Project

General

Profile

strongSwan as a Policy Enforcement Point » History » Version 3

Andreas Steffen, 14.12.2010 21:20

1 1 Andreas Steffen
h1. strongSwan as a Policy Enforcement Point
2 2 Andreas Steffen
3 3 Andreas Steffen
<pre>
4 3 Andreas Steffen
./configure --prefix=/usr --sysconfdir =/etc --disable-pluto --enable-curl
5 3 Andreas Steffen
            --enable-eap-radius
6 3 Andreas Steffen
</pre>
7 1 Andreas Steffen
8 3 Andreas Steffen
/etc/strongswan.conf - strongSwan configuration file
9 3 Andreas Steffen
10 1 Andreas Steffen
<pre>
11 3 Andreas Steffen
charon {
12 3 Andreas Steffen
  plugins {
13 3 Andreas Steffen
    eap-radius {
14 3 Andreas Steffen
      secret = gv6URkSs 
15 3 Andreas Steffen
      server = 10.1.0.10
16 3 Andreas Steffen
      filter_id = yes
17 3 Andreas Steffen
    }
18 3 Andreas Steffen
  }
19 3 Andreas Steffen
}
20 1 Andreas Steffen
</pre>
21 3 Andreas Steffen
22 3 Andreas Steffen
/etc/ipsec.secrets - strongSwan IPsec secrets file
23 3 Andreas Steffen
24 3 Andreas Steffen
<pre>
25 3 Andreas Steffen
: RSA moonKey.pem
26 3 Andreas Steffen
</pre>
27 3 Andreas Steffen
28 3 Andreas Steffen
/etc/ipsec.conf - strongSwan IPsec configuration file
29 3 Andreas Steffen
30 3 Andreas Steffen
<pre>
31 3 Andreas Steffen
conn rw-allow
32 3 Andreas Steffen
     rightgroups=allow
33 3 Andreas Steffen
     leftsubnet=10.1.0.0/28
34 3 Andreas Steffen
     also=rw-eap
35 3 Andreas Steffen
     auto=add
36 3 Andreas Steffen
37 3 Andreas Steffen
conn rw-isolate
38 3 Andreas Steffen
     rightgroups=isolate
39 3 Andreas Steffen
     leftsubnet=10.1.0.16/28
40 3 Andreas Steffen
     also=rw-eap
41 3 Andreas Steffen
     auto=add
42 3 Andreas Steffen
43 3 Andreas Steffen
conn rw-eap
44 3 Andreas Steffen
     leftcert=moonCert.pem
45 3 Andreas Steffen
     leftid=@moon.strongswan.org
46 3 Andreas Steffen
     leftauth=pubkey
47 3 Andreas Steffen
     rightauth=eap-radius
48 3 Andreas Steffen
     rightid=*@strongswan.org
49 3 Andreas Steffen
     rightsendcert=never
50 3 Andreas Steffen
     right=%any
51 3 Andreas Steffen
</pre>
52 3 Andreas Steffen
53 3 Andreas Steffen
"PEP log file":http://www.strongswan.org/uml/testresults/ikev2/rw-eap-tnc-radius/moon.daemon.log