Openswan zu strongswan

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen

ipsec

start

ipsec start

Starting strongSwan 5.1.2 IPsec [starter]...

stop

ipsec stop

Stopping strongSwan IPsec...

restart

ipsec restart

Stopping strongSwan IPsec...
Starting strongSwan 5.1.2 IPsec [starter]...

status

ipsec status

Security Associations (1 up, 0 connecting):
  franz-huey[1]: ESTABLISHED 25 seconds ago, 192.168.244.151[192.168.244.151]...192.168.242.249[192.168.242.249]
  franz-huey{1}:  INSTALLED, TUNNEL, ESP SPIs: c31e2d68_i 2b95ea12_o
  franz-huey{1}:   10.18.44.0/24 === 10.4.3.0/24

Openswan konfigurieren ( PSK )

Tunnel Parameter definieren

Tunnelkonfiguration

/etc/ipsec.conf

conn franz-huey
       authby=secret
       left=192.168.242.249
       leftsubnet=10.4.3.0/24
       right=192.168.244.151
       rightsubnet=10.18.44.0/24
       ike=aes192-md5
       phase2alg=aes192-md5
       pfs=no
       auto=add
PSK definieren

/etc/ipsec.secrets

192.168.242.249 192.168.244.151 : PSK "katzenklo"

Strongswan konfigurieren ( PSK )

Tunnel Parameter definieren

Tunnelkonfiguration

/etc/ipsec.conf conn franz-huey

       authby=secret
       left=192.168.242.249
       leftsubnet=10.4.3.0/24
       right=192.168.244.151
       rightsubnet=10.18.44.0/24
       ike=aes192-md5
       esp=aes192-md5
       auto=add
PSK definieren

/etc/ipsec.secrets

192.168.242.249 192.168.244.151 : PSK "katzenklo"