upgraded ikev2 scenarios to 5.0.0
This commit is contained in:
@@ -1,15 +1,15 @@
|
||||
carol::cat /var/log/daemon.log::server requested EAP_SIM authentication::YES
|
||||
carol::cat /var/log/daemon.log::allow mutual EAP-only authentication::YES
|
||||
carol::cat /var/log/daemon.log::authentication of 'moon.strongswan.org' with EAP successful::YES
|
||||
moon::cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
|
||||
moon::ipsec statusall::rw-eap.*ESTABLISHED.*[email protected]::YES
|
||||
carol::ipsec statusall::home.*ESTABLISHED::YES
|
||||
moon:: cat /var/log/daemon.log::authentication of '[email protected]' with EAP successful::YES
|
||||
moon:: ipsec status 2> /dev/null::rw-eap.*ESTABLISHED.*moon.strongswan.org.*[email protected]::YES
|
||||
carol::ipsec status 2> /dev/null::home.*ESTABLISHED.*[email protected].*moon.strongswan.org::YES
|
||||
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
||||
moon::tcpdump::IP carol.strongswan.org > moon.strongswan.org: ESP::YES
|
||||
moon::tcpdump::IP moon.strongswan.org > carol.strongswan.org: ESP::YES
|
||||
moon::cat /var/log/daemon.log::RADIUS authentication of '[email protected]' failed::YES
|
||||
moon::cat /var/log/daemon.log::EAP method EAP_SIM failed for peer [email protected]::YES
|
||||
moon::ipsec statusall::rw-eap.*ESTABLISHED.*[email protected]::NO
|
||||
dave::cat /var/log/daemon.log::received EAP_FAILURE, EAP authentication failed::YES
|
||||
dave::ipsec statusall::home.*ESTABLISHED::NO
|
||||
dave::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::NO
|
||||
moon:: cat /var/log/daemon.log::RADIUS authentication of '[email protected]' failed::YES
|
||||
moon:: cat /var/log/daemon.log::EAP method EAP_SIM failed for peer [email protected]::YES
|
||||
moon:: ipsec status 2> /dev/null::rw-eap.*ESTABLISHED.*moon.strongswan.org.*[email protected]::NO
|
||||
dave:: cat /var/log/daemon.log::received EAP_FAILURE, EAP authentication failed::YES
|
||||
dave:: ipsec status 2> /dev/null::home.*ESTABLISHED::NO
|
||||
dave:: ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::NO
|
||||
|
||||
@@ -17,5 +17,6 @@ conn home
|
||||
leftauth=eap
|
||||
right=PH_IP_MOON
|
||||
[email protected]
|
||||
rightauth=any
|
||||
rightsubnet=10.1.0.0/16
|
||||
auto=add
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
||||
|
||||
config setup
|
||||
strictcrlpolicy=no
|
||||
plutostart=no
|
||||
|
||||
conn %default
|
||||
|
||||
Reference in New Issue
Block a user