Strongswan zu strongswan ikev2 site to site: Unterschied zwischen den Versionen

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen
 
(5 dazwischenliegende Versionen desselben Benutzers werden nicht angezeigt)
Zeile 9: Zeile 9:
 
conn s2s
 
conn s2s
 
     authby=secret
 
     authby=secret
     keyexchange=ikev1
+
     keyexchange=ikev2
 
     left=10.82.227.12
 
     left=10.82.227.12
 
     leftid=10.82.227.12
 
     leftid=10.82.227.12
Zeile 30: Zeile 30:
 
*ipsec up  s2s
 
*ipsec up  s2s
 
<pre>
 
<pre>
initiating Main Mode IKE_SA s2s[3] to 10.82.227.22
+
initiating IKE_SA s2s[2] to 10.82.227.22
generating ID_PROT request 0 [ SA V V V V V ]
+
generating IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(HASH_ALG) N(REDIR_SUP) ]
sending packet: from 10.82.227.12[500] to 10.82.227.22[500] (180 bytes)
+
sending packet: from 10.82.227.12[500] to 10.82.227.22[500] (720 bytes)
received packet: from 10.82.227.22[500] to 10.82.227.12[500] (160 bytes)
+
received packet: from 10.82.227.22[500] to 10.82.227.12[500] (728 bytes)
parsed ID_PROT response 0 [ SA V V V V ]
+
parsed IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(HASH_ALG) N(CHDLESS_SUP) N(MULT_AUTH) ]
received XAuth vendor ID
 
received DPD vendor ID
 
received FRAGMENTATION vendor ID
 
received NAT-T (RFC 3947) vendor ID
 
 
selected proposal: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_4096
 
selected proposal: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_4096
generating ID_PROT request 0 [ KE No NAT-D NAT-D ]
+
authentication of '10.82.227.12' (myself) with pre-shared key
sending packet: from 10.82.227.12[500] to 10.82.227.22[500] (652 bytes)
+
establishing CHILD_SA s2s{2}
received packet: from 10.82.227.22[500] to 10.82.227.12[500] (652 bytes)
+
generating IKE_AUTH request 1 [ IDi N(INIT_CONTACT) IDr AUTH SA TSi TSr N(MULT_AUTH) N(EAP_ONLY) N(MSG_ID_SYN_SUP) ]
parsed ID_PROT response 0 [ KE No NAT-D NAT-D ]
+
sending packet: from 10.82.227.12[500] to 10.82.227.22[500] (256 bytes)
generating ID_PROT request 0 [ ID HASH N(INITIAL_CONTACT) ]
+
received packet: from 10.82.227.22[500] to 10.82.227.12[500] (224 bytes)
sending packet: from 10.82.227.12[500] to 10.82.227.22[500] (108 bytes)
+
parsed IKE_AUTH response 1 [ IDr AUTH SA TSi TSr N(AUTH_LFT) ]
received packet: from 10.82.227.22[500] to 10.82.227.12[500] (92 bytes)
+
authentication of '10.82.227.22' with pre-shared key successful
parsed ID_PROT response 0 [ ID HASH ]
+
IKE_SA s2s[2] established between 10.82.227.12[10.82.227.12]...10.82.227.22[10.82.227.22]
IKE_SA s2s[3] established between 10.82.227.12[10.82.227.12]...10.82.227.22[10.82.227.22]
+
scheduling reauthentication in 10119s
scheduling reauthentication in 10142s
+
maximum IKE_SA lifetime 10659s
maximum IKE_SA lifetime 10682s
+
selected proposal: ESP:AES_CBC_256/HMAC_SHA2_256_128/NO_EXT_SEQ
generating QUICK_MODE request 1581114031 [ HASH SA No KE ID ID ]
+
CHILD_SA s2s{2} established with SPIs cc16cb02_i c89d755d_o and TS 10.82.243.0/24 === 10.82.244.0/24
sending packet: from 10.82.227.12[500] to 10.82.227.22[500] (716 bytes)
 
received packet: from 10.82.227.22[500] to 10.82.227.12[500] (716 bytes)
 
parsed QUICK_MODE response 1581114031 [ HASH SA No KE ID ID ]
 
selected proposal: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_4096/NO_EXT_SEQ
 
CHILD_SA s2s{3} established with SPIs c2c20b47_i c1f461d9_o and TS 10.82.243.0/24 === 10.82.244.0/24
 
 
connection 's2s' established successfully
 
connection 's2s' established successfully
 
</pre>
 
</pre>
Zeile 63: Zeile 54:
 
*ipsec down s2s
 
*ipsec down s2s
 
<pre>
 
<pre>
closing CHILD_SA s2s{3} with SPIs c2c20b47_i (0 bytes) c1f461d9_o (0 bytes) and TS 10.82.243.0/24 === 10.82.244.0/24
+
deleting IKE_SA s2s[2] between 10.82.227.12[10.82.227.12]...10.82.227.22[10.82.227.22]
sending DELETE for ESP CHILD_SA with SPI c2c20b47
+
sending DELETE for IKE_SA s2s[2]
generating INFORMATIONAL_V1 request 2875265242 [ HASH D ]
+
generating INFORMATIONAL request 2 [ D ]
sending packet: from 10.82.227.12[500] to 10.82.227.22[500] (92 bytes)
+
sending packet: from 10.82.227.12[500] to 10.82.227.22[500] (80 bytes)
deleting IKE_SA s2s[3] between 10.82.227.12[10.82.227.12]...10.82.227.22[10.82.227.22]
+
received packet: from 10.82.227.22[500] to 10.82.227.12[500] (80 bytes)
sending DELETE for IKE_SA s2s[3]
+
parsed INFORMATIONAL response 2 [ ]
generating INFORMATIONAL_V1 request 510142709 [ HASH D ]
+
IKE_SA deleted
sending packet: from 10.82.227.12[500] to 10.82.227.22[500] (108 bytes)
+
IKE_SA [2] closed successfully
IKE_SA [3] closed successfully
+
 
 
</pre>
 
</pre>
 +
 
=Status=
 
=Status=
 
*ipsec status  s2s
 
*ipsec status  s2s
Zeile 85: Zeile 77:
 
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
 
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
 
listening on eth0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
 
listening on eth0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
08:37:31.702968 IP 10.82.227.12.500 > 10.82.227.22.500: isakmp: phase 1 I ident
+
listening on eth0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
08:37:31.707296 IP 10.82.227.22.500 > 10.82.227.12.500: isakmp: phase 1 R ident
+
09:03:46.060570 IP 10.82.227.12.500 > 10.82.227.22.500: isakmp: parent_sa ikev2_init[I]
08:37:31.764500 IP 10.82.227.12.500 > 10.82.227.22.500: isakmp: phase 1 I ident
+
09:03:46.173147 IP 10.82.227.22.500 > 10.82.227.12.500: isakmp: parent_sa ikev2_init[R]
08:37:31.888131 IP 10.82.227.22.500 > 10.82.227.12.500: isakmp: phase 1 R ident
+
09:03:46.230911 IP 10.82.227.12.500 > 10.82.227.22.500: isakmp: child_sa  ikev2_auth[I]
08:37:31.945758 IP 10.82.227.12.500 > 10.82.227.22.500: isakmp: phase 1 I ident[E]
+
09:03:46.234449 IP 10.82.227.22.500 > 10.82.227.12.500: isakmp: child_sa  ikev2_auth[R]
08:37:31.949075 IP 10.82.227.22.500 > 10.82.227.12.500: isakmp: phase 1 R ident[E]
+
 
08:37:32.018782 IP 10.82.227.12.500 > 10.82.227.22.500: isakmp: phase 2/others I oakley-quick[E]
 
08:37:32.128716 IP 10.82.227.22.500 > 10.82.227.12.500: isakmp: phase 2/others R oakley-quick[E]
 
08:37:32.193586 IP 10.82.227.12.500 > 10.82.227.22.500: isakmp: phase 2/others I oakley-quick[E]
 
 
</pre>
 
</pre>
 
down
 
down
 
<pre>
 
<pre>
08:38:13.527180 IP 10.82.227.12.500 > 10.82.227.22.500: isakmp: phase 2/others I inf[E]
+
09:04:02.224802 IP 10.82.227.12.500 > 10.82.227.22.500: isakmp: child_sa  inf2[I]
08:38:13.527950 IP 10.82.227.12.500 > 10.82.227.22.500: isakmp: phase 2/others I inf[E]
+
09:04:02.228834 IP 10.82.227.22.500 > 10.82.227.12.500: isakmp: child_sa  inf2[R]
 
</pre>
 
</pre>
  
Zeile 108: Zeile 97:
 
     authby=secret
 
     authby=secret
 
     keyexchange=ikev2
 
     keyexchange=ikev2
     left=192.168.244.93
+
     left=10.82.227.12
     leftid=@alice
+
     leftid=10.82.227.12
     leftsubnet=172.16.93.0/24,10.16.93.0/24
+
     leftsubnet=10.82.243.0/24,192.168.20.0/24
     right=192.168.244.59
+
    mobike=no
     rightid=@tiazel
+
     right=10.82.227.22
     rightsubnet=172.16.59.0/24,10.16.59.0/24
+
     rightid=10.82.227.22
     ike=aes256-sha1-modp1536
+
     rightsubnet=10.82.244.0/24
     esp=aes256-sha1-modp1536
+
     ike=aes256-sha256-modp4096!
 +
     esp=aes256-sha256-modp4096!
 
     auto=start
 
     auto=start
 
</pre>
 
</pre>
Zeile 121: Zeile 111:
 
<pre>
 
<pre>
 
Security Associations (1 up, 0 connecting):
 
Security Associations (1 up, 0 connecting):
         s2s[4]: ESTABLISHED 80 seconds ago, 192.168.244.93[alice]...192.168.244.59[tiazel]
+
         s2s[2]: ESTABLISHED 5 seconds ago, 10.82.227.12[10.82.227.12]...10.82.227.22[10.82.227.22]
         s2s{4}:  INSTALLED, TUNNEL, ESP SPIs: c0087b2d_i c3cf4303_o
+
         s2s{2}:  INSTALLED, TUNNEL, reqid 1, ESP SPIs: cda686f1_i c7f9fce6_o
         s2s{4}:  172.16.93.0/24 10.16.93.0/24 === 172.16.59.0/24 10.16.59.0/24
+
         s2s{2}:  10.82.243.0/24 192.168.20.0/24 === 10.82.244.0/24
 
</pre>
 
</pre>
  
 
=Links=
 
=Links=
 
*https://www.heise.de/security/artikel/Einfacher-VPN-Tunnelbau-dank-IKEv2-270056.html
 
*https://www.heise.de/security/artikel/Einfacher-VPN-Tunnelbau-dank-IKEv2-270056.html

Aktuelle Version vom 5. September 2022, 09:08 Uhr


Config is the same on both sites

ipsec.conf

Erklärung

Datei

conn s2s
     authby=secret
     keyexchange=ikev2
     left=10.82.227.12
     leftid=10.82.227.12
     leftsubnet=10.82.243.0/24
     mobike=no
     right=10.82.227.22
     rightid=10.82.227.22
     rightsubnet=10.82.244.0/24
     ike=aes256-sha256-modp4096!
     esp=aes256-sha256-modp4096!
     auto=start

ipsec.secrets

ID Kombination mit Authentifizierungsmethodes
10.82.227.12 10.82.227.22  : PSK "suxer"

Handling

Up

  • ipsec up s2s
initiating IKE_SA s2s[2] to 10.82.227.22
generating IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(HASH_ALG) N(REDIR_SUP) ]
sending packet: from 10.82.227.12[500] to 10.82.227.22[500] (720 bytes)
received packet: from 10.82.227.22[500] to 10.82.227.12[500] (728 bytes)
parsed IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(HASH_ALG) N(CHDLESS_SUP) N(MULT_AUTH) ]
selected proposal: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_4096
authentication of '10.82.227.12' (myself) with pre-shared key
establishing CHILD_SA s2s{2}
generating IKE_AUTH request 1 [ IDi N(INIT_CONTACT) IDr AUTH SA TSi TSr N(MULT_AUTH) N(EAP_ONLY) N(MSG_ID_SYN_SUP) ]
sending packet: from 10.82.227.12[500] to 10.82.227.22[500] (256 bytes)
received packet: from 10.82.227.22[500] to 10.82.227.12[500] (224 bytes)
parsed IKE_AUTH response 1 [ IDr AUTH SA TSi TSr N(AUTH_LFT) ]
authentication of '10.82.227.22' with pre-shared key successful
IKE_SA s2s[2] established between 10.82.227.12[10.82.227.12]...10.82.227.22[10.82.227.22]
scheduling reauthentication in 10119s
maximum IKE_SA lifetime 10659s
selected proposal: ESP:AES_CBC_256/HMAC_SHA2_256_128/NO_EXT_SEQ
CHILD_SA s2s{2} established with SPIs cc16cb02_i c89d755d_o and TS 10.82.243.0/24 === 10.82.244.0/24
connection 's2s' established successfully

Down

  • ipsec down s2s
deleting IKE_SA s2s[2] between 10.82.227.12[10.82.227.12]...10.82.227.22[10.82.227.22]
sending DELETE for IKE_SA s2s[2]
generating INFORMATIONAL request 2 [ D ]
sending packet: from 10.82.227.12[500] to 10.82.227.22[500] (80 bytes)
received packet: from 10.82.227.22[500] to 10.82.227.12[500] (80 bytes)
parsed INFORMATIONAL response 2 [ ]
IKE_SA deleted
IKE_SA [2] closed successfully

Status

  • ipsec status s2s
Security Associations (1 up, 0 connecting):
         s2s[4]: ESTABLISHED 7 seconds ago, 10.82.227.12[10.82.227.12]...10.82.227.22[10.82.227.22]
         s2s{4}:  INSTALLED, TUNNEL, reqid 1, ESP SPIs: cef198fc_i c4de821a_o
         s2s{4}:   10.82.243.0/24 === 10.82.244.0/24

TCPDump der Verbindung

  • tcpdump -ni eth0 port 500 or esp
up
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
listening on eth0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
09:03:46.060570 IP 10.82.227.12.500 > 10.82.227.22.500: isakmp: parent_sa ikev2_init[I]
09:03:46.173147 IP 10.82.227.22.500 > 10.82.227.12.500: isakmp: parent_sa ikev2_init[R]
09:03:46.230911 IP 10.82.227.12.500 > 10.82.227.22.500: isakmp: child_sa  ikev2_auth[I]
09:03:46.234449 IP 10.82.227.22.500 > 10.82.227.12.500: isakmp: child_sa  ikev2_auth[R]

down

09:04:02.224802 IP 10.82.227.12.500 > 10.82.227.22.500: isakmp: child_sa  inf2[I]
09:04:02.228834 IP 10.82.227.22.500 > 10.82.227.12.500: isakmp: child_sa  inf2[R]

Mehrere Subnetze

alice und tiazel

  • /etc/ipsec.conf
conn s2s
     authby=secret
     keyexchange=ikev2
     left=10.82.227.12
     leftid=10.82.227.12
     leftsubnet=10.82.243.0/24,192.168.20.0/24
     mobike=no
     right=10.82.227.22
     rightid=10.82.227.22
     rightsubnet=10.82.244.0/24
     ike=aes256-sha256-modp4096!
     esp=aes256-sha256-modp4096!
     auto=start
  • ipsec status
Security Associations (1 up, 0 connecting):
         s2s[2]: ESTABLISHED 5 seconds ago, 10.82.227.12[10.82.227.12]...10.82.227.22[10.82.227.22]
         s2s{2}:  INSTALLED, TUNNEL, reqid 1, ESP SPIs: cda686f1_i c7f9fce6_o
         s2s{2}:   10.82.243.0/24 192.168.20.0/24 === 10.82.244.0/24

Links