any -P in  ipsec esp/tunnel/217.91.41.188-x-x-x/require;&lt;br /&gt;
&lt;br /&gt;
*Dann wird noch das Start Stop Skript erstellt /usr/local/bin/vpn &lt;br /&gt;
&lt;br /&gt;
 !/bin/bash&lt;br /&gt;
 case $1 in&lt;br /&gt;
 start)&lt;br /&gt;
  echo starte vpn&lt;br /&gt;
  IP=$(ifconfig ippp0  | grep inet | tr -s &amp;quot; &amp;quot; | cut -f 3 -d &amp;quot; &amp;quot; | cut -f 2 -d :)&lt;br /&gt;
  sed -e &amp;quot;s/x-x-x/$IP/g&amp;quot; /etc/racoon/setkey.xinux.conf &amp;gt; /tmp/setkey.conf&lt;br /&gt;
  sed -e &amp;quot;s/x-x-x/$IP/g&amp;quot; /etc/racoon/racoon.xinux.conf &amp;gt; /tmp/racoon.conf&lt;br /&gt;
  racoon -f /tmp/racoon.conf -l /tmp/racoon.log&lt;br /&gt;
  setkey -f /tmp/setkey.conf&lt;br /&gt;
 ;;&lt;br /&gt;
 stop)&lt;br /&gt;
  echo stop vpn&lt;br /&gt;
  killall racoon&lt;br /&gt;
  setkey -F&lt;br /&gt;
  setkey -PF&lt;br /&gt;
 ;;&lt;br /&gt;
 *)&lt;br /&gt;
  echo die syntax lautet $0 start|stop &lt;br /&gt;
 ;;&lt;br /&gt;
 esac&lt;/div&gt;</summary>
		<author><name>Thomas</name></author>
	</entry>
</feed>