Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
Building And Integrating Virtual Private Networks With Openswan (2006).pdf
Скачиваний:
78
Добавлен:
17.08.2013
Размер:
4.74 Mб
Скачать

Chapter 9

NETGEAR

The configuration of NETGEAR devices, such as the FVS318, is straightforward. The terms are slightly different but speak for themselves. The following is a pre-shared key configuration example:

Connectionname

YourConnName

Local IPsec Identifier

YourRightID

Remote IPsec Identifier

YourLeftID

Tunnel can be accessed from

any local address

Local LAN start IP Address

YourNetworkAddress

Local LAN finish IP Address

YourBroadcastAddress (may be empty)

Local LAN IP Subnetmask

Your SubnetMask

Tunnel can access

a subnet of remote address

Remote LAN start IP Address

OpenswanNetworkAddress

Remote LAN finish IP Address

OpenswanBroadcastAddress (may be empty)

Remote LAN IP Subnetmask

Openswan SubnetMask

Remote WAN IP or FQDN

Openswan hostname/ip address

Secure Association

Main Mode

Perfect Forward Secrecy

Enabled

Encryption Protocol

3DES

PreSharedKey

YourPreSharedKey

KeyLife

86600

IKE Life Time

28800

NETBIOS enable

<ticked>

KAME/Racoon

KAME has split off the IKE protocol from the SPD/SAD kernel entries. The IKE daemon is called Racoon and handles all the key management. The setkey binary is used to load the proper policies into the kernel. Unfortunately, Racoon does not call setkey for you, and you need to do all the work yourself. This makes automating KAME much harder. Another problem of Racoon is that you need to restart all its IKE connections when you make a change to its configuration, for example if you wish to just add one client.

Chapter 8 has an example of the Racoon configuration file with a setkey script. Mac OS X uses Racoon as well, but adds a GUI layer on top of it that can create Racoon configuration files. You can find instructions for Mac OS X in Chapter 8 as well.

Aftercare

If your interop has been successful, it is time to back up all your configurations as a precaution. This can be done using the device's backup mode, or if the device does not have such an option, by creating screenshots. If the remote end you hooked up to Openswan is a leaf node, it is worth powercycling the appliance to make sure it is able to come back up again without configuration changes. It also will confirm that the configuration running on that device is the same as the saved configuration.

233

Interoperating with Other Vendors

Summary

We have discussed a few devices in great detail to give you an idea of the options available for IPsec appliances. We have discussed several common devices that people need to connect to and the common problems associated with those. It is always a good idea to Google for the latest information on these interop issues. With the information of this chapter, you are hopefully wellenough armed to handle any of the new devices that will undoubtedly hit the market in the next few years.

234