<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="lt">
	<id>https://wiki.eofnet.lt/w//index.php?action=history&amp;feed=atom&amp;title=Libreswan</id>
	<title>Libreswan - Versijų istorija</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.eofnet.lt/w//index.php?action=history&amp;feed=atom&amp;title=Libreswan"/>
	<link rel="alternate" type="text/html" href="https://wiki.eofnet.lt/w//index.php?title=Libreswan&amp;action=history"/>
	<updated>2026-04-21T09:57:33Z</updated>
	<subtitle>Šio puslapio versijų istorija projekte</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://wiki.eofnet.lt/w//index.php?title=Libreswan&amp;diff=8825&amp;oldid=prev</id>
		<title>\dev\null 13:57, 5 balandžio 2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.eofnet.lt/w//index.php?title=Libreswan&amp;diff=8825&amp;oldid=prev"/>
		<updated>2019-04-05T13:57:29Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Naujas puslapis&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Libreswan yra site to site [[vpn]] [[ipsec]] klientas.&lt;br /&gt;
&lt;br /&gt;
== Ubuntu 16.04 diegimas ==&lt;br /&gt;
&lt;br /&gt;
 # apt-get install devscripts libunbound-dev libevent-dev  libsystemd-dev libnss3-dev libnspr4-dev pkg-config libcap-ng-dev libcap-ng-utils libselinux1-dev libcurl4-nss-dev flex bison gcc make libnss3-tools libldns-dev xmlto dh-systemd htmldoc libaudit-dev libldap2-dev libnss3-tools man2html po-debconf&lt;br /&gt;
 # wget https://download.libreswan.org/libreswan-3.27.tar.gz&lt;br /&gt;
 # tar xzf libreswan-3.27.tar.gz&lt;br /&gt;
 # cd libreswan-3.27&lt;br /&gt;
 # echo USE_GLIBC_KERN_FLIP_HEADERS=true &amp;gt;&amp;gt; Makefile.inc.local&lt;br /&gt;
 # make all&lt;br /&gt;
 # make deb&lt;br /&gt;
 # cd ..;dpkg -i libreswan_3.27-1_amd64.deb &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Kliento konfigūracija&lt;br /&gt;
* /etc/ipsec.d/tinklas.conf&lt;br /&gt;
 config setup&lt;br /&gt;
    protostack=netkey&lt;br /&gt;
 conn tinklas&lt;br /&gt;
        type=tunnel&lt;br /&gt;
        authby=secret&lt;br /&gt;
        ikelifetime=1800s&lt;br /&gt;
        keylife=1800s&lt;br /&gt;
        ike=aes256-sha1;modp1536&lt;br /&gt;
        phase2alg=aes256-sha1;modp1536&lt;br /&gt;
        keyexchange=ike&lt;br /&gt;
        pfs=yes&lt;br /&gt;
 #lokalus klientas&lt;br /&gt;
        left=vidinis_ip&lt;br /&gt;
        leftsubnet=vidinis_ip/32&lt;br /&gt;
 #nutoles serveris&lt;br /&gt;
        right=nutoles_ip&lt;br /&gt;
        rightsubnets=nutoles_vidinis_ip/32&lt;br /&gt;
        auto=start&lt;br /&gt;
* /etc/ipsec.d/tinklas.secrets&lt;br /&gt;
 vidinis_ip Nutoles_ip: PSK &amp;quot;Preshared-keyus&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Komandos ==&lt;br /&gt;
Vidinės konfigūracijos tikrinimas (bet kokiu atveju, privalomas patikrinimas, ar sistema paruošta korektiškai veikti):&lt;br /&gt;
 ipsec verify&lt;br /&gt;
Visiškas serviso perkrovimas:&lt;br /&gt;
 service ipsec --full-restart&lt;br /&gt;
Prisijungimo pridėjimas&lt;br /&gt;
 ipsec auto --add tinklas&lt;br /&gt;
Bandymas jungtis:&lt;br /&gt;
 ipsec auto --up tinklas&lt;br /&gt;
Slaptažodžių/šifrų nuskaitymas:&lt;br /&gt;
 ipsec auto --rereadsecrets&lt;br /&gt;
Prisijungimo pakeitimas pakeitus jo konfigūraciją:&lt;br /&gt;
 ipsec auto --replace &amp;lt;connection&amp;gt;&lt;br /&gt;
Statusas:&lt;br /&gt;
 ipsec status&lt;br /&gt;
&lt;br /&gt;
IP info ir statusai:&lt;br /&gt;
 ip xfrm pol&lt;br /&gt;
 ip xfrm state&lt;br /&gt;
&lt;br /&gt;
Static route'ai:&lt;br /&gt;
''Kai kuriose libreswan versijose aptiktas bugas kuris nesudeda automatinių route'ų, todėl juos reikia nustatyti rankomis:''&lt;br /&gt;
 route add -net &amp;lt;nutoles_vidinis_subnet/24&amp;gt; gw &amp;lt;lokalus_vidinis_ip&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
== forwardas iš tinklo į serverį su vpn, tam tikro porto ==&lt;br /&gt;
 iptables -t nat -A PREROUTING -p tcp --dport 25 -j DNAT --to-destination VPN_IP:25&lt;br /&gt;
 iptables -t nat -A POSTROUTING -p tcp -d VPN_IP --dport 25 -j SNAT --to-source LOCAL_IP&lt;br /&gt;
&lt;br /&gt;
== Fail? ==&lt;br /&gt;
Žiūrim /var/log/auth.log ir /var/log/syslog&lt;br /&gt;
TCP/IP Debuginimas:&lt;br /&gt;
 tcpdump -n -i eth0 esp or udp port 500 or udp port 4500&lt;br /&gt;
&lt;br /&gt;
[[Category:Tinklas]]&lt;br /&gt;
[[Category:VPN]]&lt;br /&gt;
{{Template:Distributions}}&lt;/div&gt;</summary>
		<author><name>\dev\null</name></author>
	</entry>
</feed>