Differences between revisions 8 and 9
Revision 8 as of 2006-08-16 01:47:04
Size: 1012
Editor: JustinSearle
Comment:
Revision 9 as of 2006-08-16 01:48:03
Size: 1008
Editor: JustinSearle
Comment:
Deletions are marked like this. Additions are marked like this.
Line 18: Line 18:
 {{{
 10.15.109.5 10.15.109.36 : PSK "password"
 }}}
  {{{
10.15.109.5 10.15.109.36 : PSK "password"
  }}}
Line 22: Line 22:
 {{{
 conn vpn
 authby=secret
 left=10.15.109.36
 leftsubnet=192.168.50.0/24
 leftnexthop=10.15.109.5
 right=10.15.109.5
 rightsubnet=192.168.1.0/24
 rightnexthop=10.15.109.36
 }}}
  {{{
conn vpn
authby=secret
left=10.15.109.36
leftsubnet=192.168.50.0/24
leftnexthop=10.15.109.5
right=10.15.109.5
rightsubnet=192.168.1.0/24
rightnexthop=10.15.109.36
  }}}
Line 33: Line 33:
 {{{
 /etc/init.d/ipsec restart
 }}}
  {{{
/etc/init.d/ipsec restart
  }}}

Topology:

host 1 ------------------- vpn-gw 1 <----------------------------> vpn-gw 2 ------------------ host 2
                                               |                                       |
                                |                                     |
<--192.168.50.0/24-->    10.15.109.36                  10.15.109.5      <--192.168.1.0/24--> 

Setup:

  1. Install the openswan package. Now we got 2 main files: /etc/ipsec.secrets and /etc/ipsec.conf
  2. Edit ipsec.secrets for vpn-gw 1:
    • 10.15.109.36 10.15.109.5 : PSK "password
  3. Edit ipsec.secrets for vpn-gw 1:
    • 10.15.109.5 10.15.109.36 : PSK "password"
  4. Edit ipsec.conf for vpn-gw 1 & vpn-gw 2 (same exact stuff):

    • conn vpn
      authby=secret
      left=10.15.109.36
      leftsubnet=192.168.50.0/24
      leftnexthop=10.15.109.5
      right=10.15.109.5
      rightsubnet=192.168.1.0/24
      rightnexthop=10.15.109.36
  5. Restart ipsec:
    • /etc/init.d/ipsec restart
  6. Now you can ping from host 1 to host 2!