Linux Cisco Ipsec Vpn Configuration

Linux Cisco Config :

86400  = 24hrs = Seconds
28800  = 8hrs    = Seconds

Linux Ipsec Directory Conf :

conn commstest1
left= “Remote Peer Address”
leftnexthop= “Gateway Address”
leftsubnet= “Remote Subnet Address”
right= ”Local Wan Address”
rightsubnet= “Local Subnet Address”
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
ikelifetime=8h
keylife=24h
keyingtries=3
pfs=no
rekey=yes
auto=start

Set Keepalives :

dpdaction=restart
dpddelay=15
dpdtimeout=60

dpddelay
Set the delay (in seconds) between Dead Peer Dectection (RFC 3706) keepalives (R_U_THERE, R_U_THERE_ACK) that are sent for this connection (default 30 seconds). If dpdtimeout is set, but not dpddelay, dpddelay will be set to the default.
dpdtimeout
Set the length of time (in seconds) we will idle without hearing either an R_U_THERE poll from our peer, or an R_U_THERE_ACK reply. After this period has elapsed with no response and no traffic, we will declare the peer dead, and remove the SA (default 120 seconds). If dpddelay is set, but not dpdtimeout, dpdtimeout will be set to the default.
dpdaction
When a DPD enabled peer is declared dead, what action should be taken. hold (default) means the eroute will be put into %hold status, while clear means the eroute and SA with both be cleared. dpdaction=clear is really only usefull on the server of a Road Warrior config.

Set Domain-Name:

Fully qualified domain name in DNS of the right-hand side VPN device, which is preceded by an @ sign.
If DNS isn’t set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause
the VPN initialization to fail.

rightid=@commstest.co.uk

ipsec.secrets.conf

80.74.16.251 1.1.1.1 : PSK “commsvpn”
80.74.16.251 1.1.1.2 : PSK “commsvpn”
80.74.16.251 1.1.1.3 : PSK “commsvpn”
80.74.16.251 1.1.1.4 : PSK “commsvpn”
80.74.16.251 1.1.1.5 : PSK “commsvpn”

e.g : Template :

conn <<SITE_NAME>>
left=<<LOCAL_PHYSICAL_SERVER_PUBLC_IP_ADDRESS>>
leftnexthop=<<REMOTE_SITE_PUBLIC_ADDRESS>>
leftsubnet=<<LOCAL_PHYSICAL_SERVER_PUBLC_IP_ADDRESS>>
right=<<REMOTE_SITE_PUBLIC_ADDRESS>>
rightnexthop=<<LOCAL_PHYSICAL_SERVER_PUBLIC_IP_ADDRESS>>
rightsubnet=<<SITE_LAN_NETWORK_ADD>/<SUBNET_MASK>
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
ikelifetime=8h
keylife=24h
keyingtries=3
pfs=no
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=60