Labels

Pressefreiheit (178) Wirtschaft (167) Österreich (132) IT (125) code (78) Staatsschulden (41) EZB (28) Geopolitik (22) Pensionssystem (17)

2026-09-28

Linux: ipv4 ipsec server with roadworrior behind SNAT wlan


This describes a scenario of an ipsec server with public ip and a client behind a NAT gateway.
Server uses self signed ROOT CA and a signed ipsec certificate with public/private key for authentication.
Client uses Pre-Shared-Key PSK and servers certificate public RSA key.

ipsec server

Generate ROOT CA and ipsec rsa priv keys and certificates

#/usr/bin/bash
# delete all old certs priv keys and certificate requests rm -f strongswanKey.pem strongswanCert.pem ipsecKey.pem ipsecReq.pem ipsecCert.pem *.pem
# generate snake oil ROOT CA pki --gen --type ed25519 --outform pem > strongswanKey.pem pki --self --ca --lifetime 3652 --in strongswanKey.pem \ --dn "C=CH, O=strongSwan, CN=strongSwan Root CA" \ --outform pem > strongswanCert.pem # print snakeoil ROOT CA pki --print --in strongswanCert.pem
# generate ipsec private key and certificate pki --gen --type rsa --size 3072 --outform pem > ipsecKey.pem # pki --gen --type ed25519 --outform pem > ipsecKey.pem pki --req --type priv --in ipsecKey.pem \ --dn "C=AT, O=area23, CN=ipsec.area23.at" \ --san ipsec.area23.at --outform pem > ipsecReq.pem pki --issue --cacert strongswanCert.pem --cakey strongswanKey.pem \ --type pkcs10 --in ipsecReq.pem --serial 01 --lifetime 1826 \ --outform pem > ipsecCert.pem # print ipsec certificate pki --print --in ipsecCert.pem # copy certs and priv keys cp strongswanCert.pem /etc/ipsec.d/cacerts/. cp *Cert.pem /etc/ipsec.d/certs/. cp *Key.pem /etc/ipsec.d/private/.

server: add virtual interface to eth0

ifconfig eth0:1 10.160.0.4  netmask 255.255.255.0 broadcast 10.160.0.255 up

/etc/ipsec.conf # server

# ipsec.conf - strongSwan IPsec configuration file

# basic configuration
config setup
        strictcrlpolicy=no
        charondebug="all"
        uniqueids=no

ca strongswan  #define alternative CRL distribution point
        cacert=strongswanCert.pem  # self snake oil generated ROOT CA
        auto=add

conn %default
       keyingtries=1
       keyexchange=ikev2
conn ipsec-ikev2-vpn
        auto=add
        authby=xauthrsasig
        xauth=server
        compress=no
        type=tunnel
        keyexchange=ikev2
        fragmentation=yes
        forceencaps=yes
        # ike=aes256-sha1-modp1024,3des-sha1-modp1024!
        # esp=aes256-sha1,3des-sha1!
        dpdaction=clear                 # configure dead-peer detection
        dpddelay=300s
        rekey=no
        # configure the server (left) side IPSec parameters
        left=%any
        leftid=ipsec.area23.at
        leftcert=/etc/ipsec.d/certs/ipsecCert.pem # ipsecCert generated from ROOT CA
        leftsendcert=always
        leftsubnet=10.160.0.4/24
        # configure the client (right) side IPSec parameters like private IPs
        rightid=%any
        # rightid="C=AT, O=area23, CN=ipsec.area23.at"
        # rightauth=eap-mschapv2       
        # rightauth=pubkey
        rightauth=secret                # pre shared key
        # rightcert=strongswanCert.pem
        rightsourceip=10.160.1.0/24     # opposite subnet
        rightsubnet=10.160.1.0/24       # (IP address pool for clients)
        rightdns=8.8.8.8,8.8.4.4                    #(DNS for clients)
        rightsendcert=never

/etc/ipsec.secrets  # server

# This file holds shared secrets or RSA private keys for authentication.

# RSA private key for this host, authenticating it to any other host 
# which knows the public part. : RSA "ipsecKey.pem" : RSA "strongswanKey.pem" # EAP bra : EAP "bra@ipsec.area23.at" # Pre Shared key : PSK "wonder_bra123$%&789=0AsdFJkl#"

ipsec client

client: add virtual interface to wlp1s0

ifconfig wlp1s0:1 10.160.1.4 netmask 255.255.255.0 broadcast 10.160.1.255 up

/etc/ipsec.conf # client

# ipsec.conf - strongSwan IPsec configuration file
# basic configuration

config setup
    strictcrlpolicy=no
    uniqueids = no
    charondebug="all"

conn sample-with-ca-cert
    # general 
    keyexchange=ikev2
    auto=start
    # this side of tunnel
    leftauth=secret      # Pre Shared key 
    leftid=10.16.235.154
    leftsourceip=%config
    # right other side of tunnel 
    right=187.33.151.48
    rightsubnet=10.160.0.4/24
    rightid=ipsec.area23.at
    rightauth=pubkey     # certificate pzblic rsa key

/etc/ipsec.secrets # client

#  This file holds shared secrets or RSA private keys for authentication.
# RSA private key for this host, authenticating it to any other host 
: RSA "ipsecKey.pem"
: RSA "strongswanKey.pem"
# EAP
bra : EAP "bra@ipsec.area23.at"
# Pre Shared key
: PSK "wonder_bra123$%&789=0AsdFJkl#"

 

YouTube very fast step through: https://www.youtube.com/watch?v=xw8wUxepvJ8

Keine Kommentare:

Kommentar veröffentlichen