Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- eth1(.1) eth0(.10) eth2(.20) eth1(.1)
- LAN1---------------[SG1]-----------------(tunnel)----------------[SG2]-------------LAN2
- (192.168.10.0/24) (10.0.0.0/24) (192.168.20.0/24)
- IPSEC-PSK
- tunnel entre dos security gateways.
- gateway A, called "left"
- gateway B, called "right"
- apt-get install strongswan #en ambos nodos
- ===============================================================================
- Nodo @a
- ___________________________________________________
- /etc/ipsec.conf
- agregar:
- include /etc/ipsec.d/ab_psk.conf
- ___________________________________________________
- /etc/ipsec.d/ab_psk.conf
- config setup
- charondebug="all"
- uniqueids=yes
- strictcrlpolicy=no
- conn %default
- conn tunnel #
- left=10.0.0.10
- leftid=@a
- leftsubnet=192.168.10.0/24
- right=10.0.0.20
- rightid=@b
- rightsubnet=192.168.20.0/24
- ike=aes256-sha2_256-modp1024!
- esp=aes256-sha2_256!
- keyingtries=0
- ikelifetime=1h
- lifetime=8h
- dpddelay=30
- dpdtimeout=120
- dpdaction=restart
- authby=secret
- auto=start
- keyexchange=ikev2
- type=tunnel
- ___________________________________________________
- /etc/ipsec.secrets
- @a @b : PSK "secreta"
- ===============================================================================
- Nodo @b
- ___________________________________________________
- /etc/ipsec.conf
- agregar:
- include /etc/ipsec.d/ab_psk.conf
- ___________________________________________________
- /etc/ipsec.d/ab_psk.conf
- config setup
- charondebug="all"
- uniqueids=yes
- strictcrlpolicy=no
- conn %default
- conn tunnel #
- left=10.0.0.10
- leftid=@a
- leftsubnet=192.168.10.0/24
- right=10.0.0.20
- rightid=@b
- rightsubnet=192.168.20.0/24
- ike=aes256-sha2_256-modp1024!
- esp=aes256-sha2_256!
- keyingtries=0
- ikelifetime=1h
- lifetime=8h
- dpddelay=30
- dpdtimeout=120
- dpdaction=restart
- authby=secret
- auto=start
- keyexchange=ikev2
- type=tunnel
- ___________________________________________________
- /etc/ipsec.secrets
- @a @b : PSK "secreta"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement