strongSwan as a Policy Enforcement Point » History » Version 3
Andreas Steffen, 14.12.2010 21:20
1 | 1 | Andreas Steffen | h1. strongSwan as a Policy Enforcement Point |
---|---|---|---|
2 | 2 | Andreas Steffen | |
3 | 3 | Andreas Steffen | <pre> |
4 | 3 | Andreas Steffen | ./configure --prefix=/usr --sysconfdir =/etc --disable-pluto --enable-curl |
5 | 3 | Andreas Steffen | --enable-eap-radius |
6 | 3 | Andreas Steffen | </pre> |
7 | 1 | Andreas Steffen | |
8 | 3 | Andreas Steffen | /etc/strongswan.conf - strongSwan configuration file |
9 | 3 | Andreas Steffen | |
10 | 1 | Andreas Steffen | <pre> |
11 | 3 | Andreas Steffen | charon { |
12 | 3 | Andreas Steffen | plugins { |
13 | 3 | Andreas Steffen | eap-radius { |
14 | 3 | Andreas Steffen | secret = gv6URkSs |
15 | 3 | Andreas Steffen | server = 10.1.0.10 |
16 | 3 | Andreas Steffen | filter_id = yes |
17 | 3 | Andreas Steffen | } |
18 | 3 | Andreas Steffen | } |
19 | 3 | Andreas Steffen | } |
20 | 1 | Andreas Steffen | </pre> |
21 | 3 | Andreas Steffen | |
22 | 3 | Andreas Steffen | /etc/ipsec.secrets - strongSwan IPsec secrets file |
23 | 3 | Andreas Steffen | |
24 | 3 | Andreas Steffen | <pre> |
25 | 3 | Andreas Steffen | : RSA moonKey.pem |
26 | 3 | Andreas Steffen | </pre> |
27 | 3 | Andreas Steffen | |
28 | 3 | Andreas Steffen | /etc/ipsec.conf - strongSwan IPsec configuration file |
29 | 3 | Andreas Steffen | |
30 | 3 | Andreas Steffen | <pre> |
31 | 3 | Andreas Steffen | conn rw-allow |
32 | 3 | Andreas Steffen | rightgroups=allow |
33 | 3 | Andreas Steffen | leftsubnet=10.1.0.0/28 |
34 | 3 | Andreas Steffen | also=rw-eap |
35 | 3 | Andreas Steffen | auto=add |
36 | 3 | Andreas Steffen | |
37 | 3 | Andreas Steffen | conn rw-isolate |
38 | 3 | Andreas Steffen | rightgroups=isolate |
39 | 3 | Andreas Steffen | leftsubnet=10.1.0.16/28 |
40 | 3 | Andreas Steffen | also=rw-eap |
41 | 3 | Andreas Steffen | auto=add |
42 | 3 | Andreas Steffen | |
43 | 3 | Andreas Steffen | conn rw-eap |
44 | 3 | Andreas Steffen | leftcert=moonCert.pem |
45 | 3 | Andreas Steffen | leftid=@moon.strongswan.org |
46 | 3 | Andreas Steffen | leftauth=pubkey |
47 | 3 | Andreas Steffen | rightauth=eap-radius |
48 | 3 | Andreas Steffen | rightid=*@strongswan.org |
49 | 3 | Andreas Steffen | rightsendcert=never |
50 | 3 | Andreas Steffen | right=%any |
51 | 3 | Andreas Steffen | </pre> |
52 | 3 | Andreas Steffen | |
53 | 3 | Andreas Steffen | "PEP log file":http://www.strongswan.org/uml/testresults/ikev2/rw-eap-tnc-radius/moon.daemon.log |