ich wollte mal anfangen ein VPN aufzubauen, aussehen soll es so:
Code: Alles auswählen
W2k-Rechner ---> Internet ----> Linux-Gateway -----> Lan
W2k-Rechner: dyn IP's
Linux:
DSL: dyn. IP
LanIP: 192.168.1.1
Subnet: 192.168.1.x/24
http://www.debianforum.de/forum/viewtop ... t=openswan
http://www.natecarlson.com/linux/ipsec-x509.php
[ipsec.conf ]
Code: Alles auswählen
version 2.0
config setup
interfaces="ipsec0=eth0"
virtual_private=%v4:10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16
conn %default
keyingtries=1
compress=yes
authby=rsasig
leftrsasigkey=%cert
rightrsasigkey=%cert
conn roadwarrior-net
leftsubnet=192.168.1.0/24
also=roadwarrior
conn roadwarrior
left=192.168.1.1
leftcert=test.pem
right=%any
rightsubnet=vhost:%no,%priv
auto=add
include /etc/ipsec.d/policies/no_oe.conf
Benutze ich die Konfigurationsdatei so wie Sie hier steht...sieht der Start von ipsec gut aus ( laut ipsec barf )..
[ipsec barf]
Code: Alles auswählen
Sep 12 17:25:08 server ipsec__plutorun: Starting Pluto subsystem...
Sep 12 17:25:09 server pluto[25463]: Starting Pluto (Openswan Version 2.1.5 X.509-1.4.8-1 PLUTO_USES_KEYRR)
Sep 12 17:25:09 server pluto[25463]: including NAT-Traversal patch (Version 0.6c)
Sep 12 17:25:09 server pluto[25463]: Using KLIPS IPsec interface code
Sep 12 17:25:09 server pluto[25463]: Changing to directory '/etc/ipsec.d/cacerts'
Sep 12 17:25:10 server pluto[25463]: loaded cacert file 'cacert.pem' (1196 bytes)
Sep 12 17:25:10 server pluto[25463]: Changing to directory '/etc/ipsec.d/crls'
Sep 12 17:25:10 server pluto[25463]: loaded crl file 'crl.pem' (487 bytes)
Sep 12 17:25:11 server pluto[25463]: loaded host cert file '/etc/ipsec.d/certs/test.pem' (3490 bytes)
Sep 12 17:25:12 server pluto[25463]: added connection description "roadwarrior-net"
Sep 12 17:25:13 server pluto[25463]: loaded host cert file '/etc/ipsec.d/certs/test.pem' (3490 bytes)
Sep 12 17:25:13 server pluto[25463]: added connection description "roadwarrior"
Sep 12 17:25:13 server pluto[25463]: attempt to redefine connection "roadwarrior"
Sep 12 17:25:13 server pluto[25463]: listening for IKE messages
Sep 12 17:25:13 server pluto[25463]: NAT-Traversal: ESPINUDP(1) not supported by kernel -- NAT-T disabled
Sep 12 17:25:13 server pluto[25463]: adding interface ipsec0/eth0 192.168.1.1
Sep 12 17:25:13 server pluto[25463]: NAT-Traversal: ESPINUDP(2) not supported by kernel -- NAT-T disabled
Sep 12 17:25:13 server pluto[25463]: adding interface ipsec0/eth0 192.168.1.1:4500
Sep 12 17:25:13 server pluto[25463]: loading secrets from "/etc/ipsec.secrets"
Sep 12 17:25:13 server pluto[25463]: loaded private key file '/etc/ipsec.d/private/test.key' (1639 bytes)
Komm da echt nicht weiter..hab ich da ein grundsätzliches Problem mit dem Szenario..oder irgedeinen Config-Fehler ???
gruss