Linux Ipsec VPN Dynamic IP
Fully qualified domain name in DNS of the right-hand side VPN device,
which is preceded by an @ sign. If DNS isn’t set up for the IP addresses,
remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail.
conn comms27
left=2.2.2.2
leftsubnet=10.10.0.0/16
right=0.0.0.0
rightid=@comms27.commsgroup.ww
rightsubnet=10.10.37.0/24
authby=secret
keyexchange=ike
aggrmode=no
ikelifetime=24h
keylife=8h
keyingtries=3
rekey=no
auto=start
esp=3des-md5-96
pfs=no
dpddelay=30
dpdtimeout=120
dpdaction=clear
type=transport
ipsec.secrets config :
%any 85.234.65.53 : PSK “commsr3m0t3”
@comms30.commsgroup.ww 85.234.65.53 : PSK “commsr3m0t3”
Table 35-1 Parameters of the /etc/ipsec.conf file
| Parameter | Description |
|---|---|
Left |
Internet IP address of the left-hand side VPN device. |
Leftsubnet |
The network protected by the left-hand side VPN device. |
Leftid |
Fully qualified domain name in DNS of the left-hand side VPN device, which is preceded by an “@” sign. If DNS is set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail. |
Leftrsasigkey |
The entire left RSA sig public key for the left-hand side VPN device. This can be obtained by using the ipsec showhostkey --left command. |
Leftnexthop |
The next hop router from the left-hand side VPN device when trying to reach the right-hand side VPN device. You may use an auto-generated variable %defaultroute, which will be valid in most cases, or the actual IP address of the next hop router in cases where the next hop is not the default router. |
Right |
Internet IP address of the right-hand side VPN device. |
Rightsubnet |
The network protected by the right-hand side VPN device. |
Rightid |
Fully qualified domain name in DNS of the right-hand side VPN device, which is preceded by an @ sign. If DNS isn’t set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail. |
Rightrsasigkey |
The entire right RSA sig public key for the right-hand side VPN device. This can be obtained by using the ipsec showhostkey --right command. |
Rightnexthop |
The next hop router from the right-hand side VPN device when trying to reach the right-hand side VPN device. You may use an auto-generated variable %defaultroute, which will be valid in most cases, or the actual IP address of the next hop router in cases where the next hop is not the default router. |