<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Archives des IPsec - CoffeeBreak Info</title>
	<atom:link href="https://coffeebreak.en-images.info/tag/ipsec/feed/" rel="self" type="application/rss+xml" />
	<link>https://coffeebreak.en-images.info/tag/ipsec/</link>
	<description>Une petite pause :)</description>
	<lastBuildDate>Wed, 25 May 2022 16:49:27 +0000</lastBuildDate>
	<language>fr-FR</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://coffeebreak.en-images.info/wp-content/uploads/2021/07/cropped-Tasse_Cafe-scaled-1-32x32.jpg</url>
	<title>Archives des IPsec - CoffeeBreak Info</title>
	<link>https://coffeebreak.en-images.info/tag/ipsec/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>MODOP installation VPN IPsec – Host to Host</title>
		<link>https://coffeebreak.en-images.info/modop-installation-vpn-ipsec-host-to-host/</link>
					<comments>https://coffeebreak.en-images.info/modop-installation-vpn-ipsec-host-to-host/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Wed, 25 May 2022 16:49:25 +0000</pubDate>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[IPsec]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[RockyLinux]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6626</guid>

					<description><![CDATA[<p>MODOP sur la mise en place de IPsec  (Internet Protocol Security) entre deux machines clientes et de réseaux différents et cela afin d’assurer des communications privées et sécurisées via IP. Le But est de chiffrer et s’identifier auprès d’un hosts grâce à un échange de clefs Publiques host-to-host. IPsec se différencie de la plupart des systèmes des services pour la protection des réseaux IP car il fonctionne sur la couche 3 du modèle OSI. De fait, aucune application nécessaire à paramétrer. </p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-vpn-ipsec-host-to-host/">MODOP installation VPN IPsec – Host to Host</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3><span style="color: #003300;">Spécification de la machine vpn-ipsec-left.house.cpb</span></h3>
<p>Host&nbsp;: <strong>vpn-ipsec-left.house.cpb</strong></p>
<ul>
<li><strong>IP&nbsp;:192.168.1.56</strong></li>
<li>OS&nbsp;: <strong>RockyLinux</strong></li>
<li>vCPU&nbsp;: 2</li>
<li>DD&nbsp;: 8Go</li>
<li>Ram&nbsp;: 2Go</li>
</ul>
<h3>Spécification de la machine <span style="color: #003300;">vpn-ipsec-right.house.cpb</span></h3>
<p>Host&nbsp;: <strong>vpn-ipsec-right.house.cpb</strong></p>
<ul>
<li><strong>IP&nbsp;:172.32.185.31</strong></li>
<li>OS&nbsp;: <strong>RockyLinux </strong></li>
<li>vCPU&nbsp;: 2</li>
<li>DD&nbsp;: 8Go</li>
<li>Ram&nbsp;: 2Go</li>
</ul>
<h1 style="text-align: left;"><span style="color: #000000;">Machine vpn-ipsec-left.house.cpb – Site A</span></h1>
<p>Host&nbsp;: <strong>vpn-ipsec-left.house.cpb</strong></p>
<ul>
<li>vSwitch&nbsp;: <strong>vmbr0</strong>
<ul>
<li><strong>IP&nbsp;:192.168.1.56</strong></li>
</ul>
</li>
<li>OS&nbsp;: <strong>RockyLinux 8.4</strong></li>
<li>vCPU&nbsp;: 2</li>
<li>DD&nbsp;: 8Go</li>
<li>Ram&nbsp;: 2Go</li>
</ul>
<h3><span style="color: #003300;">Update de la machine</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">dnf -y update</span></pre>
<h3><span style="color: #000000;">TimeDate</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">timedatectl set-timezone "Europe/Paris"</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">timedatectl</span></pre>
<p><img fetchpriority="high" decoding="async" width="695" height="144" class="wp-image-6628" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-176.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-176.png 695w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-176-300x62.png 300w" sizes="(max-width: 695px) 100vw, 695px" /></p>
<h3><span style="color: #000000;">Ajout des hosts machines (si pas de DNS)</span></h3>
<pre>[root@vpn-ipsec-left ~]#<span style="color: #ff0000;"> echo "192.168.1.56 vpn-ipsec-left vpn-ipsec-left.house.cpb" &gt;&gt; /etc/hosts</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">echo "172.32.185.31 vpn-ipsec-right vpn-ipsec-right.house.cpb" &gt;&gt; /etc/hosts</span></pre>
<h3><span style="color: #000000;">Désactiver «&nbsp;rp_filter&nbsp;» de Libreswan</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">echo "net.ipv4.conf.all.rp_filter = 0" &gt;&gt; /etc/sysctl.d/50-libreswan.conf</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">sysctl --system</span></pre>
<h3><span style="color: #000000;">Installation package</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">yum install libreswan</span></pre>
<p><img decoding="async" width="1603" height="264" class="wp-image-6629" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-177.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-177.png 1603w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-177-300x49.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-177-1024x169.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-177-768x126.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-177-1536x253.png 1536w" sizes="(max-width: 1603px) 100vw, 1603px" /></p>
<h3><span style="color: #000000;">Initialiser la base nss</span></h3>
<pre>[root@vpn-ipsec-left ~]#<span style="color: #ff0000;"> systemctl stop ipsec</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">rm -f /etc/ipsec.d/*db</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ls -al /etc/ipsec.d/</span></pre>
<p><img decoding="async" width="561" height="82" class="wp-image-6630" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-178.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-178.png 561w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-178-300x44.png 300w" sizes="(max-width: 561px) 100vw, 561px" /></p>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec initnss
<em>Initializing NSS database</em></span>

[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ls -al /etc/ipsec.d/</span></pre>
<p><img loading="lazy" decoding="async" width="577" height="125" class="wp-image-6631" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-179.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-179.png 577w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-179-300x65.png 300w" sizes="auto, (max-width: 577px) 100vw, 577px" /></p>
<h3><span style="color: #000000;">Ajouter les règles Firewall</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">firewall-cmd --add-service=ipsec --permanent</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">firewall-cmd --remove-service={cockpit,dhcpv6-client} --permanent</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">firewall-cmd --reload</span></pre>
<h3><span style="color: #000000;">Démarrer le service</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">systemctl enable ipsec --now</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">systemctl status ipsec</span></pre>
<p><img loading="lazy" decoding="async" width="1193" height="428" class="wp-image-6632" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-180.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-180.png 1193w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-180-300x108.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-180-1024x367.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-180-768x276.png 768w" sizes="auto, (max-width: 1193px) 100vw, 1193px" /></p>
<h3><span style="color: #000000;">Générer une cléf RSA</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec newhostkey</span>
<em><span style="color: #ff0000;">Generated RSA key pair with CKAID f2f80cb679336256ac8c159b119464430d5bc7f9 was stored in the NSS database
The public key can be displayed using: ipsec showhostkey --left --ckaid f2f80cb679336256ac8c159b119464430d5bc7f9</span></em>

[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec showhostkey --<strong>left</strong> --ckaid</span> <span style="color: #ff0000;">f2f80cb679336256ac8c159b119464430d5bc7f9

<em> # rsakey AwEAAb9Rf</em>
<strong><em>leftrsasigkey</em></strong><em>=0sAwEAAb9RfAkykozOv4VudJodKC0RmQ+w2TueEo8Ma7Pa/Ru73h+1xFMI77nSHhDxVbIrTwDtiimwz86wDPHtY7Uz7NOkQshjCflb2tp2nQzVi0tA8+qxjnPuLe0AUKRf03QwwY8TCv4kHcP7nd0rZs8MFPvHPao7fZj5u0UBfREWS5QfXbXgtDjaicC40t6QW5ngwm7AmaoXpyLPbBBU4VeVCRNSnjky6orRpMhkDOTAg0198Iz35jNRxf5J2BxBdRjGag5HpzAkbAJX9MjBMerBTzLAC+a1XvQzelJGTTLsbeqG2ziPW4HvZ6A33hMb6TRCbJPmTyuO2fb9i9YQlOQJgJP5GcA5AQYCu0nCYOuyrQcoBQPOOoDZ2e3thpGP37qkQMYffeRsXMgIVezHhI45pAM1wylWaaeo5f3HoYgiMHUJl6S1LD+xzDXmR1fQWF9t3++mJEEWClZuAyK67YboM6+PwUCidOS4p01ISxS1LdkGDF99l8b2H0S+urn/L2U+DjMYOBA/THkjwuM=</em></span></pre>
<h3><span style="color: #000000;">Création fichier Machine left ⬄ Machine right</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">vi /etc/ipsec.d/host_to_host.conf</span></pre>
<pre><span style="color: #ff0000;"><em>conn tunnelVPN</em>
<em> leftid=@west</em>
<em> left=192.168.1.56</em>
<span style="color: #3366ff;"><em>Leftrsasigkey=0sAwEAAb9RfAkykozOv4VudJodKC0RmQ+w2TueEo8Ma7Pa/Ru73h+1xFMI77nSHhDxVbIrTwDtiimwz86wDPHtY7Uz7NOkQshjCflb2tp2nQzVi0tA8+qxjnPuLe0AUKRf03QwwY8TCv4kHcP7nd0rZs8MFPvHPao7fZj5u0UBfREWS5QfXbXgtDjaicC40t6QW5ngwm7AmaoXpyLPbBBU4VeVCRNSnjky6orRpMhkDOTAg0198Iz35jNRxf5J2BxBdRjGag5HpzAkbAJX9MjBMerBTzLAC+a1XvQzelJGTTLsbeqG2ziPW4HvZ6A33hMb6TRCbJPmTyuO2fb9i9YQlOQJgJP5GcA5AQYCu0nCYOuyrQcoBQPOOoDZ2e3thpGP37qkQMYffeRsXMgIVezHhI45pAM1wylWaaeo5f3HoYgiMHUJl6S1LD+xzDXmR1fQWF9t3++mJEEWClZuAyK67YboM6+PwUCidOS4p01ISxS1LdkGDF99l8b2H0S+urn/L2U+DjMYOBA/THkjwuM=</em></span>
<em> rightid=@east</em>
<em> right=172.32.185.31</em>
<span style="color: #ff6600;"><em>rightrsasigkey=0sAwEAAdptcCuPX9bb9VoI+Y8jW8CJTXNPFqXrg5Q1AGqLfrr/2Pyc9m3GkkaBtZDIWVYAE5JpSHwFAwrAvONaeldppssCjsch8tRXTYOCD0MnI44VTn1L1b6L/ofECV/Hm1CIfzE82MJiIWekrfxfj34AnZplSPc8oTZZm7J0n4yEUC452Y7zeWBH/OA4vIFRnk8MY3JrsKMI3zt4LkFL828mWyXhqU2qLtNm/cjPf2wlczv0U6EgFIB8V6XmnD+TZZkBid0NziNrXKc/BdSRB4ZFk0VbH2BoM7TcwgQurAacODb6dWRxG+fxyYAn0STQbwfVUwcymVtAjQFj3jT0GAUbc6IdEQiQNuGuS6K0uhYWShODE+P9fSDWHZnIEtHGQzyU/BDUZnjwYAVV2h6kZvdFQoMOCGQYVM8PIWR8yZTR8hHdj2dsLb/XM/AzLJaf35bBSYAnp1RJRwjtMMjXraxJ2ijx/ssezw80gu3Bvj/ntyQDhzFMwQaa37mlqbsHdjxIy7504ylBOyILVkHdqSKZB83kT2XuFWkXHjHVD0yzu/rlE/zQmOaiKuGDgXp6DYUwQN7MM1XdT35DHSBlxrcVs91xusxgeYSD7zFI/WwZtPPf3Bm7BcAlQUz93brQLTr3WuRREDe/pqdT4xDrQw==</em></span>
<em> authby=rsasig</em></span></pre>
<p><img loading="lazy" decoding="async" width="1102" height="253" class="wp-image-6633" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-181.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-181.png 1102w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-181-300x69.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-181-1024x235.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-181-768x176.png 768w" sizes="auto, (max-width: 1102px) 100vw, 1102px" /></p>
<ul>
<li><strong><span style="color: #3366ff;">En bleu</span>&nbsp;: Clef site public A (left)</strong></li>
<li><strong><span style="color: #ff6600;">En orange</span>&nbsp;: Clef site public B (right)</strong></li>
</ul>
<h3><span style="color: #000000;">Mise en place du Tunnel</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">systemctl restart ipsec</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec auto --add tunnelVPN
<em>002 "tunnelVPN": added IKEv2 connection</em></span></pre>
<p><span style="color: #ff0000;"><strong>LANCER La commande add tunelVPN sur les deux machines avant de lancer le UP</strong></span><br />
<strong><span style="color: #ff0000;">Quand le add tunnelVPN est lancé sur les deux machines.</span></strong></p>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec auto --up tunnelVPN</span></pre>
<p><img loading="lazy" decoding="async" width="1612" height="87" class="wp-image-6634" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-182.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-182.png 1612w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-182-300x16.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-182-1024x55.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-182-768x41.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-182-1536x83.png 1536w" sizes="auto, (max-width: 1612px) 100vw, 1612px" /></p>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec verify</span></pre>
<p><img loading="lazy" decoding="async" width="776" height="321" class="wp-image-6635" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-183.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-183.png 776w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-183-300x124.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-183-768x318.png 768w" sizes="auto, (max-width: 776px) 100vw, 776px" /></p>
<h1><span style="color: #000000;">Machine vpn-ipsec-right.house.cpb – Site B</span></h1>
<p>Host&nbsp;: <strong>vpn-ipsec-right.house.cpb</strong></p>
<ul>
<li>vSwitch&nbsp;: <strong>vmbr2</strong>
<ul>
<li><strong>IP&nbsp;:172.32.185.31</strong></li>
</ul>
</li>
<li>OS&nbsp;: <strong>RockyLinux 8.4</strong></li>
<li>vCPU&nbsp;: 2</li>
<li>DD&nbsp;: 8Go</li>
<li>Ram&nbsp;: 2Go</li>
</ul>
<h2><span style="color: #000000;">Update de la machine</span></h2>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">dnf -y update</span></pre>
<h3><span style="color: #000000;">TimeDate</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">timedatectl set-timezone "Europe/Paris"&nbsp;</span></pre>
<h3><span style="color: #000000;">Ajout des hosts machine (si pas de DNS)</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">echo "192.168.1.56 vpn-ipsec-left vpn-ipsec-left.house.cpb" &gt;&gt; /etc/hosts</span>
[root@vpn-ipsec-right ~]#<span style="color: #ff0000;"> echo "172.32.185.31 vpn-ipsec-right vpn-ipsec-right.house.cpb" &gt;&gt; /etc/hosts</span></pre>
<h3><span style="color: #000000;">Installation package</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">yum install libreswan</span></pre>
<h3><img loading="lazy" decoding="async" width="1603" height="264" class="wp-image-6636" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-184.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-184.png 1603w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-184-300x49.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-184-1024x169.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-184-768x126.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-184-1536x253.png 1536w" sizes="auto, (max-width: 1603px) 100vw, 1603px" /></h3>
<h3><span style="color: #000000;">Initialiser la base nss</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">systemctl stop ipsec</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">rm -f /etc/ipsec.d/*db</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ls -al /etc/ipsec.d/</span>

[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ipsec initnss
<em>Initializing NSS database</em></span></pre>
<h3><span style="color: #000000;">Ajouter les règles Firewall</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">firewall-cmd --add-service=ipsec --permanent</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">firewall-cmd --remove-service={cockpit,dhcpv6-client} --permanent</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">firewall-cmd --reload</span></pre>
<h3><span style="color: #000000;">Désactiver «&nbsp;rp_filter&nbsp;» de Libreswan</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">echo "net.ipv4.conf.all.rp_filter = 0" &gt;&gt; /etc/sysctl.d/50-libreswan.conf</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">sysctl --system</span></pre>
<h3><span style="color: #000000;">Démarrer le service</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">systemctl enable ipsec --now</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">systemctl status ipsec</span></pre>
<p><img loading="lazy" decoding="async" width="1244" height="434" class="wp-image-6637" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-185.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-185.png 1244w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-185-300x105.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-185-1024x357.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-185-768x268.png 768w" sizes="auto, (max-width: 1244px) 100vw, 1244px" /></p>
<h3><span style="color: #000000;">Générer une cléf RSA</span></h3>
<pre>[root@vpn-ipsec-right ~]#<span style="color: #ff0000;"> ipsec newhostkey
<em>Generated RSA key pair with CKAID 957f4e4b42de1ec6a61af4e58796747e5dc264b3 was stored in the NSS database</em>
<em>The public key can be displayed using: ipsec showhostkey --left --ckaid 957f4e4b42de1ec6a61af4e58796747e5dc264b3</em></span>

[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ipsec showhostkey --<strong>right</strong> --ckaid</span> <span style="color: #ff0000;">957f4e4b42de1ec6a61af4e58796747e5dc264b3</span>
<span style="color: #ff0000;"><em>
 # rsakey AwEAAdptc</em>

<strong><em>rightrsasigkey</em></strong><em>=0sAwEAAdptcCuPX9bb9VoI+Y8jW8CJTXNPFqXrg5Q1AGqLfrr/2Pyc9m3GkkaBtZDIWVYAE5JpSHwFAwrAvONaeldppssCjsch8tRXTYOCD0MnI44VTn1L1b6L/ofECV/Hm1CIfzE82MJiIWekrfxfj34AnZplSPc8oTZZm7J0n4yEUC452Y7zeWBH/OA4vIFRnk8MY3JrsKMI3zt4LkFL828mWyXhqU2qLtNm/cjPf2wlczv0U6EgFIB8V6XmnD+TZZkBid0NziNrXKc/BdSRB4ZFk0VbH2BoM7TcwgQurAacODb6dWRxG+fxyYAn0STQbwfVUwcymVtAjQFj3jT0GAUbc6IdEQiQNuGuS6K0uhYWShODE+P9fSDWHZnIEtHGQzyU/BDUZnjwYAVV2h6kZvdFQoMOCGQYVM8PIWR8yZTR8hHdj2dsLb/XM/AzLJaf35bBSYAnp1RJRwjtMMjXraxJ2ijx/ssezw80gu3Bvj/ntyQDhzFMwQaa37mlqbsHdjxIy7504ylBOyILVkHdqSKZB83kT2XuFWkXHjHVD0yzu/rlE/zQmOaiKuGDgXp6DYUwQN7MM1XdT35DHSBlxrcVs91xusxgeYSD7zFI/WwZtPPf3Bm7BcAlQUz93brQLTr3WuRREDe/pqdT4xDrQw==</em></span></pre>
<h3><span style="color: #000000;">Récupération de la Conf Client left (certificats left et right)</span></h3>
<pre>[root@<strong>vpn-ipsec-left</strong> ~]# <span style="color: #ff0000;">scp /etc/ipsec.d/host_to_host.conf <a style="color: #ff0000;" href="mailto:root@vpn-ipsec-right:/etc/ipsec.d/host_to_host.conf">root@vpn-ipsec-right:/etc/ipsec.d/host_to_host.conf</a></span>

[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ls -al /etc/ipsec.d/host_to_host.conf
<em>-rw-r--r--. 1 root root 1353 May 22 14:50 /etc/ipsec.d/host_to_host.conf</em></span></pre>
<h3><span style="color: #000000;">Mise en place Tunnel entre les Hosts</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">systemctl restart ipsec</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ipsec auto --add tunnelVPN
<em>002 "tunnelVPN": added IKEv2 connection</em></span>

[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ipsec auto --up tunnelVPN</span></pre>
<p><img loading="lazy" decoding="async" width="1621" height="110" class="wp-image-6638" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-186.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-186.png 1621w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-186-300x20.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-186-1024x69.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-186-768x52.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-186-1536x104.png 1536w" sizes="auto, (max-width: 1621px) 100vw, 1621px" /></p>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ipsec verify</span></pre>
<p><img loading="lazy" decoding="async" width="808" height="329" class="wp-image-6639" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-187.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-187.png 808w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-187-300x122.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-187-768x313.png 768w" sizes="auto, (max-width: 808px) 100vw, 808px" /></p>
<h1><span style="color: #000000;">Check le Tunnel entre les Hosts (2 machines)</span></h1>
<h3><span style="color: #000000;">Sur vpn-ipsec-right</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">journalctl –xe</span></pre>
<p><img loading="lazy" decoding="async" width="1598" height="592" class="wp-image-6640" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-188.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-188.png 1598w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-188-300x111.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-188-1024x379.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-188-768x285.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-188-1536x569.png 1536w" sizes="auto, (max-width: 1598px) 100vw, 1598px" /></p>
<h3><span style="color: #000000;">Sur vpn-ipsec-left</span></h3>
<p><img loading="lazy" decoding="async" width="1596" height="386" class="wp-image-6641" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-189.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-189.png 1596w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-189-300x73.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-189-1024x248.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-189-768x186.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-189-1536x371.png 1536w" sizes="auto, (max-width: 1596px) 100vw, 1596px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]# <span style="color: #ff0000;">ipsec show
<em>192.168.1.56/32 &lt;=&gt; 172.32.185.31/32 using reqid 16389</em></span></pre>
<p><img loading="lazy" decoding="async" width="549" height="60" class="wp-image-6642" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-190.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-190.png 549w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-190-300x33.png 300w" sizes="auto, (max-width: 549px) 100vw, 549px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-right</span></strong> ~]# <span style="color: #ff0000;">ipsec show
<em>172.32.185.31/32 &lt;=&gt; 192.168.1.56/32 using reqid 16389</em></span></pre>
<p><img loading="lazy" decoding="async" width="552" height="65" class="wp-image-6643" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-191.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-191.png 552w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-191-300x35.png 300w" sizes="auto, (max-width: 552px) 100vw, 552px" /></p>
<pre>[root@<span style="color: #ff0000;">vpn-ipsec-left</span> ~]# <span style="color: #ff0000;">ipsec look</span></pre>
<p><img loading="lazy" decoding="async" width="1418" height="837" class="wp-image-6644" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-192.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-192.png 1418w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-192-300x177.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-192-1024x604.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-192-768x453.png 768w" sizes="auto, (max-width: 1418px) 100vw, 1418px" /></p>
<p><strong>Le tunnel VPN est bien étable entre les deux clients 192.168.1.56 vers 172.32.185.31</strong></p>
<h1><span style="color: #000000;">Ajoutons les logs(2 machines)</span></h1>
<pre>Editer le fichier <span style="color: #ff0000;">/etc/ipsec.conf</span></pre>
<pre>[root@<strong>vpn-ipsec-xxx</strong>~]# <span style="color: #ff0000;">vi /etc/ipsec.conf
<em>config setup</em>
<em> # If logfile= is unset, syslog is used to send log messages too.</em>
<em> # Note that on busy VPN servers, the amount of logging can trigger</em>
<em> # syslogd (or journald) to rate limit messages.</em>
<strong><em> logfile=/var/log/pluto</em>.log</strong></span></pre>
<h3><span style="color: #000000;">Restart ipsec &#8211; vpn-ipsec-left</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">systemctl restart ipsec</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec auto --add tunnelVPN</span></pre>
<h3><span style="color: #000000;">Restart ipsec &#8211; vpn-ipsec-right</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">systemctl restart ipsec</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ipsec auto --add tunnelVPN</span></pre>
<h3><span style="color: #000000;">Restart tunnelVPN &#8211; vpn-ipsec-left et vpn-ipsec-right</span></h3>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]# <span style="color: #ff0000;">ipsec auto --up tunnelVPN</span>
[root@<span style="color: #ff0000;"><strong>vpn-ipsec-right</strong></span> ~]# <span style="color: #ff0000;">ipsec auto --up tunnelVP</span></pre>
<h2><span style="color: #000000;">Check le log pluto</span></h2>
<h3><span style="color: #000000;">Check &#8211; vpn-ipsec-left</span></h3>
<pre>[root@vpn-ipsec-left ~]#<span style="color: #ff0000;"> tail -30 /var/log/pluto.log</span></pre>
<p><img loading="lazy" decoding="async" width="1603" height="260" class="wp-image-6645" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-193.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-193.png 1603w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-193-300x49.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-193-1024x166.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-193-768x125.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-193-1536x249.png 1536w" sizes="auto, (max-width: 1603px) 100vw, 1603px" /></p>
<h3><span style="color: #000000;">Check &#8211; vpn-ipsec-right</span></h3>
<pre>[oot@vpn-ipsec-right ~]# <span style="color: #ff0000;">tail -30 /var/log/pluto.log</span></pre>
<p><img loading="lazy" decoding="async" width="1600" height="586" class="wp-image-6646" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-194.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-194.png 1600w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-194-300x110.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-194-1024x375.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-194-768x281.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-194-1536x563.png 1536w" sizes="auto, (max-width: 1600px) 100vw, 1600px" /></p>
<h1><span style="color: #000000;">Ajoutons VPN start Automatique (2 machines)</span></h1>
<pre>[root@<span style="color: #ff0000;">vpn-ipsec-right</span> ~]# <span style="color: #ff0000;">echo "  auto=start" &gt;&gt; /etc/ipsec.d/host_to_host.conf</span>
[root@<span style="color: #ff0000;">vpn-ipsec-left</span> ~]# <span style="color: #ff0000;">echo "  auto=start" &gt;&gt; /etc/ipsec.d/host_to_host.conf</span>

[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">cat /etc/ipsec.d/host_to_host.conf</span></pre>
<p><img loading="lazy" decoding="async" width="745" height="233" class="wp-image-6647" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-195.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-195.png 745w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-195-300x94.png 300w" sizes="auto, (max-width: 745px) 100vw, 745px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]# <span style="color: #ff0000;">ipsec stop &amp;&amp; ipsec start</span>
[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]# <span style="color: #ff0000;">ipsec status</span></pre>
<p><img loading="lazy" decoding="async" width="1612" height="517" class="wp-image-6648" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-196.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-196.png 1612w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-196-300x96.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-196-1024x328.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-196-768x246.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-196-1536x493.png 1536w" sizes="auto, (max-width: 1612px) 100vw, 1612px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-right</span></strong> ~]# <span style="color: #ff0000;">ipsec stop &amp;&amp; ipsec start</span>
[root@<strong><span style="color: #ff0000;">vpn-ipsec-right</span> </strong>~]# <span style="color: #ff0000;">ipsec status</span></pre>
<p><img loading="lazy" decoding="async" width="1343" height="291" class="wp-image-6649" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-197.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-197.png 1343w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-197-300x65.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-197-1024x222.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-197-768x166.png 768w" sizes="auto, (max-width: 1343px) 100vw, 1343px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]# <span style="color: #ff0000;">ping -c 3 vpn-ipsec-right</span></pre>
<p><img loading="lazy" decoding="async" width="734" height="158" class="wp-image-6650" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-198.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-198.png 734w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-198-300x65.png 300w" sizes="auto, (max-width: 734px) 100vw, 734px" /></p>
<pre>[root@<span style="color: #ff0000;"><strong>vpn-ipsec-right</strong></span> ~]# <span style="color: #ff0000;">ping -c 3 vpn-ipsec-left</span></pre>
<p><img loading="lazy" decoding="async" width="710" height="158" class="wp-image-6651" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-199.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-199.png 710w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-199-300x67.png 300w" sizes="auto, (max-width: 710px) 100vw, 710px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-right</span> </strong>~]# <span style="color: #ff0000;">ipsec showstates</span></pre>
<p><img loading="lazy" decoding="async" width="1294" height="83" class="wp-image-6652" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-200.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-200.png 1294w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-200-300x19.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-200-1024x66.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-200-768x49.png 768w" sizes="auto, (max-width: 1294px) 100vw, 1294px" /></p>
<h2><span style="color: #000000;">Check Transaction SSL entre vpn-ipsec-right =&gt; vpn-ipsec-left</span></h2>
<h3><span style="color: #000000;">Installation tcpflow sur vpn-ipsec-left</span></h3>
<pre>[root@<span style="color: #ff0000;"><strong>vpn-ipsec-left</strong></span> ~]#<span style="color: #ff0000;">dnf install wget</span>
[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]#<span style="color: #ff0000;">dnf install https://forensics.cert.org/cert-forensics-tools-release-el8.rpm</span>
[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]#<span style="color: #ff0000;">dnf install epel-release</span>
[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span> </strong>~]#<span style="color: #ff0000;">dnf --enablerepo=forensics install tcpflow</span></pre>
<h2><span style="color: #000000;">Lancement une écoute sur port 22 sur vpn-ipsec-left</span></h2>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">tcpflow -c -p -i any dst port 22 &gt;&gt; ecoute.txt |tail -f ecoute.txt</span></pre>
<h3><span style="color: #000000;">Lancement d’un copie de fichier &#8211; vpn-ipsec-right =&gt; vpn-ipsec-left</span></h3>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-right</span></strong> chris]# <span style="color: #ff0000;">touch titi.txt</span>
[root@<span style="color: #ff0000;"><strong>vpn-ipsec-right</strong></span> chris]# <span style="color: #ff0000;">scp titi.txt root@192.168.1.56:/home/chris/toto.txt</span>

[root@<span style="color: #ff0000;">vpn-ipsec-left</span> ~]# <span style="color: #ff0000;">cat ecoute.txt</span></pre>
<p><img loading="lazy" decoding="async" width="1549" height="401" class="wp-image-6653" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-201.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-201.png 1549w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-201-300x78.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-201-1024x265.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-201-768x199.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-201-1536x398.png 1536w" sizes="auto, (max-width: 1549px) 100vw, 1549px" /></p>
<p>Views: 3</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-vpn-ipsec-host-to-host/">MODOP installation VPN IPsec – Host to Host</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-installation-vpn-ipsec-host-to-host/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
