Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- apt install xl2tpd # en ambos nodos
- Server (left)
- /etc/ipsec.d/l2tp_psk.conf
- config setup
- strictcrlpolicy=no
- conn %default
- ikelifetime=30m
- keylife=15m
- rekeymargin=3m
- keyingtries=1
- mobike=no
- dpdaction=clear
- dpddelay=30
- dpdtimeout=120
- conn mainconn
- left=10.0.0.10
- leftprotoport=17/1701
- right=%any
- rightprotoport=17/1701
- authby=secret
- type=transport
- keyexchange=ikev1
- auto=add
- /etc/ipsec.conf
- include /etc/ipsec.d/l2tp_psk.conf
- /etc/ipsec.secrets
- : PSK "secreta"
- ------------------------------------------
- Client (right)
- /etc/ipsec.d/l2tp_psk_cli.conf
- config setup
- strictcrlpolicy=no
- conn %default
- ikelifetime=30m
- keylife=15m
- rekeymargin=3m
- keyingtries=1
- mobike=no
- dpdaction=restart
- dpddelay=30
- dpdtimeout=120
- conn l2tp
- left=10.0.0.10
- leftprotoport=17/1701
- right=10.0.0.20
- rightprotoport=17/1701
- authby=secret
- type=transport
- keyexchange=ikev1
- auto=route
- /etc/ipsec.conf
- include /etc/ipsec.d/l2tp_psk.conf
- /etc/ipsec.secrets
- : PSK "secreta"
- ==================================================
- L2TP server:
- /etc/xl2tp/xl2tp.conf
- [global]
- debug network = yes
- debug tunnel = yes
- [lns default]
- ip range = 192.168.100.10-192.168.100.50
- local ip = 192.168.100.1
- require chap = yes
- refuse pap = yes
- require authentication = yes
- name = l2tpd
- ppp debug = yes
- pppoptfile = /etc/ppp/options.l2tpd
- length bit = yes
- /etc/ppp/options.l2tp
- ipcp-accept-local
- ipcp-accept-remote
- lcp-echo-interval 30
- lcp-echo-failure 10
- ms-dns 8.8.8.8
- noccp
- auth
- mtu 1400
- mru 1400
- defaultroute
- debug
- proxyarp
- connect-delay 5000
- require-chap
- /etc/ppp/chap-secrets
- diego l2tpd 123123 *
- --------------------------------
- L2TP client
- /etc/xl2tp/xl2tpd.conf
- [lac myvpn]
- lns = 10.0.0.10
- ppp debug = yes
- pppoptfile = /etc/ppp/options.l2tpd.client
- length bit = yes
- /etc/ppp/options.l2tpd.client
- ipcp-accept-local
- ipcp-accept-remote
- refuse-eap
- require-chap
- noccp
- noauth
- mtu 1280
- mru 1280
- noipdefault
- defaultroute
- usepeerdns
- connect-delay 5000
- name diego
- password 123123
- /etc/ppp/chap-secrets
- diego * 123123 *
- ==============================
- para conectar, en el cliente:
- ## conectar con
- # echo "c myvpn" > /var/run/xl2tpd/l2tp-control
- ## desconectar con
- # echo "d myvpn" > /var/run/xl2tpd/l2tp-control
Add Comment
Please, Sign In to add comment