Networking-Blog

My WordPress Blog

Linux: OpenSwan VPN

Below is an example OpenSwan configuration file with a brief explanation of each line.

conn <connname>

type=tunnel
the type of the connection; currently the accepted values are tunnel (the default) signifying a host-to-host, host-to-subnet, or subnet-to-subnet tunnel; transport, signifying host-to-host transport mode; passthrough, signifying that no IPsec processing should be done at all; drop, signifying that packets should be discarded; and reject, signifying that packets should be discarded and a diagnostic ICMP returned.

authby=secret
How the two security gateways should authenticate each other; acceptable values are “secret” for shared secrets, “rsasig” for RSA digital signatures (the default), secret|rsasig for either, and never if negotiation is never to be attempted or accepted (useful for shunt-only conns). Digital signatures are superior in every way to shared secrets.

auth=esp
Whether authentication should be done as part of ESP encryption, or separately using the AH protocol; acceptable values are esp (the default) and ah.

esp=3des-md5-96
(encrypted Secure Payload) defines what cipher, hash and PFSGroup you wish to use for the connection.

  # ONLY allow AES 256bit w/MD5
  esp=!aes256-md5
  # Prefer aes, 3des, blowfish in that order, but permit other combinations
  esp=aes,3des,blowfish
  # Only permit AES or 3DES with MD5 or SHA1
  esp=!aes-md5,!aes-sha1,!3des-md5,!3des-sha1

left=80.74.16.163
(required) the IP address of the left participant’s pub-lic-network interface, in any form accepted byipsec_ttoaddr(3) or one of several magic values.

leftsubnet=192.168.0.0/16

private subnet behind the left participant, expressed as network/netmask (actually, any form acceptable to ipsec_ttosubnet(3)); if omitted, essentially assumed to be left/32, signifying that the left end of the connection goes to the left participant only

right=85.234.71.226

(required) the IP address of the right participant’s pub-lic-network interface.

rightsubnet=192.168.1.0/24

private subnet behind the right participant, expressed as network/netmask.

keyingtries=3

how many attempts (a whole number or %forever) should be made to negotiate a connection, or a replacement for one, before giving up (default %forever). The value %forever means “never give up” (obsolete: this can be written 0). Relevant only locally, other end need not agree on it.

pfs=no
Whether Perfect Forward Secrecy of keys is desired on the connection’s keying channel (with PFS, penetration of the key-exchange protocol does not compromise keys negotiated earlier); acceptable values are yes (the default) and no.

rekey=yes

whether a connection should be renegotiated when it is about to expire; acceptable values are yes (the default) and no. The two ends need not agree, but while a value of no prevents Pluto from requesting renegotiation, it does not prevent responding to renegotiation requested from the other end, so no will be largely ineffective unless both ends agree on it.

auto=start
auto starts the vpn tunnel on a ipsec service restart.

keyexchange=ike

method of key exchange; the default and currently the only accepted value is ike

ikelifetime=1h

How long the connection to the other key-management daemon should last before being renegotiated; acceptable values as for keylife (default set by ipsec_pluto(8), currently 1h, maximum 8h).

keylife=8h

how long a particular instance of a connection (a set of encryption/authentication keys for user packets) should last, from successful negotiation to expiry; acceptable values are an integer optionally followed by s (a time in seconds) or a decimal number followed by m, h, or d (a time in minutes, hours, or days respectively) (default 8.0h, maximum 24h). Normally, the connection is renegotiated (via the keying channel) before it expires. The two ends need not exactly agree on keylife, although if they do not, there will be some clutter of superseded connections on the end which thinks the lifetime is longer.

dpdaction=restart

When a DPD enabled peer is declared dead, what action should be taken. hold (default) means the eroute will be put into %hold status, while clear means the eroute and SA with both be cleared. dpdaction=clear is really only usefull on the server of a Road Warrior config.

dpddelay=30

Set the delay (in seconds) between Dead Peer Dectection (RFC 3706) keepalives (R_U_THERE, R_U_THERE_ACK) that are sent for this connection (default 30 seconds). If dpdtimeout is set, but not dpddelay, dpddelay will be set to the default.

dpdtimeout=120
Set the length of time (in seconds) we will idle without hearing either an R_U_THERE poll from our peer, or an R_U_THERE_ACK reply. After this period has elapsed with no response and no traffic, we will declare the peer dead, and remove the SA (default 120 seconds). If dpddelay is set, but not dpdtimeout, dpdtimeout will be set to the default.

Cisco Linux IPSEC VPN

Create hq additional vpn profile on the vm :

conn comms1
left=90.90.90.90
leftsubnet=192.168.0.0/16
rightid=@commshq.networks.ww
right=217.33.177.219
rightsubnet=172.16.30.0/24
authby=secret
ikelifetime=1h
keylife=24h
keyingtries=3
rekey=yes
auto=start
esp=3des-md5-96
pfs=yes

Create comms2 additional vpn profile on the vm :

conn comms2
left=90.90.90.90
leftsubnet=172.16.30.0/24
right=216.12.12.12
rightsubnet=192.168.49.0/24
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
ikelifetime=1h
keylife=24h
keyingtries=3
pfs=yes
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=30

Added additional vpn on hq router :

ip access-list extended VPN
remark LAN_TO_LAN
permit ip 172.16.30.0 0.0.0.255 192.168.0.0 0.0.255.255

Added additional vpn on comms2 router :

ip access-list extended VPN
remark LAN_TO_LAN
permit ip 192.168.49.0 0.0.0.255 172.16.30.0 0.0.0.255

Added additional rule to VM on the FORWARD chain to allow traffic
from 192.168.0.0 to 172.16.30.0 :

sudo iptables -I FORWARD 7 -s 192.168.0.0/255.255.0.0 -d 172.16.30.0/255.255.255.0 -j ACCEPT
!
Added additional rule to VM on the FORWARD chain to allow traffic
from
172.16.30.0 to
192.168.0.0 :

sudo iptables -I FORWARD 7 -s 172.16.30.0/255.255.255.0 -d 192.168.0.0/255.255.0.0 -j ACCEPT

Linux Ipsec VPN Parameters

Parameters of the /etc/ipsec.conf file

Left – Internet IP address of the left-hand side VPN device.
Leftsubnet – The network protected by the left-hand side VPN device.
Leftid – Fully qualified domain name in DNS of the left-hand side VPN device, which is preceded by an “@” sign. If DNS is set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail.
Leftrsasigkey – The entire left RSA sig public key for the left-hand side VPN device. This can be obtained by using the ipsec showhostkey –left command.
Leftnexthop – The next hop router from the left-hand side VPN device when trying to reach the right-hand side VPN device. You may use an auto-generated variable %defaultroute, which will be valid in most cases, or the actual IP address of the next hop router in cases where the next hop is not the default router.
Right – Internet IP address of the right-hand side VPN device.
Rightsubnet – The network protected by the right-hand side VPN device.
Rightid – Fully qualified domain name in DNS of the right-hand side VPN device, which is preceded by an @ sign. If DNS isn’t set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail.
Rightrsasigkey – The entire right RSA sig public key for the right-hand side VPN device. This can be obtained by using the ipsec showhostkey –right command.
Rightnexthop – The next hop router from the right-hand side VPN device when trying to reach the right-hand side VPN device. You may use an auto-generated variable %defaultroute, which will be valid in most cases, or the actual IP address of the next hop router in cases where the next hop is not the default router.

e.g :

conn test
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
left=80.74.16.239
leftnexthop=85.234.66.212
leftsubnet=10.20.0.0/16
right=85.234.66.212
rightnexthop=80.74.16.239
rightsubnet=10.20.194.64/26
keyingtries=3
pfs=no
rekey=yes
auto=start
keyexchange=ike
ikelifetime=8h
keylife=24h
dpdaction=restart
dpddelay=15
dpdtimeout=30

Linux Zyxel Ipsec VPN Configuration

Zyxel Router Linux Config.

Phase 1 (IKE) = Lifetime   8Hrs
Phase 2 (IPSEC) = Keylife 24hrs

86400  = 24hrs = Seconds
28800  = 8hrs    = Seconds
1440     = 24hrs  = Minutes
480       = 8hrs     = Minutes

Linux Ipsec Directory Conf :

conn commtest
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
left= “Remote Peer Address”
leftsubnet= “Remote Subnet Address”
right=”Local Wan Address”
rightsubnet= “Local Subnet Address”
keyingtries=3
pfs=yes
rekey=yes
auto=start
keyexchange=ike
ikelifetime=8h
keylife=24h
dpdaction=restart
dpddelay=30
dpdtimeout=120

ipsec.secrets.conf

80.74.16.251 1.1.1.1 : PSK “commsvpn”
80.74.16.251 1.1.1.2 : PSK “commsvpn”
80.74.16.251 1.1.1.3 : PSK “commsvpn”
80.74.16.251 1.1.1.4 : PSK “commsvpn”
80.74.16.251 1.1.1.5 : PSK “commsvpn”

Rereadsecrets Command Forces OpenSWAN to reload the secrets from the ipsec.secrets file

sudo ipsec auto –rereadsecrets