Хабр Курсы для всех
РЕКЛАМА
Практикум, Хекслет, SkyPro, авторские курсы — собрали всех и попросили скидки. Осталось выбрать!
path pre_shared_key "/etc/racoon/psk.txt";
path certificate "/etc/racoon/certs";
listen {
isakmp #{src_ip} [500];
isakmp_natt #{src_ip} [4500];
}
remote anonymous {
proposal_check obey;
passive on;
exchange_mode main,aggressive;
my_identifier fqdn "#{host_fqdn}";
mode_cfg on;
verify_cert off;
ike_frag on;
generate_policy on;
nat_traversal on;
dpd_delay 20;
proposal {
encryption_algorithm aes;
hash_algorithm sha1;
authentication_method xauth_psk_server;
dh_group 2;
}
}
mode_cfg {
conf_source local;
auth_source system;
save_passwd on;
dns4 8.8.8.8;
network4 10.0.0.1;
pool_size 255;
}
sainfo anonymous {
encryption_algorithm aes;
authentication_algorithm hmac_sha1;
compression_algorithm deflate;
}
save_passwd on
log debug;
path certificate "/etc/racoon/certs";
listen {
isakmp ip.add.re.ss [500];
isakmp_natt ip.add.re.ss [4500];
}
remote anonymous {
lifetime time 24 hour;
proposal_check obey;
passive on;
exchange_mode aggressive,main;
my_identifier asn1dn;
peers_identifier asn1dn;
verify_identifier on;
certificate_type x509 "server.crt" "server.key";
ca_type x509 "ca.crt";
mode_cfg on;
verify_cert on;
ike_frag on;
generate_policy on;
nat_traversal on;
dpd_delay 20;
proposal {
encryption_algorithm aes;
hash_algorithm sha1;
authentication_method xauth_rsa_server;
dh_group modp1024;
}
}
mode_cfg {
conf_source local;
auth_source system;
auth_throttle 3;
save_passwd on;
dns4 8.8.8.8;
network4 10.9.8.1;
netmask4 255.255.255.0;
pool_size 128;
}
sainfo anonymous {
pfs_group 2;
lifetime time 3600 sec;
encryption_algorithm aes;
authentication_algorithm hmac_sha1;
compression_algorithm deflate;
}
save_passwd on во время первого подключения, то он больше его не проверяет и всегда запрашивает пароль, даже если конфиг сервера потом поменять. Помогает удаление профиля VPN на устройстве и создание нового.auth_source system, а параметра path pre_shared_key я не вижу. Работать не должно. Серверу надо знать, как проверять имя-пароль.Oct 30 22:42:41 iPhone racoon[151] <Notice>: IPSec Extended Authentication Passed. Oct 30 22:42:41 iPhone racoon[151] <Notice>: IPSec Network Configuration requested. Oct 30 22:42:41 iPhone racoon[151] <Warning>: Ignored attribute APPLICATION_VERSION Oct 30 22:42:41 iPhone racoon[151] <Warning>: Ignored short attribute UNITY_SAVE_PASSWD Oct 30 22:42:41 iPhone racoon[151] <Notice>: IPSec Network Configuration established. Oct 30 22:42:41 iPhone racoon[151] <Notice>: >>>>> phase change status = phase 1 established
pppd[10746]: IPSec connection started
racoon[1193]: Connecting.
racoon[1193]: IPSec Phase1 started (Initiated by me).
racoon[1193]: IKE Packet: transmit success. (Initiator, Main-Mode message 1).
racoon[1193]: IKE Packet: transmit success. (Phase1 Retransmit).
--- last message repeated 2 times ---
pppd[10746]: IPSec connection failed
VPN для iPhone