{"id":7681,"date":"2022-04-22T13:40:42","date_gmt":"2022-04-22T20:40:42","guid":{"rendered":"https:\/\/www.xh86.me\/?p=7681"},"modified":"2022-04-22T13:40:42","modified_gmt":"2022-04-22T20:40:42","slug":"%e9%85%8d%e7%bd%aestrongswan%e5%92%8ch3c-vsr%e7%9a%84ipsec%e5%af%b9%e6%8e%a5%e6%a1%88%e4%be%8b","status":"publish","type":"post","link":"https:\/\/www.xh86.me\/?p=7681","title":{"rendered":"\u914d\u7f6estrongSwan\u548cH3C VSR\u7684IPsec\u5bf9\u63a5\u6848\u4f8b"},"content":{"rendered":"<div class=\"wxsyncmain\">\n<section><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-a1a47f39026cfb8602010cae60cbca2d.gif'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" style=\"float: left; width: auto !important; max-width: 100% !important; height: auto !important;\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-a1a47f39026cfb8602010cae60cbca2d.gif\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.160075329566855\" data-type=\"gif\" data-w=\"531\" \/><\/div><\/p>\n<p>&nbsp;<\/p>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">strongSwan\u662f\u4e00\u4e2a\u5f00\u6e90\u7684\u57fa\u4e8eIPsec\u7684VPN\u89e3\u51b3\u65b9\u6848\uff0c\u7ecf\u8fc7\u524d\u9762\u51e0\u7bc7\u6587\u7ae0\u7684\u94fa\u57ab\uff0c\u4eca\u5929\u7ec8\u4e8e\u53ef\u4ee5\u6d4b\u8bd5strongSwan\u548c\u534e\u4e09\u8bbe\u5907\u7684\u5bf9\u63a5\u60c5\u51b5\u4e86\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">strongSwan\u7684\u9ed8\u8ba4\u5b89\u88c5\u8def\u5f84\u662f\/etc\/strongswan\/\uff0c\u8fd9\u91cc\u9762\u6bd4\u8f83\u91cd\u8981\u7684\u5c31\u662fipsec.conf\u548cipsec.secrets\u8fd9\u4e24\u4e2a\u914d\u7f6e\u6587\u4ef6\u4e86\u3002<\/p>\n<p style=\"margin-top: 10px; margin-bottom: 10px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-917b2241d3ab35a24bd7e3cf9a981c58.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-917b2241d3ab35a24bd7e3cf9a981c58.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.288981288981289\" data-type=\"png\" data-w=\"481\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u5bf9\u7ec4\u7f51\u62d3\u6251\u7a0d\u4f5c\u8c03\u6574\uff0c\u7528\u4e00\u53f0\u534e\u4e09VSR\u66ff\u6362\u6389Linux2\u4e3b\u673a\uff0c\u4f7fLinux\u670d\u52a1\u5668\u548cVSR\u76f4\u63a5\u5bf9\u63a5\uff0c\u5982\u4e0b\u56fe\u6240\u793a\uff1a<\/p>\n<p style=\"margin-top: 10px; margin-bottom: 10px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-0ff4696fee99b7ba2df31c1b0a5ad45e.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-0ff4696fee99b7ba2df31c1b0a5ad45e.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.2747093023255814\" data-type=\"png\" data-w=\"688\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u6211\u4eec\u5df2\u7ecf\u5bf9strongSwan\u548cVSR\u7684IPsec\u914d\u7f6e\u8fdb\u884c\u4e86\u521d\u6b65\u5bf9\u6bd4\uff0c\u7b80\u5355\u56de\u987e\u4e00\u4e0b\uff1a<\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u5148\u770bVSR\u548cstrongSwan\u4e00\u6837\u7684\u5730\u65b9\uff1a\u7b2c\u4e00\u9636\u6bb5\u7684\u534f\u5546\u6a21\u5f0f\u9ed8\u8ba4\u90fd\u662f\u4e3b\u6a21\u5f0f\uff0c\u7b2c\u4e8c\u9636\u6bb5\u9ed8\u8ba4\u7684\u52a0\u5bc6\u6a21\u5f0f\u90fd\u662fESP\uff0c\u62a5\u6587\u5c01\u88c5\u6a21\u5f0f\u9ed8\u8ba4\u90fd\u662f\u96a7\u9053\u6a21\u5f0f\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u518d\u770b\u6709\u5dee\u522b\u7684\u5730\u65b9\uff0cstrongSwan\u7684ipsec.conf\u914d\u7f6e\u6587\u4ef6\u5982\u4e0b\uff1a<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"makefile\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\"># cat\u00a0\/etc\/strongswan\/ipsec.conf<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">conn swan<\/span><\/code><code><span class=\"code-snippet_outer\">  authby = psk<\/span><\/code><code><span class=\"code-snippet_outer\">  keyexchange=ikev1<\/span><\/code><code><span class=\"code-snippet_outer\">  left=12.1.1.1<\/span><\/code><code><span class=\"code-snippet_outer\">  leftsubnet=11.1.1.0\/24<\/span><\/code><code><span class=\"code-snippet_outer\">  right=12.1.1.2<\/span><\/code><code><span class=\"code-snippet_outer\">  rightsubnet=22.1.1.0\/24<\/span><\/code><code><span class=\"code-snippet_outer\">  auto=route<\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u8fd9\u91cc\u9762\u6709\u9690\u85cf\u7684\u9ed8\u8ba4\u914d\u7f6e\uff1a<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"makefile\"><code><span class=\"code-snippet_outer\">conn swan<\/span><\/code><code><span class=\"code-snippet_outer\">  leftid=12.1.1.1<\/span><\/code><code><span class=\"code-snippet_outer\">  rightid=12.1.1.2<\/span><\/code><code><span class=\"code-snippet_outer\">  ike = aes128-sha256-modp3072<\/span><\/code><code><span class=\"code-snippet_outer\">  esp = aes128-sha256<\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u8fd9\u91cc\u6709\u4e2a\u95ee\u9898\uff0c\u5c31\u662fIKE\u7b97\u6cd5\u4e2d\u7684PRF-modp3072\u7b97\u6cd5\u534e\u4e09\u6682\u65f6\u662f\u4e0d\u652f\u6301\u7684\u3002\u540c\u65f6strongSwan\u6709\u914d\u7f6e\u8bf4\u660e\uff0c\u5982\u679c\u6ca1\u6709\u7ed9\u51faPRF\uff0c\u5219\u4e3a\u5b8c\u6574\u6027\u5b9a\u4e49\u7684\u7b97\u6cd5\u5c06\u7528\u4e8ePRF\uff0c\u6240\u4ee5\u6211\u4eec\u628a\u914d\u7f6e\u4fee\u6539\u4e3aike = aes128-sha256\u8bd5\u4e00\u4e0b\u3002<\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u5230\u8fd9\u91cc\uff0cstrongSwan\u7684\u914d\u7f6e\u5c31\u5b8c\u6210\u4e86\u3002<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"makefile\"><code><span class=\"code-snippet_outer\">conn swan<\/span><\/code><code><span class=\"code-snippet_outer\">  authby = psk<\/span><\/code><code><span class=\"code-snippet_outer\">  keyexchange=ikev1<\/span><\/code><code><span class=\"code-snippet_outer\">  left=12.1.1.1<\/span><\/code><code><span class=\"code-snippet_outer\">  leftid=12.1.1.1<\/span><\/code><code><span class=\"code-snippet_outer\">  leftsubnet=11.1.1.0\/24<\/span><\/code><code><span class=\"code-snippet_outer\">  right=12.1.1.2<\/span><\/code><code><span class=\"code-snippet_outer\">  rightid=12.1.1.2<\/span><\/code><code><span class=\"code-snippet_outer\">  rightsubnet=22.1.1.0\/24<\/span><\/code><code><span class=\"code-snippet_outer\">  auto=route<\/span><\/code><code><span class=\"code-snippet_outer\">  ike = aes128-sha256<\/span><\/code><code><span class=\"code-snippet_outer\">  esp = aes128-sha256<\/span><\/code><\/pre>\n<\/section>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"nginx\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\"># cat \/etc\/strongswan\/ipsec.secrets<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">12.1.1.2 12.1.1.1 : <span class=\"code-snippet__attribute\">PSK<\/span> swan<\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u63a5\u4e0b\u6765\u5c31\u662f\u6bd4\u8f83\u62ff\u624b\u7684H3C\u914d\u7f6e\u4e86\uff0c\u6309\u7167strongSwan\u7684\u914d\u7f6e\u8fdb\u884c\u8c03\u6574\uff0c\u76f4\u63a5\u4e0a\u914d\u7f6e\uff1a<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"properties\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">ike<\/span> <span class=\"code-snippet__string\">keychain swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">pre-shared-key<\/span> <span class=\"code-snippet__string\">address 12.1.1.1 255.255.255.0 key simple swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">ike<\/span> <span class=\"code-snippet__string\">proposal 10<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">encryption-algorithm<\/span> <span class=\"code-snippet__string\">aes-cbc-128<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">authentication-algorithm<\/span> <span class=\"code-snippet__string\">sha256<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">ike<\/span> <span class=\"code-snippet__string\">profile swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">keychain<\/span> <span class=\"code-snippet__string\">swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">local-identity<\/span> <span class=\"code-snippet__string\">address 12.1.1.2<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">match<\/span> <span class=\"code-snippet__string\">remote identity address 12.1.1.1 255.255.255.0<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">proposal<\/span> <span class=\"code-snippet__string\">10<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">acl<\/span> <span class=\"code-snippet__string\">advanced 3402<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">rule<\/span> <span class=\"code-snippet__string\">0 permit ip source 22.1.1.0 0.0.0.255 destination 11.1.1.0 0.0.0.255<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">ipsec<\/span> <span class=\"code-snippet__string\">transform-set swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">esp<\/span> <span class=\"code-snippet__string\">encryption-algorithm aes-cbc-128<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">esp<\/span> <span class=\"code-snippet__string\">authentication-algorithm sha256<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">ipsec<\/span> <span class=\"code-snippet__string\">policy swan 10 isakmp<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">transform-set<\/span> <span class=\"code-snippet__string\">swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">security<\/span> <span class=\"code-snippet__string\">acl 3402<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">local-address\u00a012.1.1.2<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">remote-address<\/span> <span class=\"code-snippet__string\">12.1.1.1<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">ike-profile<\/span> <span class=\"code-snippet__string\">swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">interface<\/span> <span class=\"code-snippet__string\">GigabitEthernet3\/0<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">ipsec<\/span> <span class=\"code-snippet__string\">apply policy swan<\/span><\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u7136\u540e\u89e6\u53d1\u4e00\u4e0b\uff0c\u53d1\u73b0IPsec\u534f\u5546\u5931\u8d25\uff0c\u72b6\u6001\u672a\u77e5\u3002<\/p>\n<p style=\"margin-top: 10px; margin-bottom: 10px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-7f3d784076131d08322cb688cd64f972.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-7f3d784076131d08322cb688cd64f972.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.18739903069466882\" data-type=\"png\" data-w=\"619\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u5728Linux\u7aef\u67e5\u770b\u4e5f\u662fIKE SA\u5efa\u7acb\u5931\u8d25\u3002<\/p>\n<p style=\"margin-top: 10px; margin-bottom: 10px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-22e4b3dddb395ebfc969481da8cd84b3.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-22e4b3dddb395ebfc969481da8cd84b3.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.532520325203252\" data-type=\"png\" data-w=\"738\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u5728VSR\u4e0a\u8fdb\u884cdebug\uff0c\u53d1\u73b0\u6709\u62a5\u9519\uff0c\u63d0\u793a\u201c<em>No HASH in notification payload.<\/em>\u201d\uff0c\u7ffb\u8bd1\u4e00\u4e0b\u5c31\u662f\u8bf4\u901a\u77e5\u6709\u6548\u8d1f\u8f7d\u4e2d\u6ca1\u6709HASH\u3002<\/p>\n<p style=\"margin-top: 10px; margin-bottom: 10px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-649436a382b0ed011fe9fdfd70a73b75.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-649436a382b0ed011fe9fdfd70a73b75.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.7255154639175257\" data-type=\"png\" data-w=\"776\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u7136\u540e\u6293\u5305\u770b\u4e00\u4e0b\u3002<\/p>\n<p style=\"margin-top: 10px; margin-bottom: 10px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-8008ab9d048fcfa83d67d8f215ba2452.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-8008ab9d048fcfa83d67d8f215ba2452.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.22407407407407406\" data-type=\"png\" data-w=\"1080\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u6211\u4eec\u53d1\u73b0DH\u7ec4\u548c\u751f\u547d\u5468\u671f\u4fe1\u606f\u8fd8\u662f\u5b58\u5728\u4e00\u4e9b\u5dee\u5f02\uff0c\u4fee\u6539strongSwan\u7684\u7b97\u6cd5\u914d\u7f6e\u4e3aike = aes128-sha256-modp1024\uff0c\u5bf9\u5e94\u7684\uff0c\u8c03\u6574VSR\u4e2dike proposal\u7684DH\u7ec4\u4e3a2\uff081024-bit\uff09\uff0c\u547d\u4ee4dh group2\u3002\u540c\u65f6\u8c03\u6574strongSwan\u7684ikelifetime\u4e3a86400\uff081\u5929\uff09\u3002<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<ul class=\"code-snippet__line-index code-snippet__js\">\n<li><\/li>\n<li><\/li>\n<\/ul>\n<pre class=\"code-snippet__js\" data-lang=\"ini\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">ike<\/span> = aes128-sha256-modp1024<\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">ikelifetime<\/span>=<span class=\"code-snippet__number\">86400<\/span><\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u518d\u6b21\u89e6\u53d1\u4e00\u4e0b\uff0c\u901a\u4e86\uff01<\/p>\n<p style=\"margin-top: 10px; margin-bottom: 10px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-405de3b2e1bfffdc9db68486024cd137.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-405de3b2e1bfffdc9db68486024cd137.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.275\" data-type=\"png\" data-w=\"520\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u67e5\u770bVSR\u4e0a\u76f8\u5173\u7684SA\u4fe1\u606f\u3002<\/p>\n<p style=\"margin-top: 10px; margin-bottom: 10px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-270e4cdc2700e3a0cce366a722e8ed4a.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-270e4cdc2700e3a0cce366a722e8ed4a.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"1.339652448657188\" data-type=\"png\" data-w=\"633\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u67e5\u770bstrongSwan\u7684\u76f8\u5173\u72b6\u6001\u4fe1\u606f\u3002<\/p>\n<p style=\"margin-top: 10px; margin-bottom: 10px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-53b2b6bed401eee6dd8fa1ad8fa1af2b.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-53b2b6bed401eee6dd8fa1ad8fa1af2b.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.6237980769230769\" data-type=\"png\" data-w=\"832\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u62a5\u6587\u4ea4\u4e92\u4e5f\u662f\u6b63\u5e38\u7684\u3002<\/p>\n<p style=\"margin-top: 10px; margin-bottom: 10px; text-indent: 0em;\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-242e8d108eb72439c3a8b42c3c8ceaa5.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" class=\"rich_pages wxw-img\" data-original=\"https:\/\/www.xh86.me\/wp-content\/uploads\/2022\/04\/wxsync-2022-04-242e8d108eb72439c3a8b42c3c8ceaa5.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" data-ratio=\"0.7340553549939831\" data-type=\"png\" data-w=\"831\" \/><\/div><\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u770b\u6765strongSwan\u548cH3C\u7684IPsec\u5bf9\u63a5\u4e5f\u4e0d\u96be\u554a\uff01<\/p>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">\u6700\u540e\u7ed9\u4e00\u4efd\u5b8c\u6574\u7684\u8bbe\u5907\u914d\u7f6e\u3002<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"makefile\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\"># cat \/etc\/strongswan\/ipsec.conf<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">conn swan<\/span><\/code><code><span class=\"code-snippet_outer\">  authby = psk<\/span><\/code><code><span class=\"code-snippet_outer\">  keyexchange=ikev1<\/span><\/code><code><span class=\"code-snippet_outer\">  left=12.1.1.1<\/span><\/code><code><span class=\"code-snippet_outer\">  leftid=12.1.1.1<\/span><\/code><code><span class=\"code-snippet_outer\">  leftsubnet=11.1.1.0\/24<\/span><\/code><code><span class=\"code-snippet_outer\">  right=12.1.1.2<\/span><\/code><code><span class=\"code-snippet_outer\">  rightid=12.1.1.2<\/span><\/code><code><span class=\"code-snippet_outer\">  rightsubnet=22.1.1.0\/24<\/span><\/code><code><span class=\"code-snippet_outer\">  auto=route<\/span><\/code><code><span class=\"code-snippet_outer\">  ike = aes128-sha256-modp1024<\/span><\/code><code><span class=\"code-snippet_outer\">  esp = aes128-sha256<\/span><\/code><code><span class=\"code-snippet_outer\">  ikelifetime=86400<\/span><\/code><\/pre>\n<\/section>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"nginx\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\"># cat \/etc\/strongswan\/ipsec.secrets<\/span><\/span><\/code><code><span class=\"code-snippet_outer\">12.1.1.1 12.1.1.2 : <span class=\"code-snippet__attribute\">PSK<\/span> swan<\/span><\/code><\/pre>\n<\/section>\n<p style=\"text-indent: 2em; margin-top: 10px; margin-bottom: 10px;\">VSR\u914d\u7f6e\uff1a<\/p>\n<section class=\"code-snippet__fix code-snippet__js\">\n<pre class=\"code-snippet__js\" data-lang=\"properties\"><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">interface<\/span> <span class=\"code-snippet__string\">GigabitEthernet3\/0<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">ipsec<\/span> <span class=\"code-snippet__string\">apply policy swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">acl<\/span> <span class=\"code-snippet__string\">advanced 3402<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">rule<\/span> <span class=\"code-snippet__string\">0 permit ip source 22.1.1.0 0.0.0.255 destination 11.1.1.0 0.0.0.255<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">ipsec<\/span> <span class=\"code-snippet__string\">transform-set swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">esp<\/span> <span class=\"code-snippet__string\">encryption-algorithm aes-cbc-128<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">esp<\/span> <span class=\"code-snippet__string\">authentication-algorithm sha256<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">ipsec<\/span> <span class=\"code-snippet__string\">policy swan 10 isakmp<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">transform-set<\/span> <span class=\"code-snippet__string\">swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">security<\/span> <span class=\"code-snippet__string\">acl 3402<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">local-address<\/span> <span class=\"code-snippet__string\">12.1.1.2<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">remote-address<\/span> <span class=\"code-snippet__string\">12.1.1.1<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">ike-profile<\/span> <span class=\"code-snippet__string\">swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">ike<\/span> <span class=\"code-snippet__string\">profile swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">keychain\u00a0swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">local-identity<\/span> <span class=\"code-snippet__string\">address 12.1.1.2<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">match<\/span> <span class=\"code-snippet__string\">remote identity address 12.1.1.1 255.255.255.0<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">proposal<\/span> <span class=\"code-snippet__string\">10<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">ike<\/span> <span class=\"code-snippet__string\">proposal 10<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">encryption-algorithm<\/span> <span class=\"code-snippet__string\">aes-cbc-128<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__attr\">dh<\/span> <span class=\"code-snippet__string\">group2<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">authentication-algorithm<\/span> <span class=\"code-snippet__string\">sha256<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__comment\">#<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"><span class=\"code-snippet__attr\">ike<\/span> <span class=\"code-snippet__string\">keychain swan<\/span><\/span><\/code><code><span class=\"code-snippet_outer\"> <span class=\"code-snippet__meta\">pre-shared-key<\/span> <span class=\"code-snippet__string\">address 12.1.1.1 255.255.255.0 key simple swan<\/span><\/span><\/code><\/pre>\n<\/section>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; strongSwan\u662f\u4e00\u4e2a\u5f00\u6e90\u7684\u57fa\u4e8eIPsec\u7684VPN\u89e3\u51b3\u65b9\u6848\uff0c\u7ecf\u8fc7\u524d\u9762\u51e0\u7bc7\u6587\u7ae0\u7684\u94fa\u57ab\uff0c\u4eca\u5929\u7ec8\u4e8e [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,2],"tags":[],"class_list":["post-7681","post","type-post","status-publish","format-standard","hentry","category-19","category-network"],"_links":{"self":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts\/7681","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7681"}],"version-history":[{"count":1,"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts\/7681\/revisions"}],"predecessor-version":[{"id":7752,"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts\/7681\/revisions\/7752"}],"wp:attachment":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7681"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7681"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7681"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}