Server uses self signed ROOT CA and a signed ipsec certificate with public/private key for authentication.
Client uses Pre-Shared-Key PSK and servers certificate public RSA key.
ipsec server
Generate ROOT CA and ipsec rsa priv keys and certificates
#/usr/bin/bash
# delete all old certs priv keys and certificate requests rm -f strongswanKey.pem strongswanCert.pem ipsecKey.pem ipsecReq.pem ipsecCert.pem *.pem
# generate snake oil ROOT CA pki --gen --type ed25519 --outform pem > strongswanKey.pem pki --self --ca --lifetime 3652 --in strongswanKey.pem \ --dn "C=CH, O=strongSwan, CN=strongSwan Root CA" \ --outform pem > strongswanCert.pem # print snakeoil ROOT CA pki --print --in strongswanCert.pem
# generate ipsec private key and certificate pki --gen --type rsa --size 3072 --outform pem > ipsecKey.pem # pki --gen --type ed25519 --outform pem > ipsecKey.pem pki --req --type priv --in ipsecKey.pem \ --dn "C=AT, O=area23, CN=ipsec.area23.at" \ --san ipsec.area23.at --outform pem > ipsecReq.pem pki --issue --cacert strongswanCert.pem --cakey strongswanKey.pem \ --type pkcs10 --in ipsecReq.pem --serial 01 --lifetime 1826 \ --outform pem > ipsecCert.pem # print ipsec certificate pki --print --in ipsecCert.pem # copy certs and priv keys cp strongswanCert.pem /etc/ipsec.d/cacerts/. cp *Cert.pem /etc/ipsec.d/certs/. cp *Key.pem /etc/ipsec.d/private/.
server: add virtual interface to eth0
ifconfig eth0:1 10.160.0.4 netmask 255.255.255.0 broadcast 10.160.0.255 up
/etc/ipsec.conf # server
# ipsec.conf - strongSwan IPsec configuration file
# basic configuration
config setup
strictcrlpolicy=no
charondebug="all"
uniqueids=no
ca strongswan #define alternative CRL distribution point
cacert=strongswanCert.pem # self snake oil generated ROOT CA
auto=add
conn %default
keyingtries=1
keyexchange=ikev2
conn ipsec-ikev2-vpn
auto=add
authby=xauthrsasig
xauth=server
compress=no
type=tunnel
keyexchange=ikev2
fragmentation=yes
forceencaps=yes
# ike=aes256-sha1-modp1024,3des-sha1-modp1024!
# esp=aes256-sha1,3des-sha1!
dpdaction=clear # configure dead-peer detection
dpddelay=300s
rekey=no
# configure the server (left) side IPSec parameters
left=%any
leftid=ipsec.area23.at
leftcert=/etc/ipsec.d/certs/ipsecCert.pem # ipsecCert generated from ROOT CA
leftsendcert=always
leftsubnet=10.160.0.4/24
# configure the client (right) side IPSec parameters like private IPs
rightid=%any
# rightid="C=AT, O=area23, CN=ipsec.area23.at"
# rightauth=eap-mschapv2
# rightauth=pubkey
rightauth=secret # pre shared key
# rightcert=strongswanCert.pem
rightsourceip=10.160.1.0/24 # opposite subnet
rightsubnet=10.160.1.0/24 # (IP address pool for clients)
rightdns=8.8.8.8,8.8.4.4 #(DNS for clients)
rightsendcert=never
/etc/ipsec.secrets # server
# This file holds shared secrets or RSA private keys for authentication. # RSA private key for this host, authenticating it to any other host
# which knows the public part. : RSA "ipsecKey.pem" : RSA "strongswanKey.pem" # EAP bra : EAP "bra@ipsec.area23.at" # Pre Shared key : PSK "wonder_bra123$%&789=0AsdFJkl#"
ipsec client
client: add virtual interface to wlp1s0
ifconfig wlp1s0:1 10.160.1.4 netmask 255.255.255.0 broadcast 10.160.1.255 up
/etc/ipsec.conf # client
# ipsec.conf - strongSwan IPsec configuration file
# basic configuration
config setup
strictcrlpolicy=no
uniqueids = no
charondebug="all"
conn sample-with-ca-cert
# general
keyexchange=ikev2
auto=start
# this side of tunnel
leftauth=secret # Pre Shared key
leftid=10.16.235.154
leftsourceip=%config
# right other side of tunnel
right=187.33.151.48
rightsubnet=10.160.0.4/24
rightid=ipsec.area23.at
rightauth=pubkey # certificate pzblic rsa key
/etc/ipsec.secrets # client
# This file holds shared secrets or RSA private keys for authentication. # RSA private key for this host, authenticating it to any other host : RSA "ipsecKey.pem" : RSA "strongswanKey.pem" # EAP bra : EAP "bra@ipsec.area23.at" # Pre Shared key : PSK "wonder_bra123$%&789=0AsdFJkl#"
YouTube very fast step through: https://www.youtube.com/watch?v=xw8wUxepvJ8

Keine Kommentare:
Kommentar veröffentlichen