实验内容:
利用strongswan软件和多台ubuntu虚拟机搭建IPsec 环境,使用场景为 site to site,认证方式为PSK,密钥交换协议为IKEv1;
实验步骤:
1.下载strongswan
sudo apt install strongswan
2.编辑文件,加载配置
配置ipsec.conf
config setup
conn %default
ikelifetime=1440m
keylife=60m
rekeymargin=3m
keyingtries=0
keyexchange=ikev1
authby=secret
conn snt
left=192.168.78.130
leftsubnet=192.168.10.0/24
leftid=192.168.78.130
right=192.168.78.131
rightsubnet=192.168.20.0/24
rightid=192