Strongswan zu strongswan aggressive modus: Unterschied zwischen den Versionen

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen
Zeile 1: Zeile 1:
=Config on Server=
+
=Config on server=
 
Add thin entry
 
Add thin entry
 
*/etc/strongswan.conf
 
*/etc/strongswan.conf
Zeile 26: Zeile 26:
 
10.84.252.32 %any : PSK "123"
 
10.84.252.32 %any : PSK "123"
 
</pre>
 
</pre>
 +
 
=Config on client=
 
=Config on client=
 
Add thin entry
 
Add thin entry

Version vom 9. November 2017, 08:00 Uhr

Config on server

Add thin entry

  • /etc/strongswan.conf
 charon {
        i_dont_care_about_security_and_use_aggressive_mode_psk = yes
        ... 
}
  • /etc/ipsec.conf
conn s2s
     authby=secret
     keyexchange=ikev1
     aggressive = yes
     left=10.84.252.32
     leftsubnet=10.83.32.0/24
     right=%any
     rightsubnet=10.83.33.0/24
     ike=aes128-sha1-modp1024
     esp=aes128-sha1-modp1024
     auto=start
  • /etc/ipsec.secrets
10.84.252.32 %any : PSK "123"

Config on client

Add thin entry

  • /etc/strongswan.conf
 charon {
        i_dont_care_about_security_and_use_aggressive_mode_psk = yes
        ... 
}
  • /etc/ipsec.conf
conn s2s
     authby=secret
     keyexchange=ikev1
     aggressive = yes
     left=10.84.252.32
     leftsubnet=10.83.32.0/24
     right=%any
     rightsubnet=10.83.33.0/24
     ike=aes128-sha1-modp1024
     esp=aes128-sha1-modp1024
     auto=start
  • /etc/ipsec.secrets
10.84.252.32 %any : PSK "123"