2.架设服务器
具体过程不再赘述,相关配置文件如下:
OpenSWan 主要配置文件:
/etc/ipsec.secrets 用来保存private RSA keys 和 preshared secrets (PSKs)
/etc/ipsec.conf 配置文件(settings, options, defaults, connections)
OpenSWan 主要配置目录 :
/etc/ipsec.d/cacerts 存放X.509 认证证书(根证书-"root certificates")
/etc/ipsec.d/certs 存放X.509 客户端证书(X.509 client Certificates)
/etc/ipsec.d/private 存放X.509 认证私钥(X.509 Certificate private keys)
/etc/ipsec.d/crls 存放X.509 证书撤消列表(X.509 Certificate Revocation Lists)
/etc/ipsec.d/ocspcerts 存放X.500 OCSP 证书(Online Certificate Status Protocol certificates)
/etc/ipsec.d/passwd XAUTH 密码文件(XAUTH password file)
/etc/ipsec.d/policies 存放Opportunistic Encryption 策略组(The Opportunistic Encryption policy groups)
[root@mm ~]# cat /etc/ppp/chap-secrets # Secrets for authentication using CHAP #
client server secret IP addresses
test1 * test1 *
l2tptest1 * l2tptest1 10.1.1.1
l2tptest2 * l2tptest2 *
[root@mm ~]# cat /etc/ipsec.secrets
RSA /etc/ipsec.d/private/vpngateway.key "123456"
#192.168.1.251 %any : PSK "123456"
[root@mm ~]# cat /etc/ipsec.conf
#version 2.0
config setup
interfaces=%defaultroute
nat_traversal=yes
virtual_private=%v4:192.168.0.0/16,%v4:10.0.0.0/8,%v4:172.16.1.0/24,%v4:!192.168.1.0/24
conn %default
compress=yes
authby=rsasig
leftrsasigkey=%cert
rightrsasigkey=%cert
#conn roadwarrior
#left=172.16.1.100
#leftcert=vpngateway.cert
#leftsubnet=172.16.1.0/24
#right=%any
#auto=add
conn l2tpx509
pfs=no auto=add
left=192.168.1.251
leftcert=vpngateway.cert
leftprotoport=17/1701
right=%any
rightca=%same
rightprotoport=17/%any ############################################################################# #configure preshared secret authentication
上一篇:SAP与Novell联手提供拓展Linux支持选择
下一篇:没有了