<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de">
	<id>https://wiki.ixheim.de/index.php?action=history&amp;feed=atom&amp;title=Strongswan_mit_vti-Interfaces</id>
	<title>Strongswan mit vti-Interfaces - Versionsgeschichte</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.ixheim.de/index.php?action=history&amp;feed=atom&amp;title=Strongswan_mit_vti-Interfaces"/>
	<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Strongswan_mit_vti-Interfaces&amp;action=history"/>
	<updated>2026-06-29T01:22:17Z</updated>
	<subtitle>Versionsgeschichte dieser Seite in Xinux Wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=Strongswan_mit_vti-Interfaces&amp;diff=16100&amp;oldid=prev</id>
		<title>Janning: /* Rechner 2 */</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Strongswan_mit_vti-Interfaces&amp;diff=16100&amp;oldid=prev"/>
		<updated>2017-12-15T09:46:48Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Rechner 2&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 15. Dezember 2017, 09:46 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l48&quot; &gt;Zeile 48:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 48:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*ip tunnel add vti0 local 10.84.252.44 remote 10.84.252.43 mode vti key 100&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*ip tunnel add vti0 local 10.84.252.44 remote 10.84.252.43 mode vti key 100&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*ip link set vti0 up&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*ip link set vti0 up&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*ip addr add 10.2.2.2&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;/24 &lt;/del&gt;remote 10.2.2.1&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;/24 &lt;/del&gt;dev vti0&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*ip addr add 10.2.2.2 remote 10.2.2.1 dev vti0&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=rp-filter, policy und xfrm einstellen=&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=rp-filter, policy und xfrm einstellen=&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Janning</name></author>
	</entry>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=Strongswan_mit_vti-Interfaces&amp;diff=16099&amp;oldid=prev</id>
		<title>Janning: /* Rechner 1 */</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Strongswan_mit_vti-Interfaces&amp;diff=16099&amp;oldid=prev"/>
		<updated>2017-12-15T09:46:41Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Rechner 1&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 15. Dezember 2017, 09:46 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l43&quot; &gt;Zeile 43:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 43:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*ip tunnel add vti0 local 10.84.252.43 remote 10.84.252.44 mode vti key 100&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*ip tunnel add vti0 local 10.84.252.43 remote 10.84.252.44 mode vti key 100&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*ip link set vti0 up&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*ip link set vti0 up&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*ip addr add 10.2.2.1&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;/24 &lt;/del&gt;remote 10.2.2.2&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;/24 &lt;/del&gt;dev vti0&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*ip addr add 10.2.2.1 remote 10.2.2.2 dev vti0&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Rechner 2==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Rechner 2==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Janning</name></author>
	</entry>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=Strongswan_mit_vti-Interfaces&amp;diff=16098&amp;oldid=prev</id>
		<title>Janning: Die Seite wurde neu angelegt: „=ipsec-Routing deaktivieren= *vi /etc/strongswan.conf &lt;pre&gt; charon {         load_modular = yes         install_routes = no         plugins {                 i…“</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Strongswan_mit_vti-Interfaces&amp;diff=16098&amp;oldid=prev"/>
		<updated>2017-12-15T08:03:36Z</updated>

		<summary type="html">&lt;p&gt;Die Seite wurde neu angelegt: „=ipsec-Routing deaktivieren= *vi /etc/strongswan.conf &amp;lt;pre&amp;gt; charon {         load_modular = yes         install_routes = no         plugins {                 i…“&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt;=ipsec-Routing deaktivieren=&lt;br /&gt;
*vi /etc/strongswan.conf&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
charon {&lt;br /&gt;
        load_modular = yes&lt;br /&gt;
        install_routes = no&lt;br /&gt;
        plugins {&lt;br /&gt;
                include strongswan.d/charon/*.conf&lt;br /&gt;
        }&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
include strongswan.d/*.conf&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=ipsec.conf und ipsec.secrets einrichten=&lt;br /&gt;
*vi /etc/ipsec.conf&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
conn routed-vpn&lt;br /&gt;
    right=10.84.252.44&lt;br /&gt;
    left=10.84.252.43&lt;br /&gt;
    leftsubnet=0.0.0.0/0&lt;br /&gt;
    rightsubnet=0.0.0.0/0&lt;br /&gt;
    ike=aes256-sha256-modp2048&lt;br /&gt;
    ikelifetime=3600s&lt;br /&gt;
    esp=aes256-sha256-modp2048&lt;br /&gt;
    keylife=1800s&lt;br /&gt;
    rekeymargin=540s&lt;br /&gt;
    type=tunnel&lt;br /&gt;
    compress=no&lt;br /&gt;
    authby=secret&lt;br /&gt;
    mark=100&lt;br /&gt;
    auto=start&lt;br /&gt;
    keyingtries=%forever&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*vi /etc/ipsec.secrets&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
10.84.252.43 10.84.252.44  : PSK &amp;quot;suxer&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=vti-interface einrichten=&lt;br /&gt;
==Rechner 1==&lt;br /&gt;
*ip tunnel add vti0 local 10.84.252.43 remote 10.84.252.44 mode vti key 100&lt;br /&gt;
*ip link set vti0 up&lt;br /&gt;
*ip addr add 10.2.2.1/24 remote 10.2.2.2/24 dev vti0&lt;br /&gt;
&lt;br /&gt;
==Rechner 2==&lt;br /&gt;
*ip tunnel add vti0 local 10.84.252.44 remote 10.84.252.43 mode vti key 100&lt;br /&gt;
*ip link set vti0 up&lt;br /&gt;
*ip addr add 10.2.2.2/24 remote 10.2.2.1/24 dev vti0&lt;br /&gt;
&lt;br /&gt;
=rp-filter, policy und xfrm einstellen=&lt;br /&gt;
*echo 0 &amp;gt; /proc/sys/net/ipv4/conf/vti0/rp_filter&lt;br /&gt;
*echo 1 &amp;gt; /proc/sys/net/ipv4/conf/vti0/disable_policy&lt;br /&gt;
*echo 1 &amp;gt; /proc/sys/net/ipv4/conf/ens7/disable_xfrm&lt;br /&gt;
*echo 1 &amp;gt; /proc/sys/net/ipv4/conf/ens7/disable_policy&lt;br /&gt;
&lt;br /&gt;
=Routing-Tabelle 220 leeren=&lt;br /&gt;
*ip route flush table 220&lt;br /&gt;
&lt;br /&gt;
=Routen setzen=&lt;br /&gt;
==Rechner 1==&lt;br /&gt;
*ip route add 10.83.44.0/24 via 10.2.2.1&lt;br /&gt;
&lt;br /&gt;
==Rechner 2==&lt;br /&gt;
*ip route add 10.83.43.0/24 via 10.2.2.2&lt;/div&gt;</summary>
		<author><name>Janning</name></author>
	</entry>
</feed>