<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de">
	<id>https://kb.pocnet.net/index.php?action=history&amp;feed=atom&amp;title=IPSEC-VPN_Openswan_mit_IPv6</id>
	<title>IPSEC-VPN Openswan mit IPv6 - Versionsgeschichte</title>
	<link rel="self" type="application/atom+xml" href="https://kb.pocnet.net/index.php?action=history&amp;feed=atom&amp;title=IPSEC-VPN_Openswan_mit_IPv6"/>
	<link rel="alternate" type="text/html" href="https://kb.pocnet.net/index.php?title=IPSEC-VPN_Openswan_mit_IPv6&amp;action=history"/>
	<updated>2026-05-02T09:46:56Z</updated>
	<subtitle>Versionsgeschichte dieser Seite in Knowledgebase</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://kb.pocnet.net/index.php?title=IPSEC-VPN_Openswan_mit_IPv6&amp;diff=683&amp;oldid=prev</id>
		<title>PoC: Link</title>
		<link rel="alternate" type="text/html" href="https://kb.pocnet.net/index.php?title=IPSEC-VPN_Openswan_mit_IPv6&amp;diff=683&amp;oldid=prev"/>
		<updated>2010-09-08T17:58:08Z</updated>

		<summary type="html">&lt;p&gt;Link&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Dies ist eine Musterkonfiguration für ein Site2Site-VPN zwischen &amp;#039;&amp;#039;&amp;#039;Openswan&amp;#039;&amp;#039;&amp;#039; unter Linux mit &amp;#039;&amp;#039;&amp;#039;IPv6&amp;#039;&amp;#039;&amp;#039; und Pre-Shared-Key. Wie das ganze mit RSA-Keys geht, siehe [[Openswan-VPN mit RSA-Signaturen]].&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;/etc/ipsec.secrets&amp;#039;&amp;#039; (relevanter Ausschnitt):&lt;br /&gt;
 2001:6f8:1296:1:210:18ff:fe06:7c06 2001:6f8:1176:0:200:92ff:fe93:501c : PSK &amp;quot;ug8uLu0aiqueetah5ush2yoghieh7phu&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;/etc/ipsec.conf&amp;#039;&amp;#039; (relevanter Ausschnitt):&lt;br /&gt;
 conn leela-ci-v6&lt;br /&gt;
        connaddrfamily=ipv6&lt;br /&gt;
        left=2001:6f8:1296:1:210:18ff:fe06:7c06&lt;br /&gt;
        right=2001:6f8:1176:0:200:92ff:fe93:501c&lt;br /&gt;
        type=transport&lt;br /&gt;
        authby=secret&lt;br /&gt;
        auto=start&lt;br /&gt;
        dpdaction=restart&lt;br /&gt;
        ike=aes256-sha1&lt;br /&gt;
        esp=aes256-sha1&lt;br /&gt;
        compress=yes&lt;br /&gt;
&lt;br /&gt;
Danach muß die Konfiguration neu eingelesen und die Connection gestartet werden:&lt;br /&gt;
 ipsec auto --rereadall&lt;br /&gt;
 ipsec auto --up leela-ci-v6&lt;br /&gt;
&lt;br /&gt;
 ipsec auto --status |fgrep leela-ci-v6&lt;br /&gt;
 000 &amp;quot;leela-ci-v6&amp;quot;: 2001:6f8:1296:1:210:18ff:fe06:7c06...2001:6f8:1176:0:200:92ff:fe93:501c; erouted; eroute owner: #79&lt;br /&gt;
 000 &amp;quot;leela-ci-v6&amp;quot;:     srcip=unset; dstip=unset; srcup=ipsec _updown; dstup=ipsec _updown;&lt;br /&gt;
 000 &amp;quot;leela-ci-v6&amp;quot;:   ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0&lt;br /&gt;
 000 &amp;quot;leela-ci-v6&amp;quot;:   policy: PSK+ENCRYPT+COMPRESS+PFS; prio: 128,128; interface: eth0; encap: esp;&lt;br /&gt;
 000 &amp;quot;leela-ci-v6&amp;quot;:   newest ISAKMP SA: #78; newest IPsec SA: #79; &lt;br /&gt;
 000 &amp;quot;leela-ci-v6&amp;quot;:   IKE algorithms wanted: AES_CBC(7)_256-SHA1(2)-MODP1536(5), AES_CBC(7)_256-SHA1(2)-MODP1024(2); flags=strict&lt;br /&gt;
 000 &amp;quot;leela-ci-v6&amp;quot;:   IKE algorithms found: AES_CBC(7)_256-SHA1(2)_160-MODP1536(5), AES_CBC(7)_256-SHA1(2)_160-MODP1024(2)&lt;br /&gt;
 000 &amp;quot;leela-ci-v6&amp;quot;:   IKE algorithm newest: AES_CBC_256-SHA1-MODP1536&lt;br /&gt;
 000 &amp;quot;leela-ci-v6&amp;quot;:   ESP algorithms wanted: AES(12)_256-SHA1(2); flags=strict&lt;br /&gt;
 000 &amp;quot;leela-ci-v6&amp;quot;:   ESP algorithms loaded: AES(12)_256-SHA1(2); flags=strict&lt;br /&gt;
 000 &amp;quot;leela-ci-v6&amp;quot;:   ESP algorithm newest: AES_256-HMAC_SHA1; pfsgroup=&amp;lt;Phase1&amp;gt;&lt;br /&gt;
 000 #79: &amp;quot;leela-ci-v6&amp;quot;:500 STATE_QUICK_R2 (IPsec SA established); EVENT_SA_REPLACE in 26429s; newest IPSEC; eroute owner&lt;br /&gt;
 000 #79: &amp;quot;leela-ci-v6&amp;quot; esp:ba6cb75d@2001:6f8:1176:0:200:92ff:fe93:501c esp:e1b7909e@2001:6f8:1296:1:210:18ff:fe06:7c06 comp:eb21@2001:6f8:1176:0:200:92ff:fe93:501c comp:d2b3@2001:6f8:1296:1:210:18ff:fe06:7c06&lt;br /&gt;
 000 #78: &amp;quot;leela-ci-v6&amp;quot;:500 STATE_MAIN_R3 (sent MR3, ISAKMP SA established); EVENT_SA_REPLACE in 1228s; newest ISAKMP; lastdpd=-1s(seq in:0 out:0)&lt;br /&gt;
&lt;br /&gt;
[[Kategorie:Linux]]&lt;br /&gt;
[[Kategorie:Crypto]]&lt;br /&gt;
[[Kategorie:Netzwerk]]&lt;br /&gt;
[[Kategorie:Internet]]&lt;/div&gt;</summary>
		<author><name>PoC</name></author>
	</entry>
</feed>