Cấu hình strongSwan
Bài viết hướng dẫn dựng thiết bị Router để đấu nối VPN S2S với dịch vụ VPN Site-to-Site của FPT Smart Cloud.
- Bước 1: Cấu hình VPN Site-to-Site
- Bước 2: Cấu hình strongSwan
Cần đảm bảo các điều kiện sau:
- VPNaaS trên Portal
- Ubuntu 20.04 đã tải và cài đặt kèm: strongSwan 5.9.14
- Một public IP — để đơn giản, gán trực tiếp vào VM thay vì dùng Floating IP
- Một VM pfSense để debug (tuỳ chọn)
Bước 1: Cấu hình VPN Site-to-Site trên FPT Cloud Portal
Tạo Customer Gateway và VPN Connection cho thiết bị strongSwan trên FPT Cloud Portal. Xem chi tiết tại Tạo VPN Connection.
Bước 2: Cấu hình VPN cho strongSwan
Chạy các lệnh sau (thay tham số bằng giá trị thực tế của bạn):
Check strongSwan version
swanctl -v
Sửa file /etc/ipsec.conf theo mẫu sau:
config setup
charondebug="all"
uniqueids=yes
conn myvpn
type=tunnel
auto=start
keyexchange=ikev2
ike=aes256-sha256-modp2048
keyingtries=%forever
lifetime=3600s
dpddelay=30s
dpdtimeout=120s
dpdaction=restart
esp=aes256-sha256-modp2048
left=x.x.x.x //IP of strongSwan
leftsubnet=x.x.x.x/24 //Subnet of strongSwan
leftauth=psk
right=x.x.x.x // IP of the remote peer
rightsubnet=x.x.x.x/24 //Subnet of the remote peer
rightauth=psk
authby=secret
auto=start
Sửa file /etc/ipsec.secret theo mẫu sau:
x.x.x.x x.x.x.x : PSK "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" // Pre-shared key
Lưu ý
- strongSwan chạy dưới dạng dịch vụ nền trên Ubuntu. Bật multi-network trên CPU để đạt hiệu năng tốt nhất.
- strongSwan chạy dưới dạng dịch vụ nền trên Ubuntu. Bật firewall và routing để cho phép kết nối.
- Nếu chạy trên OpenStack của FCI, thêm Static route trên router với Destination là IP của peer và nexthop là IP LAN của strongSwan.