upgraded gcrypt-ikev2 scenarios to 5.0.0
This commit is contained in:
parent
44bd9b48c8
commit
04d7b1725d
|
@ -1,11 +1,13 @@
|
||||||
moon::ipsec statusall::rw.*INSTALLED::YES
|
moon:: ipsec status 2> /dev/null::rw.*ESTABLISHED.*moon.strongswan.org.*carol@strongswan.org::YES
|
||||||
carol::ipsec statusall::home.*INSTALLED::YES
|
carol::ipsec status 2> /dev/null::home.*ESTABLISHED.*carol@strongswan.org.*moon.strongswan.org::YES
|
||||||
moon::ipsec statusall::IKE proposal: CAMELLIA_CBC_256/HMAC_SHA2_512_256/PRF_HMAC_SHA2_512/MODP_2048::YES
|
moon:: ipsec status 2> /dev/null::rw.*INSTALLED, TUNNEL::YES
|
||||||
carol::ipsec statusall::IKE proposal: CAMELLIA_CBC_256/HMAC_SHA2_512_256/PRF_HMAC_SHA2_512/MODP_2048::YES
|
carol::ipsec status 2> /dev/null::home.*INSTALLED, TUNNEL::YES
|
||||||
|
moon:: ipsec statusall 2> /dev/null::IKE proposal: CAMELLIA_CBC_256/HMAC_SHA2_512_256/PRF_HMAC_SHA2_512/MODP_2048::YES
|
||||||
|
carol::ipsec statusall 2> /dev/null::IKE proposal: CAMELLIA_CBC_256/HMAC_SHA2_512_256/PRF_HMAC_SHA2_512/MODP_2048::YES
|
||||||
carol::ping -c 1 -s 120 -p deadbeef PH_IP_ALICE::128 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
carol::ping -c 1 -s 120 -p deadbeef PH_IP_ALICE::128 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
||||||
moon::ipsec statusall::CAMELLIA_CBC_192/HMAC_SHA1_96::YES
|
moon:: ipsec statusall 2> /dev/null::CAMELLIA_CBC_192/HMAC_SHA2_384_192::YES
|
||||||
carol::ipsec statusall::CAMELLIA_CBC_192/HMAC_SHA1_96::YES
|
carol::ipsec statusall 2> /dev/null::CAMELLIA_CBC_192/HMAC_SHA2_384_192::YES
|
||||||
moon::ip xfrm state::enc cbc(camellia)::YES
|
moon:: ip xfrm state::enc cbc(camellia)::YES
|
||||||
carol::ip xfrm state::enc cbc(camellia)::YES
|
carol::ip xfrm state::enc cbc(camellia)::YES
|
||||||
moon::tcpdump::IP carol.strongswan.org > moon.strongswan.org: ESP.*length 196::YES
|
moon::tcpdump::IP carol.strongswan.org > moon.strongswan.org: ESP.*length 208::YES
|
||||||
moon::tcpdump::IP moon.strongswan.org > carol.strongswan.org: ESP.*length 196::YES
|
moon::tcpdump::IP moon.strongswan.org > carol.strongswan.org: ESP.*length 208::YES
|
||||||
|
|
|
@ -1,8 +1,6 @@
|
||||||
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
||||||
|
|
||||||
config setup
|
config setup
|
||||||
crlcheckinterval=180
|
|
||||||
strictcrlpolicy=yes
|
|
||||||
plutostart=no
|
plutostart=no
|
||||||
|
|
||||||
conn %default
|
conn %default
|
||||||
|
@ -12,7 +10,7 @@ conn %default
|
||||||
keyingtries=1
|
keyingtries=1
|
||||||
keyexchange=ikev2
|
keyexchange=ikev2
|
||||||
ike=camellia256-sha512-modp2048!
|
ike=camellia256-sha512-modp2048!
|
||||||
esp=camellia192-sha1!
|
esp=camellia192-sha384!
|
||||||
|
|
||||||
conn home
|
conn home
|
||||||
left=PH_IP_CAROL
|
left=PH_IP_CAROL
|
||||||
|
|
|
@ -1,8 +1,6 @@
|
||||||
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
||||||
|
|
||||||
config setup
|
config setup
|
||||||
crlcheckinterval=180
|
|
||||||
strictcrlpolicy=yes
|
|
||||||
plutostart=no
|
plutostart=no
|
||||||
|
|
||||||
conn %default
|
conn %default
|
||||||
|
@ -12,7 +10,7 @@ conn %default
|
||||||
keyingtries=1
|
keyingtries=1
|
||||||
keyexchange=ikev2
|
keyexchange=ikev2
|
||||||
ike=camellia256-sha512-modp2048!
|
ike=camellia256-sha512-modp2048!
|
||||||
esp=camellia192-sha1!
|
esp=camellia192-sha384!
|
||||||
|
|
||||||
conn rw
|
conn rw
|
||||||
left=PH_IP_MOON
|
left=PH_IP_MOON
|
||||||
|
|
|
@ -1,10 +1,14 @@
|
||||||
moon::ipsec statusall::rw.*ESTABLISHED::YES
|
carol::ipsec status 2> /dev/null::home.*ESTABLISHED.*carol@strongswan.org.*moon.strongswan.org::YES
|
||||||
carol::ipsec statusall::home.*ESTABLISHED::YES
|
dave:: ipsec status 2> /dev/null::home.*ESTABLISHED.*dave@strongswan.org.*moon.strongswan.org::YES
|
||||||
dave::ipsec statusall::home.*ESTABLISHED::YES
|
moon:: ipsec status 2> /dev/null::rw\[1]: ESTABLISHED.*moon.strongswan.org.*carol@strongswan.org::YES
|
||||||
|
moon:: ipsec status 2> /dev/null::rw\[2]: ESTABLISHED.*moon.strongswan.org.*dave@strongswan.org::YES
|
||||||
|
carol::ipsec status 2> /dev/null::home.*INSTALLED, TUNNEL::YES
|
||||||
|
dave:: ipsec status 2> /dev/null::home.*INSTALLED, TUNNEL::YES
|
||||||
|
moon:: ipsec status 2> /dev/null::rw[{]1}.*INSTALLED, TUNNEL::YES
|
||||||
|
moon:: ipsec status 2> /dev/null::rw[{]2}.*INSTALLED, TUNNEL::YES
|
||||||
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
||||||
dave::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
dave:: ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
||||||
moon::tcpdump::IP carol.strongswan.org > moon.strongswan.org: ESP::YES
|
moon::tcpdump::IP carol.strongswan.org > moon.strongswan.org: ESP::YES
|
||||||
moon::tcpdump::IP moon.strongswan.org > carol.strongswan.org: ESP::YES
|
moon::tcpdump::IP moon.strongswan.org > carol.strongswan.org: ESP::YES
|
||||||
moon::tcpdump::IP dave.strongswan.org > moon.strongswan.org: ESP::YES
|
moon::tcpdump::IP dave.strongswan.org > moon.strongswan.org: ESP::YES
|
||||||
moon::tcpdump::IP moon.strongswan.org > dave.strongswan.org: ESP::YES
|
moon::tcpdump::IP moon.strongswan.org > dave.strongswan.org: ESP::YES
|
||||||
|
|
||||||
|
|
|
@ -1,8 +1,6 @@
|
||||||
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
||||||
|
|
||||||
config setup
|
config setup
|
||||||
crlcheckinterval=180
|
|
||||||
strictcrlpolicy=no
|
|
||||||
plutostart=no
|
plutostart=no
|
||||||
|
|
||||||
conn %default
|
conn %default
|
||||||
|
@ -12,6 +10,7 @@ conn %default
|
||||||
keyingtries=1
|
keyingtries=1
|
||||||
keyexchange=ikev2
|
keyexchange=ikev2
|
||||||
ike=3des-sha1-modp1536!
|
ike=3des-sha1-modp1536!
|
||||||
|
esp=3des-sha1!
|
||||||
|
|
||||||
conn home
|
conn home
|
||||||
left=PH_IP_CAROL
|
left=PH_IP_CAROL
|
||||||
|
|
|
@ -1,8 +1,6 @@
|
||||||
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
||||||
|
|
||||||
config setup
|
config setup
|
||||||
crlcheckinterval=180
|
|
||||||
strictcrlpolicy=no
|
|
||||||
plutostart=no
|
plutostart=no
|
||||||
|
|
||||||
conn %default
|
conn %default
|
||||||
|
@ -11,7 +9,8 @@ conn %default
|
||||||
rekeymargin=3m
|
rekeymargin=3m
|
||||||
keyingtries=1
|
keyingtries=1
|
||||||
keyexchange=ikev2
|
keyexchange=ikev2
|
||||||
ike=aes256-sha256-modp2048!
|
ike=aes256-sha512-modp2048!
|
||||||
|
esp=aes256-sha512!
|
||||||
|
|
||||||
conn home
|
conn home
|
||||||
left=PH_IP_DAVE
|
left=PH_IP_DAVE
|
||||||
|
|
|
@ -1,8 +1,6 @@
|
||||||
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
||||||
|
|
||||||
config setup
|
config setup
|
||||||
crlcheckinterval=180
|
|
||||||
strictcrlpolicy=no
|
|
||||||
plutostart=no
|
plutostart=no
|
||||||
|
|
||||||
conn %default
|
conn %default
|
||||||
|
@ -11,7 +9,8 @@ conn %default
|
||||||
rekeymargin=3m
|
rekeymargin=3m
|
||||||
keyingtries=1
|
keyingtries=1
|
||||||
keyexchange=ikev2
|
keyexchange=ikev2
|
||||||
ike=aes256-sha256-modp2048,3des-sha1-modp1536!
|
ike=aes256-sha512-modp2048,3des-sha1-modp1536!
|
||||||
|
esp=aes256-sha512,3des-sha1!
|
||||||
|
|
||||||
conn rw
|
conn rw
|
||||||
left=PH_IP_MOON
|
left=PH_IP_MOON
|
||||||
|
|
Loading…
Reference in New Issue