upgraded ikev1 scenarios to 5.0.0
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
The roadwarrior <b>carol</b> sets up an IPsec tunnel connection to the gateway <b>moon</b>
|
||||
which in turn activates <b>Dead Peer Detection</b> (DPD) with a polling interval of 10 s.
|
||||
When the network connectivity between <b>carol</b> and <b>moon</b> is forcefully disrupted,
|
||||
<b>moon</b> clears the connection after the configured timeout of 30 s.
|
||||
<b>moon</b> clears the connection after 4 unsuccessful retransmits.
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
carol::ipsec status::STATE_MAIN_I4 (ISAKMP SA established)::YES
|
||||
carol::ipsec status 2> /dev/null::home.*INSTALLED, TUNNEL::YES
|
||||
moon:: ipsec status 2> /dev/null::rw.*INSTALLED, TUNNEL::YES
|
||||
carol::iptables -A INPUT -i eth0 -s PH_IP_MOON -j DROP::no output expected::NO
|
||||
moon::sleep 50::no output expected::NO
|
||||
moon::cat /var/log/auth.log::inserting event EVENT_DPD::YES
|
||||
moon::cat /var/log/auth.log::DPD: No response from peer - declaring peer dead::YES
|
||||
moon::cat /var/log/auth.log::DPD: Terminating all SAs using this connection::YES
|
||||
moon::cat /var/log/auth.log::DPD: Clearing connection::YES
|
||||
moon:: sleep 60::no output expected::NO
|
||||
moon:: cat /var/log/daemon.log::sending DPD request::YES
|
||||
moon::cat /var/log/daemon.log::DPD check timed out, enforcing DPD action::YES
|
||||
moon:: ipsec status 2> /dev/null::rw.*INSTALLED::NO
|
||||
|
||||
@@ -0,0 +1,21 @@
|
||||
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
||||
|
||||
config setup
|
||||
plutostart=no
|
||||
|
||||
conn %default
|
||||
ikelifetime=60m
|
||||
keylife=20m
|
||||
rekeymargin=3m
|
||||
keyingtries=1
|
||||
|
||||
conn home
|
||||
left=PH_IP_CAROL
|
||||
leftcert=carolCert.pem
|
||||
[email protected]
|
||||
leftfirewall=yes
|
||||
right=PH_IP_MOON
|
||||
[email protected]
|
||||
rightsubnet=10.1.0.0/16
|
||||
keyexchange=ikev1
|
||||
auto=add
|
||||
@@ -0,0 +1,5 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
charon {
|
||||
load = curl aes des sha1 sha2 md5 pem pkcs1 gmp random nonce x509 revocation hmac xcbc stroke kernel-netlink socket-default updown
|
||||
}
|
||||
@@ -1,10 +1,7 @@
|
||||
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
||||
|
||||
config setup
|
||||
plutodebug=control
|
||||
crlcheckinterval=180
|
||||
strictcrlpolicy=no
|
||||
charonstart=no
|
||||
plutostart=no
|
||||
|
||||
conn %default
|
||||
ikelifetime=60m
|
||||
@@ -14,7 +11,7 @@ conn %default
|
||||
keyexchange=ikev1
|
||||
dpdaction=clear
|
||||
dpddelay=10
|
||||
dpdtimeout=30
|
||||
dpdtimeout=45
|
||||
|
||||
conn rw
|
||||
left=PH_IP_MOON
|
||||
@@ -24,6 +21,3 @@ conn rw
|
||||
right=%any
|
||||
[email protected]
|
||||
auto=add
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
charon {
|
||||
load = curl aes des sha1 sha2 md5 pem pkcs1 gmp random nonce x509 revocation hmac xcbc stroke kernel-netlink socket-default
|
||||
}
|
||||
Reference in New Issue
Block a user