In /var/ipsec/ipsec.secrets c'è l'ip del router e la chiave IPSec precondivisa che ho impostato da GUI.
In /var/ipsec/ipsec.conf c'è:
# generated by /etc/init.d/ipsec
version 2
conn l2tp-server
left=%any
right=%any
leftsubnet=0.0.0.0/0[udp/l2tp]
leftfirewall=yes
ikelifetime=60m
lifetime=60m
margintime=9m
keyingtries=3
dpdaction=clear
dpddelay=0
leftauth=psk
rightauth=psk
rightsubnet=0.0.0.0/0[udp/%any]
auto=add
keyexchange=ike
esp=aes128-sha1
ike=3des-sha1-modp1024,aes128-sha1
type=transport
In etc/ipsec.conf
# ipsec.conf - strongSwan IPsec configuration file
# basic configuration
config setup
# strictcrlpolicy=yes
# uniqueids = no
# Add connections here.
# Sample VPN connections
#conn sample-self-signed
# leftsubnet=10.1.0.0/16
# leftcert=selfCert.der
# leftsendcert=never
# right=192.168.0.2
# rightsubnet=10.2.0.0/16
# rightcert=peerCert.der
# auto=start
#conn sample-with-ca-cert
# leftsubnet=10.1.0.0/16
# leftcert=myCert.pem
# right=192.168.0.2
# rightsubnet=10.2.0.0/16
# rightid="C=CH, O=Linux strongSwan CN=peer name"
# auto=start
include /var/ipsec/ipsec.conf
Dando il comando ipsec statusall ottengo:
root@modemtim:~# ipsec statusall
Status of IKE charon daemon (strongSwan 5.6.3, Linux 4.1.38, armv7l):
uptime: 113 minutes, since Mar 17 13:09:14 2020
malloc: sbrk 638976, mmap 0, used 131976, free 507000
worker threads: 11 of 16 idle, 5/0/0/0 working, job queue: 0/0/0/0, scheduled: 0
loaded plugins: charon aes des rc2 sha2 sha1 md5 random nonce x509 revocation constraints pubkey pkcs1 pgp dnskey sshkey pem fips-prf gmp xcbc hmac attr kernel-netlink resolve socket-default connmark stroke updown xauth-generic
Listening IP addresses:
IP DEL MIO ROUTER
Connections:
Security Associations (0 up, 0 connecting):
none