Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Desktop(artyom-H97-D3H):
- artyom@artyom-H97-D3H:~$ ping6 fd00:7306:6bc5::1
- PING fd00:7306:6bc5::1(fd00:7306:6bc5::1) 56 data bytes
- 64 bytes from fd00:7306:6bc5::1: icmp_seq=1 ttl=63 time=4.13 ms
- From fd7a:46c:f954:0:76d4:35ff:fef8:9f90 icmp_seq=2 Destination unreachable: Address unreachable
- From fd7a:46c:f954:0:76d4:35ff:fef8:9f90 icmp_seq=3 Destination unreachable: Address unreachable
- From fd7a:46c:f954:0:76d4:35ff:fef8:9f90 icmp_seq=4 Destination unreachable: Address unreachable
- 64 bytes from fd00:7306:6bc5::1: icmp_seq=5 ttl=63 time=7.73 ms
- From fd7a:46c:f954:0:76d4:35ff:fef8:9f90 icmp_seq=6 Destination unreachable: Address unreachable
- From fd7a:46c:f954:0:76d4:35ff:fef8:9f90 icmp_seq=7 Destination unreachable: Address unreachable
- From fd7a:46c:f954:0:76d4:35ff:fef8:9f90 icmp_seq=8 Destination unreachable: Address unreachable
- 64 bytes from fd00:7306:6bc5::1: icmp_seq=9 ttl=63 time=4.05 ms
- From fd7a:46c:f954:0:76d4:35ff:fef8:9f90 icmp_seq=10 Destination unreachable: Address unreachable
- From fd7a:46c:f954:0:76d4:35ff:fef8:9f90 icmp_seq=11 Destination unreachable: Address unreachable
- From fd7a:46c:f954:0:76d4:35ff:fef8:9f90 icmp_seq=12 Destination unreachable: Address unreachable
- 64 bytes from fd00:7306:6bc5::1: icmp_seq=13 ttl=63 time=9.09 ms
- ^C
- --- fd00:7306:6bc5::1 ping statistics ---
- 13 packets transmitted, 4 received, +9 errors, 69% packet loss, time 12197ms
- rtt min/avg/max/mdev = 4.054/6.253/9.095/2.213 ms
- artyom@artyom-H97-D3H:~$ sudo ip -6 addr
- 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 state UNKNOWN qlen 1
- inet6 ::1/128 scope host
- valid_lft forever preferred_lft forever
- 2: eno1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
- inet6 fd7a:46c:f954:0:76d4:35ff:fef8:9f90/64 scope global mngtmpaddr dynamic
- valid_lft forever preferred_lft forever
- inet6 2002:b035:e00d:0:76d4:35ff:fef8:9f90/64 scope global mngtmpaddr dynamic
- valid_lft forever preferred_lft forever
- inet6 fe80::76d4:35ff:fef8:9f90/64 scope link
- valid_lft forever preferred_lft forever
- artyom@artyom-H97-D3H:~$ sudo ip -6 neighbor
- fe80::21e:6ff:fecb:1923 dev eno1 lladdr 00:1e:06:cb:19:23 router STALE
- fe80::12fe:edff:fee5:bd00 dev eno1 lladdr 10:fe:ed:e5:bd:00 router STALE
- fd7a:46c:f954::110 dev eno1 lladdr 00:1e:06:cb:19:23 router STALE
- fd00:7306:6bc5::1 dev eno1 FAILED
- 2002:b035:e00d:ff00::ff dev eno1 lladdr 00:1e:06:cb:19:23 STALE
- artyom@artyom-H97-D3H:~$ sudo ip -6 route
- 2002:b035:e00d::/64 dev eno1 proto kernel metric 256 mtu 1280 pref medium
- 2002:b035:e00d:ff00::/64 via fe80::21e:6ff:fecb:1923 dev eno1 proto ra metric 1024 expires 1485sec pref medium
- 2002:b035:e00d::/48 via fe80::12fe:edff:fee5:bd00 dev eno1 proto ra metric 1024 pref medium
- fd7a:46c:f954::/64 dev eno1 proto kernel metric 256 mtu 1280 pref medium
- fd7a:46c:f954::/48 via fe80::12fe:edff:fee5:bd00 dev eno1 proto ra metric 1024 pref medium
- fe80::/64 dev eno1 proto kernel metric 256 mtu 1280 pref medium
- default via fe80::12fe:edff:fee5:bd00 dev eno1 proto ra metric 1024 expires 65409sec mtu 1280 hoplimit 64 pref medium
- VPN server(odroid):
- [artyom@odroid ~]$ ping -6 -c 8 fd00:7306:6bc5::1
- PING fd00:7306:6bc5::1(fd00:7306:6bc5::1) 56 data bytes
- 64 bytes from fd00:7306:6bc5::1: icmp_seq=1 ttl=64 time=4.76 ms
- 64 bytes from fd00:7306:6bc5::1: icmp_seq=2 ttl=64 time=2.91 ms
- 64 bytes from fd00:7306:6bc5::1: icmp_seq=3 ttl=64 time=6.99 ms
- 64 bytes from fd00:7306:6bc5::1: icmp_seq=4 ttl=64 time=5.44 ms
- 64 bytes from fd00:7306:6bc5::1: icmp_seq=5 ttl=64 time=7.38 ms
- 64 bytes from fd00:7306:6bc5::1: icmp_seq=6 ttl=64 time=5.33 ms
- 64 bytes from fd00:7306:6bc5::1: icmp_seq=7 ttl=64 time=3.09 ms
- 64 bytes from fd00:7306:6bc5::1: icmp_seq=8 ttl=64 time=3.96 ms
- --- fd00:7306:6bc5::1 ping statistics ---
- 8 packets transmitted, 8 received, 0% packet loss, time 7010ms
- rtt min/avg/max/mdev = 2.914/4.989/7.388/1.546 ms
- [artyom@odroid ~]$ sudo ip -6 addr
- 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536
- inet6 ::1/128 scope host
- valid_lft forever preferred_lft forever
- 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qlen 1000
- inet6 2002:b035:e00d:0:4cc2:9b49:6ca5:dcc3/64 scope global
- valid_lft forever preferred_lft forever
- inet6 fd7a:46c:f954::110/128 scope global
- valid_lft forever preferred_lft forever
- inet6 fd7a:46c:f954:0:996:caf:7824:6b02/64 scope global
- valid_lft forever preferred_lft forever
- inet6 fe80::21e:6ff:fecb:1923/64 scope link
- valid_lft forever preferred_lft forever
- 3: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500
- inet6 fe80::42:ff:fe81:c862/64 scope link
- valid_lft forever preferred_lft forever
- [artyom@odroid ~]$ sudo ip -6 neigh
- fe80::21e:6ff:fecb:1923 dev eth0 lladdr 00:1e:06:cb:19:23 router STALE
- fd7a:46c:f954:0:20d5:2bda:e015:2ca5 dev eth0 lladdr 34:13:e8:2f:49:ff STALE
- fe80::8d5a:30a6:cfd8:cba0 dev docker0 lladdr 02:42:00:81:c8:62 STALE
- fd7a:46c:f954:0:5893:a1bd:ecf0:7d66 dev eth0 lladdr 34:13:e8:2f:49:ff STALE
- fe80::20c:e7ff:fe01:8177 dev eth0 lladdr 00:0c:e7:01:81:77 STALE
- fe80::9410:4323:5ba9:492f dev eth0 lladdr 74:d4:35:f8:9f:90 STALE
- fd7a:46c:f954:0:f0b1:2a30:f392:6334 dev eth0 lladdr cc:fa:00:ab:87:f0 STALE
- fe80::34bc:b02a:489:b1ee dev eth0 lladdr 3c:83:75:ae:b5:98 STALE
- fe80::3613:e8ff:fe2f:49ff dev eth0 lladdr 34:13:e8:2f:49:ff STALE
- fd7a:46c:f954:0:8d4f:8602:96a5:821e dev eth0 lladdr 34:13:e8:2f:49:ff STALE
- fd7a:46c:f954::1 dev eth0 lladdr 10:fe:ed:e5:bd:00 router STALE
- 2002:b035:e00d::1 dev eth0 lladdr 10:fe:ed:e5:bd:00 router STALE
- fd7a:46c:f954:0:34ca:aae5:630:d44f dev eth0 FAILED
- fe80::42:ff:fe81:c862 dev docker0 lladdr 02:42:00:81:c8:62 STALE
- fe80::76d4:35ff:fef8:9f90 dev eth0 lladdr 74:d4:35:f8:9f:90 STALE
- fe80::a7cc:bbb:98b5:a7e2 dev eth0 lladdr 34:13:e8:2f:49:ff STALE
- fe80::12fe:edff:fee5:bd00 dev eth0 lladdr 10:fe:ed:e5:bd:00 router STALE
- fe80::48e6:cf19:e734:4880 dev eth0 lladdr 74:2f:68:ec:1d:01 STALE
- fd7a:46c:f954:f954::1 dev eth0 FAILED
- fd7a:46c:f954:0:60c5:9e48:d302:d5b5 dev eth0 lladdr 74:d4:35:f8:9f:90 STALE
- fd7a:46c:f954::100 dev eth0 FAILED
- fd7a:46c:f954:0:2151:3c65:99b:1f77 dev eth0 lladdr 74:d4:35:f8:9f:90 STALE
- fd7a:46c:f954:0:4c17:c11c:b800:d1cd dev eth0 lladdr cc:fa:00:ab:87:f0 STALE
- fd7a:46c:f954:0:c8a5:968f:89b7:8108 dev eth0 lladdr cc:fa:00:ab:87:f0 STALE
- fd7a:46c:f954:0:76d4:35ff:fef8:9f90 dev eth0 lladdr 74:d4:35:f8:9f:90 REACHABLE
- fd7a:46c:f954:0:cdc3:336:9ca:4862 dev eth0 lladdr 74:d4:35:f8:9f:90 STALE
- fd7a:46c:f954:0:bda2:eeef:57f2:29ef dev eth0 lladdr cc:fa:00:ab:87:f0 STALE
- 2002:b035:e00d:0:76d4:35ff:fef8:9f90 dev eth0 lladdr 74:d4:35:f8:9f:90 STALE
- fd7a:46c:f954:0:f417:a266:1ad7:c9c0 dev eth0 FAILED
- fe80::cefa:ff:feab:87f0 dev eth0 lladdr cc:fa:00:ab:87:f0 STALE
- [artyom@odroid ~]$ sudo ip -6 route
- 2002:b035:e00d::/64 dev eth0 proto kernel metric 202 mtu 1280
- 2002:b035:e00d::/64 dev eth0 proto kernel metric 256
- fd7a:46c:f954::110 dev eth0 proto kernel metric 256
- fd7a:46c:f954::/64 dev eth0 proto kernel metric 202 mtu 1280
- fd7a:46c:f954::/64 dev eth0 proto kernel metric 256
- fe80::/64 dev eth0 proto kernel metric 256
- fe80::/64 dev docker0 proto kernel metric 256
- default via fe80::12fe:edff:fee5:bd00 dev eth0 metric 202 mtu 1280
- [artyom@odroid ~]$ sudo swanctl -v
- strongSwan swanctl 5.5.2
- [artyom@odroid ~]$ sudo swanctl -l
- work: #2, ESTABLISHED, IKEv2, ba05118e41b6b0ee_i cbab7f3248286584_r*
- local 'CN=vpn.h31.ishere.ru' @ 192.168.1.110[4500]
- remote 'work' @ 195.209.231.150[4500] [192.168.1.120 fd00:7306:6bc5::1]
- AES_GCM_16-256/PRF_HMAC_SHA2_256/MODP_2048
- established 571s ago, reauth in 9350s
- work: #2, reqid 2, INSTALLED, TUNNEL-in-UDP, ESP:AES_CTR-128/HMAC_SHA1_96
- installed 571s ago, rekeying in 1997s, expires in 3029s
- in c6a67c89, 3818 bytes, 30 packets, 32s ago
- out cf1bac8f, 2496 bytes, 24 packets, 32s ago
- local 192.168.1.110/32 192.168.1.200/32 ::/0
- remote 192.168.1.120/32 fd00:7306:6bc5::1/128
- [artyom@odroid ~]$ sudo swanctl -L
- work: IKEv2, reauthentication every 10260s, no rekeying
- local: %any
- remote: %any
- local public key authentication:
- id: CN=vpn.h31.ishere.ru
- certs: CN=vpn.h31.ishere.ru
- remote public key authentication:
- id: work
- work: TUNNEL, rekeying every 3060s
- local: 192.168.1.0/24 ::/0
- remote: dynamic
- [artyom@odroid ~]$ cat /etc/ipsec.conf
- # ipsec.conf - strongSwan IPsec configuration file
- # basic configuration
- config setup
- # strictcrlpolicy=yes
- # uniqueids = no
- # Add connections here.
- conn %default
- keyexchange=ikev2
- ike=aes256gcm16-sha256-modp2048,aes256-aes128-sha256-sha1-modp2048-modp4096-modp1024!
- esp=aes128ctr-sha1-sha256-modp2048!
- fragmentation=yes
- dpdaction=clear
- dpddelay=35s
- dpdtimeout=300s
- # left - local (server) side
- left=%any
- leftauth=pubkey
- leftcert=vpn.h31.ishere.ru.crt
- leftsendcert=always
- leftsubnet=0.0.0.0/0,::/0
- leftfirewall = yes
- # right - remote (client) side
- right=%any
- rightdns=
- rightauth=pubkey
- rightsourceip=%dhcp
- conn work
- rightid=work
- rightcert=work.crt
- leftsubnet=192.168.1.1/24,::/0
- rightsourceip=%dhcp,fd00:7306:6bc5::1
- auto=add
- Work(artyom-MSI):
- artyom@artyom-MSI:~$ sudo ipsec statusall
- Status of IKE charon daemon (strongSwan 5.3.5, Linux 4.4.0-72-generic, x86_64):
- uptime: 5 hours, since Apr 29 16:14:46 2017
- malloc: sbrk 2703360, mmap 0, used 407152, free 2296208
- worker threads: 11 of 16 idle, 5/0/0/0 working, job queue: 0/0/0/0, scheduled: 12
- loaded plugins: charon test-vectors aes rc2 sha1 sha2 md4 md5 random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pkcs8 pkcs12 pgp dnskey sshkey pem openssl fips-prf gmp agent xcbc hmac gcm attr kernel-netlink resolve socket-default connmark stroke updown
- Listening IP addresses:
- 192.168.1.75
- 10.140.20.1
- Connections:
- ikev2-rw: %any...vpn.h31.ishere.ru IKEv1/2
- ikev2-rw: local: [work] uses public key authentication
- ikev2-rw: cert: "CN=work"
- ikev2-rw: remote: [vpn.h31.ishere.ru] uses public key authentication
- ikev2-rw: child: dynamic === 192.168.1.110/32 192.168.1.200/32 ::/0 TUNNEL
- Security Associations (1 up, 0 connecting):
- ikev2-rw[7]: ESTABLISHED 13 minutes ago, 192.168.1.75[work]...176.53.224.13[CN=vpn.h31.ishere.ru]
- ikev2-rw[7]: IKEv2 SPIs: eeb0b6418e1105ba_i* 84652848327fabcb_r, public key reauthentication in 2 hours
- ikev2-rw[7]: IKE proposal: AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_2048
- ikev2-rw{12}: INSTALLED, TUNNEL, reqid 7, ESP in UDP SPIs: cf1bac8f_i c6a67c89_o
- ikev2-rw{12}: AES_CTR_128/HMAC_SHA1_96, 12733 bytes_i (135 pkts, 0s ago), 12639 bytes_o (98 pkts, 20s ago), rekeying in 32 minutes
- ikev2-rw{12}: 192.168.1.120/32 fd00:7306:6bc5::1/128 === 192.168.1.110/32 192.168.1.200/32 ::/0
- artyom@artyom-MSI:~$ cat /etc/ipsec.conf
- # ipsec.conf - strongSwan IPsec configuration file
- # basic configuration
- config setup
- # strictcrlpolicy=yes
- # uniqueids = no
- # Add connections here.
- conn ikev2-rw
- right=vpn.h31.ishere.ru
- dpdaction=restart
- dpddelay=0
- rightid=%vpn.h31.ishere.ru
- rightsubnet=192.168.1.110/32,192.168.1.200/32,::/0
- rightauth=pubkey
- rightfirewall=yes
- leftid=work
- leftsourceip=%config4,%config6
- leftauth=pubkey
- leftfirewall=yes
- leftcert=work.crt
- ike=aes256gcm16-sha256-modp2048!
- esp=aes128ctr-sha1-sha256-modp2048!
- auto=start
- closeaction=restart
Advertisement
Add Comment
Please, Sign In to add comment