Linux Cisco Ipsec Vpn Configuration
Linux Cisco Config :
86400 = 24hrs = Seconds
28800 = 8hrs = Seconds
Linux Ipsec Directory Conf :
conn commstest1
left= “Remote Peer Address”
leftnexthop= “Gateway Address”
leftsubnet= “Remote Subnet Address”
right= ”Local Wan Address”
rightsubnet= “Local Subnet Address”
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
ikelifetime=8h
keylife=24h
keyingtries=3
pfs=no
rekey=yes
auto=start
Set Keepalives :
dpdaction=restart
dpddelay=15
dpdtimeout=60
- dpddelay
- Set the delay (in seconds) between Dead Peer Dectection (RFC 3706) keepalives (R_U_THERE, R_U_THERE_ACK) that are sent for this connection (default 30 seconds). If dpdtimeout is set, but not dpddelay, dpddelay will be set to the default.
- dpdtimeout
- Set the length of time (in seconds) we will idle without hearing either an R_U_THERE poll from our peer, or an R_U_THERE_ACK reply. After this period has elapsed with no response and no traffic, we will declare the peer dead, and remove the SA (default 120 seconds). If dpddelay is set, but not dpdtimeout, dpdtimeout will be set to the default.
- dpdaction
- When a DPD enabled peer is declared dead, what action should be taken. hold (default) means the eroute will be put into %hold status, while clear means the eroute and SA with both be cleared. dpdaction=clear is really only usefull on the server of a Road Warrior config.
Set Domain-Name:
Fully qualified domain name in DNS of the right-hand side VPN device, which is preceded by an @ sign.
If DNS isn’t set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause
the VPN initialization to fail.
rightid=@commstest.co.uk
ipsec.secrets.conf
80.74.16.251 1.1.1.1 : PSK “commsvpn”
80.74.16.251 1.1.1.2 : PSK “commsvpn”
80.74.16.251 1.1.1.3 : PSK “commsvpn”
80.74.16.251 1.1.1.4 : PSK “commsvpn”
80.74.16.251 1.1.1.5 : PSK “commsvpn”
e.g : Template :
conn <<SITE_NAME>>
left=<<LOCAL_PHYSICAL_SERVER_PUBLC_IP_ADDRESS>>
leftnexthop=<<REMOTE_SITE_PUBLIC_ADDRESS>>
leftsubnet=<<LOCAL_PHYSICAL_SERVER_PUBLC_IP_ADDRESS>>
right=<<REMOTE_SITE_PUBLIC_ADDRESS>>
rightnexthop=<<LOCAL_PHYSICAL_SERVER_PUBLIC_IP_ADDRESS>>
rightsubnet=<<SITE_LAN_NETWORK_ADD>/<SUBNET_MASK>
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
ikelifetime=8h
keylife=24h
keyingtries=3
pfs=no
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=60