Aller à :navigation, rechercher
Wiki





notempty
Dieser Artikel bezieht sich auf eine nicht mehr aktuelle Version!

notempty
Der Artikel für die neueste Version steht hier

notempty
Zu diesem Artikel gibt es bereits eine neuere Version, die sich allerdings auf eine Reseller-Preview bezieht


















































































































De.png
En.png
Fr.png





Warnung: Der Anzeigetitel „“ überschreibt den früheren Anzeigetitel „IPSec Site-to-Site“.

12.5.0
  • (v12.4)
  • (v12.4)
  • (v12.4)
→ VPN →IPSec




[[Datei: ]]
  • Roadwarrior
  • Site to Site

|| IPSec S2S || || class="Bild" rowspan="3" | [[Datei: ]]
IKE v1IKE v2 Default: IKEv2

  



   
  • [[Datei: ]]

    '

    '
       

    '


    '
    RSA-Site2Site
    »192.168.122.0/24

    192.0.2.192 [[Datei: ]]
    192.0.2.192

    '
    RSA-Site2Site
    »192.168.192.0/24

  • IKEv1

    Step-by-step.png






    notempty




























































    {{var | DH-Gruppe (PFS) | DH-Gruppe (PFS): | DH-Group (PFS):

































    De.png
    En.png
    Fr.png


    Phase 1
    → VPN →IPSec Phase 1

    [[Datei: ]]
    [[Datei: ]]
    [[Datei: ]]
    [[Datei: ]]

    Default
    Outgoing
    Incoming
    Route
    Route
    Ignore
    notempty
    v12.4

    '
  • 30Link=
  • 10Link=

    Default
    Default-Werte UTM Default-Werte NCP-Client [[Datei: ]]
    1
    [[Datei: ]]
    2
    Verschlüsselung: aes128 AES 128 Bit
    Authentifizierung: sha2_256 Hash: SHA2 256 Bit
    ecp521 IKE DH-Gruppe: DH2 (modp1024)
     :
    notempty
    v12.5
    Strict:
    3Link=
    1
    notempty
    : v12.4
    2Link=
    notempty




    ike_lifetime = 2
    ike_rekeytime = 0


    ike_lifetime = 0
    ike_rekeytime = 2

    ----


    ike_lifetime = 2
    ike_rekeytime = 1


    ike_lifetime =2
    ike_rekeytime = 1
      
      

    Phase 2
    → VPN →IPSec Phase 2

    :

    Default-Werte UTM Default-Werte NCP-Client [[Datei: ]]
    / IKEv1 / Roadwarrior
    [[Datei: ]]
    / IKEv2 / Roadwarrior
    [[Datei: ]]
    / IKEv1 / S2S
    [[Datei: ]]
    / IKEv2 / S2S
    aes128 AES 128 Bit
    sha2_256 SHA2 256 Bit
    ecp521 IKE DH-Gruppe: DH2 (modp1024)
    IKE DH-Gruppe: DH2 (modp1024)
    Schlüssel-Lebensdauer: 8
    Austausch-Modus Main Mode (nicht konfigurierbar) Aggressive Mode (IKEv1)
  • :

    notempty
    v12.5

  • [[Datei: ]]
       

       

    '



  • root@firewall:~# swanctl --list-conns

    IPSec$20S2S: IKEv2, reauthentication every 3060s, no rekeying, dpd delay 10s
     local:  %any
     remote: 192.0.2.192
     local pre-shared key authentication:
       id: 192.168.175.218
     remote pre-shared key authentication:
       id: 192.0.2.192
     IPSec$20S2S: TUNNEL, rekeying every 28260s, dpd action is restart
       local:  192.168.218.0/24 192.168.219.0/24
       remote: 192.168.192.0/24 192.168.193.0/24
    



    root@firewall:~# swanctl --list-conns

     IPSec$20S2S: IKEv2, reauthentication every 3060s, no rekeying, dpd delay 10s
       local:  %any
       remote: 192.0.2.192
       local pre-shared key authentication:
         id: 192.168.175.218
       remote pre-shared key authentication:
         id: 192.0.2.192
       IPSec$20S2S_4: TUNNEL, rekeying every 28260s, dpd action is restart
         local:  192.168.218.0/24
         remote: 192.168.192.0/24
       IPSec$20S2S_5: TUNNEL, rekeying every 28260s, dpd action is restart
         local:  192.168.218.0/24
         remote: 192.168.193.0/24
       IPSec$20S2S_6: TUNNEL, rekeying every 28260s, dpd action is restart
         local:  192.168.219.0/24
         remote: 192.168.192.0/24
       IPSec$20S2S_7: TUNNEL, rekeying every 28260s, dpd action is restart
         local:  192.168.219.0/24
         remote: 192.168.193.0/24
    

    [[Datei: ]]
    '


    root@firewall:~# swanctl --list-conns IPSec$20S2S: IKEv2, reauthentication every 3060s, no rekeying, dpd delay 10s

     local:  %any
     remote: 192.0.2.192
     local pre-shared key authentication:
       id: 192.168.175.218
     remote pre-shared key authentication:
       id: 192.0.2.192
     IPSec$20S2S: TUNNEL, rekeying every 28260s, dpd action is restart
       local:  192.168.218.0/24 192.168.219.0/24
       remote: 192.168.192.0/24 192.168.193.0/24
    



    root@firewall:~# swanctl --list-conns IPSec$20S2S: IKEv2, reauthentication every 3060s, no rekeying, dpd delay 10s

     local:  %any
     remote: 192.0.2.192
     local pre-shared key authentication:
       id: 192.168.175.218
     remote pre-shared key authentication:
       id: 192.0.2.192
     IPSec$20S2S_4: TUNNEL, rekeying every 28260s, dpd action is restart
       local:  192.168.218.0/24
       remote: 192.168.192.0/24
     IPSec$20S2S_5: TUNNEL, rekeying every 28260s, dpd action is restart
       local:  192.168.218.0/24
       remote: 192.168.193.0/24
     IPSec$20S2S_6: TUNNEL, rekeying every 28260s, dpd action is restart
       local:  192.168.219.0/24
       remote: 192.168.192.0/24
    

    [[Datei: ]]



    IKEv2

    Step-by-step.png






    notempty




























































    {{var | DH-Gruppe (PFS) | DH-Gruppe (PFS): | DH-Group (PFS):

































    De.png
    En.png
    Fr.png


    Phase 1
    → VPN →IPSec Phase 1

    [[Datei: ]]
    [[Datei: ]]
    [[Datei: ]]
    [[Datei: ]]

    Default
    Outgoing
    Incoming
    Route
    Route
    Ignore
    notempty
    v12.4

    '
  • 30Link=
  • 10Link=

    Default
    Default-Werte UTM Default-Werte NCP-Client [[Datei: ]]
    1
    [[Datei: ]]
    2
    Verschlüsselung: aes128 AES 128 Bit
    Authentifizierung: sha2_256 Hash: SHA2 256 Bit
    ecp521 IKE DH-Gruppe: DH2 (modp1024)
     :
    notempty
    v12.5
    Strict:
    3Link=
    1
    notempty
    : v12.4
    2Link=
    notempty




    ike_lifetime = 2
    ike_rekeytime = 0


    ike_lifetime = 0
    ike_rekeytime = 2

    ----


    ike_lifetime = 2
    ike_rekeytime = 1


    ike_lifetime =2
    ike_rekeytime = 1
      
      

    Phase 2
    → VPN →IPSec Phase 2

    :

    Default-Werte UTM Default-Werte NCP-Client [[Datei: ]]
    / IKEv1 / Roadwarrior
    [[Datei: ]]
    / IKEv2 / Roadwarrior
    [[Datei: ]]
    / IKEv1 / S2S
    [[Datei: ]]
    / IKEv2 / S2S
    aes128 AES 128 Bit
    sha2_256 SHA2 256 Bit
    ecp521 IKE DH-Gruppe: DH2 (modp1024)
    IKE DH-Gruppe: DH2 (modp1024)
    Schlüssel-Lebensdauer: 8
    Austausch-Modus Main Mode (nicht konfigurierbar) Aggressive Mode (IKEv1)
  • :

    notempty
    v12.5

  • [[Datei: ]]
       

       

    '



  • root@firewall:~# swanctl --list-conns

    IPSec$20S2S: IKEv2, reauthentication every 3060s, no rekeying, dpd delay 10s
     local:  %any
     remote: 192.0.2.192
     local pre-shared key authentication:
       id: 192.168.175.218
     remote pre-shared key authentication:
       id: 192.0.2.192
     IPSec$20S2S: TUNNEL, rekeying every 28260s, dpd action is restart
       local:  192.168.218.0/24 192.168.219.0/24
       remote: 192.168.192.0/24 192.168.193.0/24
    



    root@firewall:~# swanctl --list-conns

     IPSec$20S2S: IKEv2, reauthentication every 3060s, no rekeying, dpd delay 10s
       local:  %any
       remote: 192.0.2.192
       local pre-shared key authentication:
         id: 192.168.175.218
       remote pre-shared key authentication:
         id: 192.0.2.192
       IPSec$20S2S_4: TUNNEL, rekeying every 28260s, dpd action is restart
         local:  192.168.218.0/24
         remote: 192.168.192.0/24
       IPSec$20S2S_5: TUNNEL, rekeying every 28260s, dpd action is restart
         local:  192.168.218.0/24
         remote: 192.168.193.0/24
       IPSec$20S2S_6: TUNNEL, rekeying every 28260s, dpd action is restart
         local:  192.168.219.0/24
         remote: 192.168.192.0/24
       IPSec$20S2S_7: TUNNEL, rekeying every 28260s, dpd action is restart
         local:  192.168.219.0/24
         remote: 192.168.193.0/24
    

    [[Datei: ]]
    '


    root@firewall:~# swanctl --list-conns IPSec$20S2S: IKEv2, reauthentication every 3060s, no rekeying, dpd delay 10s

     local:  %any
     remote: 192.0.2.192
     local pre-shared key authentication:
       id: 192.168.175.218
     remote pre-shared key authentication:
       id: 192.0.2.192
     IPSec$20S2S: TUNNEL, rekeying every 28260s, dpd action is restart
       local:  192.168.218.0/24 192.168.219.0/24
       remote: 192.168.192.0/24 192.168.193.0/24
    



    root@firewall:~# swanctl --list-conns IPSec$20S2S: IKEv2, reauthentication every 3060s, no rekeying, dpd delay 10s

     local:  %any
     remote: 192.0.2.192
     local pre-shared key authentication:
       id: 192.168.175.218
     remote pre-shared key authentication:
       id: 192.0.2.192
     IPSec$20S2S_4: TUNNEL, rekeying every 28260s, dpd action is restart
       local:  192.168.218.0/24
       remote: 192.168.192.0/24
     IPSec$20S2S_5: TUNNEL, rekeying every 28260s, dpd action is restart
       local:  192.168.218.0/24
       remote: 192.168.193.0/24
     IPSec$20S2S_6: TUNNEL, rekeying every 28260s, dpd action is restart
       local:  192.168.219.0/24
       remote: 192.168.192.0/24
    

    [[Datei: ]]




    [[Datei: ]]


  • || IPSec-S2S || || class="bild width-m" rowspan="5" | [[Datei: ]]
    ||     ||
    || 192.168.192.0/24 ||
    || vpn-ipsec ||
    ||     ||


  • [[Datei: ]]
    '
    || internal-network ||
    ||     ||
    ||     ||
    NAT
    || Hidenat Exclude ||
    || external-interface ||

    '
    ||     ||
    || internal-network ||
    ||     ||
    NAT:


    [[Datei: |hochkant=2|mini| ]]