upgraded tnc scenarios to 5.0.0

This commit is contained in:
Andreas Steffen
2012-05-04 11:57:31 +02:00
parent a71f0f3bdc
commit 22bec9d4ae
42 changed files with 161 additions and 156 deletions
+2 -2
View File
@@ -10,8 +10,8 @@ moon::cat /var/log/daemon.log::added group membership 'allow'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES moon:: ipsec statusall 2> /dev/null::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES
moon::ipsec statusall::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES moon:: ipsec statusall 2> /dev/null::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO
dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -1,7 +1,6 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file # /etc/ipsec.conf - strongSwan IPsec configuration file
config setup config setup
strictcrlpolicy=no
plutostart=no plutostart=no
charondebug="tnc 3" charondebug="tnc 3"
@@ -1,7 +1,6 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file # /etc/ipsec.conf - strongSwan IPsec configuration file
config setup config setup
strictcrlpolicy=no
plutostart=no plutostart=no
conn %default conn %default
@@ -10,8 +10,8 @@ moon::cat /var/log/daemon.log::received RADIUS attribute Filter-Id: 'allow'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon:: cat /var/log/daemon.log::received RADIUS attribute Filter-Id: 'isolate'::YES moon:: cat /var/log/daemon.log::received RADIUS attribute Filter-Id: 'isolate'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES moon:: ipsec statusall 2> /dev/null::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES
moon::ipsec statusall::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES moon:: ipsec statusall 2> /dev/null::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO
dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES
@@ -1,7 +1,6 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file # /etc/ipsec.conf - strongSwan IPsec configuration file
config setup config setup
strictcrlpolicy=no
plutostart=no plutostart=no
conn %default conn %default
+2 -2
View File
@@ -10,8 +10,8 @@ moon::cat /var/log/daemon.log::added group membership 'allow'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES moon:: ipsec statusall 2> /dev/null::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES
moon::ipsec statusall::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES moon:: ipsec statusall 2> /dev/null::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO
dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -1,7 +1,6 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file # /etc/ipsec.conf - strongSwan IPsec configuration file
config setup config setup
strictcrlpolicy=no
plutostart=no plutostart=no
charondebug="tnc 3, imv 3" charondebug="tnc 3, imv 3"
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -1,7 +1,6 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file # /etc/ipsec.conf - strongSwan IPsec configuration file
config setup config setup
strictcrlpolicy=no
plutostart=no plutostart=no
charondebug="tnc 3, imv 3" charondebug="tnc 3, imv 3"
@@ -10,8 +10,8 @@ moon::cat /var/log/daemon.log::added group membership 'allow'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES moon:: ipsec statusall 2> /dev/null::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES
moon::ipsec statusall::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES moon:: ipsec statusall 2> /dev/null::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO
dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -1,7 +1,6 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file # /etc/ipsec.conf - strongSwan IPsec configuration file
config setup config setup
strictcrlpolicy=no
plutostart=no plutostart=no
charondebug="tnc 3, imv 2" charondebug="tnc 3, imv 2"
+2 -2
View File
@@ -10,8 +10,8 @@ moon::cat /var/log/daemon.log::added group membership 'allow'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES moon:: ipsec statusall 2> /dev/null::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES
moon::ipsec statusall::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES moon:: ipsec statusall 2> /dev/null::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO
dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -1,7 +1,6 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file # /etc/ipsec.conf - strongSwan IPsec configuration file
config setup config setup
strictcrlpolicy=no
plutostart=no plutostart=no
charondebug="tnc 3, imv 2" charondebug="tnc 3, imv 2"
+2 -3
View File
@@ -10,10 +10,9 @@ moon::cat /var/log/daemon.log::received RADIUS attribute Filter-Id: 'allow'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon:: cat /var/log/daemon.log::received RADIUS attribute Filter-Id: 'isolate'::YES moon:: cat /var/log/daemon.log::received RADIUS attribute Filter-Id: 'isolate'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES moon:: ipsec statusall 2>/dev/null::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES
moon::ipsec statusall::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES moon:: ipsec statusall 2>/dev/null::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO
dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES
dave:: ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_VENUS: icmp_seq=1::NO dave:: ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_VENUS: icmp_seq=1::NO
@@ -1,7 +1,6 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file # /etc/ipsec.conf - strongSwan IPsec configuration file
config setup config setup
strictcrlpolicy=no
plutostart=no plutostart=no
conn %default conn %default
@@ -10,8 +10,8 @@ moon::cat /var/log/daemon.log::added group membership 'allow'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES moon:: ipsec statusall 2> /dev/null::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES
moon::ipsec statusall::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES moon:: ipsec statusall 2> /dev/null::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO
dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -1,7 +1,6 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file # /etc/ipsec.conf - strongSwan IPsec configuration file
config setup config setup
strictcrlpolicy=no
plutostart=no plutostart=no
charondebug="tnc 3, imv 2" charondebug="tnc 3, imv 2"
+2 -2
View File
@@ -10,8 +10,8 @@ moon::cat /var/log/daemon.log::added group membership 'allow'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES moon:: ipsec statusall 2> /dev/null::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES
moon::ipsec statusall::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES moon:: ipsec statusall 2> /dev/null::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO
dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES
@@ -19,6 +19,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -19,6 +19,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -1,7 +1,6 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file # /etc/ipsec.conf - strongSwan IPsec configuration file
config setup config setup
strictcrlpolicy=no
plutostart=no plutostart=no
charondebug="tnc 2, imv 2" charondebug="tnc 2, imv 2"
+2 -2
View File
@@ -10,8 +10,8 @@ moon::cat /var/log/daemon.log::added group membership 'allow'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES moon:: ipsec statusall 2> /dev/null::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES
moon::ipsec statusall::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES moon:: ipsec statusall 2> /dev/null::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO
dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -1,7 +1,6 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file # /etc/ipsec.conf - strongSwan IPsec configuration file
config setup config setup
strictcrlpolicy=no
plutostart=no plutostart=no
charondebug="tnc 3, imv 2" charondebug="tnc 3, imv 2"
+2 -2
View File
@@ -18,8 +18,8 @@ moon::cat /var/log/daemon.log::final recommendation is 'isolate' and evaluation
moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES moon:: cat /var/log/daemon.log::added group membership 'isolate'::YES
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
moon:: cat /var/log/daemon.log::removed TNCCS Connection ID 2::YES moon:: cat /var/log/daemon.log::removed TNCCS Connection ID 2::YES
moon::ipsec statusall::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES moon:: ipsec statusall 2> /dev/null::rw-allow.*10.1.0.0/28 === 192.168.0.100/32::YES
moon::ipsec statusall::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES moon:: ipsec statusall 2> /dev/null::rw-isolate.*10.1.0.16/28 === 192.168.0.200/32::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO carol::ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_ALICE: icmp_seq=1::NO
dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES dave:: ping -c 1 PH_IP_VENUS::64 bytes from PH_IP_VENUS: icmp_seq=1::YES
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -18,6 +18,7 @@ conn home
leftfirewall=yes leftfirewall=yes
right=PH_IP_MOON right=PH_IP_MOON
[email protected] [email protected]
rightauth=any
rightsendcert=never rightsendcert=never
rightsubnet=10.1.0.0/16 rightsubnet=10.1.0.0/16
auto=add auto=add
@@ -1,7 +1,6 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file # /etc/ipsec.conf - strongSwan IPsec configuration file
config setup config setup
strictcrlpolicy=no
plutostart=no plutostart=no
charondebug="tnc 3, imv 3" charondebug="tnc 3, imv 3"