Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- root@OpenWrt:/usr/local/bin# uname -a
- Linux OpenWrt 3.3.8 #1 Sat Mar 23 16:49:30 UTC 2013 mips GNU/Linux
- root@OpenWrt:/usr/local/bin# opkg list-installed strongswan*
- strongswan - 5.0.0-1
- strongswan-charon - 5.0.0-1
- strongswan-default - 5.0.0-1
- strongswan-mod-aes - 5.0.0-1
- strongswan-mod-af-alg - 5.0.0-1
- strongswan-mod-attr - 5.0.0-1
- strongswan-mod-blowfish - 5.0.0-1
- strongswan-mod-constraints - 5.0.0-1
- strongswan-mod-des - 5.0.0-1
- strongswan-mod-dhcp - 5.0.0-1
- strongswan-mod-dnskey - 5.0.0-1
- strongswan-mod-eap-identity - 5.0.0-1
- strongswan-mod-eap-md5 - 5.0.0-1
- strongswan-mod-eap-mschapv2 - 5.0.0-1
- strongswan-mod-farp - 5.0.0-1
- strongswan-mod-fips-prf - 5.0.0-1
- strongswan-mod-gcrypt - 5.0.0-1
- strongswan-mod-gmp - 5.0.0-1
- strongswan-mod-hmac - 5.0.0-1
- strongswan-mod-kernel-netlink - 5.0.0-1
- strongswan-mod-md4 - 5.0.0-1
- strongswan-mod-md5 - 5.0.0-1
- strongswan-mod-nonce - 5.0.0-1
- strongswan-mod-openssl - 5.0.0-1
- strongswan-mod-pem - 5.0.0-1
- strongswan-mod-pgp - 5.0.0-1
- strongswan-mod-pkcs1 - 5.0.0-1
- strongswan-mod-pkcs11 - 5.0.0-1
- strongswan-mod-pkcs8 - 5.0.0-1
- strongswan-mod-pubkey - 5.0.0-1
- strongswan-mod-random - 5.0.0-1
- strongswan-mod-resolve - 5.0.0-1
- strongswan-mod-revocation - 5.0.0-1
- strongswan-mod-sha1 - 5.0.0-1
- strongswan-mod-sha2 - 5.0.0-1
- strongswan-mod-socket-default - 5.0.0-1
- strongswan-mod-stroke - 5.0.0-1
- strongswan-mod-test-vectors - 5.0.0-1
- strongswan-mod-updown - 5.0.0-1
- strongswan-mod-x509 - 5.0.0-1
- strongswan-mod-xauth-eap - 5.0.0-1
- strongswan-mod-xauth-generic - 5.0.0-1
- strongswan-mod-xcbc - 5.0.0-1
- strongswan-utils - 5.0.0-1
- root@OpenWrt:/usr/local/bin# ipsec statusall
- Status of IKE charon daemon (strongSwan 5.0.0, Linux 3.3.8, mips):
- uptime: 21 minutes, since Oct 26 04:05:32 2013
- malloc: sbrk 139264, mmap 0, used 123944, free 15320
- worker threads: 6 of 16 idle, 9/1/0/0 working, job queue: 0/0/0/0, scheduled: 0
- loaded plugins: charon test-vectors pkcs11 aes des blowfish sha1 sha2 md4 md5 random nonce x509 revocation constraints pubkey pkcs1 pkcs8 pgp dnskey pem openssl gcrypt af-alg fips-prf gmp xcbc hmac attr kernel-netlink resolve socket-default farp stroke updown eap-identity eap-md5 eap-mschapv2 xauth-generic xauth-eap dhcp
- Listening IP addresses:
- 192.168.1.1
- 116.xx.xx.253
- Connections:
- Security Associations (0 up, 0 connecting):
- none
- root@OpenWrt:/usr/local/bin#
- root@OpenWrt:/usr/local/bin#logread
- Oct 26 04:31:12 OpenWrt daemon.info syslog: 05[NET] received packet: from 182.xxx.xx.111[45149] to 116.xxx.xxx.253[500]
- Oct 26 04:31:12 OpenWrt daemon.info syslog: 05[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ]
- Oct 26 04:31:12 OpenWrt daemon.info syslog: 05[IKE] no IKE config found for 116.xxx.xxx.253...182.xxx.xxx.111, sending NO_PROPOSAL_CHOSEN
- Oct 26 04:31:12 OpenWrt daemon.info syslog: 05[ENC] generating IKE_SA_INIT response 0 [ N(NO_PROP) ]
- Oct 26 04:31:12 OpenWrt daemon.info syslog: 05[NET] sending packet: from 116.xxx.xxx.253[500] to 182.xxx.xxx.111[45149]
- Oct 26 04:31:13 OpenWrt daemon.info syslog: 04[NET] received packet: from 182.xxx.xxx.111[45149] to 116.xxx.xxx.253[500]
- Oct 26 04:31:13 OpenWrt daemon.info syslog: 04[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ]
- Oct 26 04:31:13 OpenWrt daemon.info syslog: 04[IKE] no IKE config found for 116.xxx.xxx.253...182.xxx.xxx.111, sending NO_PROPOSAL_CHOSEN
- Oct 26 04:31:13 OpenWrt daemon.info syslog: 04[ENC] generating IKE_SA_INIT response 0 [ N(NO_PROP) ]
- Oct 26 04:31:13 OpenWrt daemon.info syslog: 04[NET] sending packet: from 116.xxx.xxx.253[500] to 182.xxx.xxx.111[45149]
- root@OpenWrt:/usr/local/bin#
- root@OpenWrt:/usr/local/bin# cat /etc/ipsec.conf
- # ipsec.conf - strongSwan IPsec configuration file
- # basic configuration
- config setup
- # plutodebug=all
- # crlcheckinterval=600
- # strictcrlpolicy=yes
- # cachecrls=yes
- # nat_traversal=yes
- # charonstart=no
- # plutostart=no
- #
- conn %default
- # left=%any
- # leftsubnet=0.0.0.0/0
- # leftfirewall=yes
- # leftcert=serverCert.pem
- # right=%any
- # rightsubnet=192.168.0.0/24
- # rightsourceip=%dhcp
- conn ikev2
- keyexchange=ikev2
- left=%any
- leftsubnet=0.0.0.0/0
- leftsourceip=192.168.1.1
- leftauth=pubkey
- leftcert=serverCert.pem
- right=%any
- rightsourceip=%dhcp
- rightauth=pubkey
- root@OpenWrt:/usr/local/bin# cat /etc/strongswan.conf
- # strongswan.conf - strongSwan configuration file
- charon {
- dns1 = 192.168.1.1
- threads = 16
- plugins {
- dhcp {
- server = 192.168.1.1
- }
- }
- }
- pluto {
- }
- libstrongswan {
- # set to no, the DH exponent size is optimized
- # dh_exponent_ansi_x9_42 = no
- }
- root@OpenWrt:/usr/local/bin# cat /etc/ipsec.secrets
- # /etc/ipsec.secrets - strongSwan IPsec secrets file
- : RSA serverKey.pem
- guestuser : XAUTH "youkoso"
- iPhone5 : XAUTH "kakakaka"
- android : EAP "hogehoge"
Advertisement
Add Comment
Please, Sign In to add comment