Chuyển tới nội dung chính

Cấu hình strongSwan

Bài viết hướng dẫn dựng thiết bị Router để đấu nối VPN S2S với dịch vụ VPN Site-to-Site của FPT Smart Cloud.

  • Bước 1: Cấu hình VPN Site-to-Site
  • Bước 2: Cấu hình strongSwan

Cần đảm bảo các điều kiện sau:

  • VPNaaS trên Portal
  • Ubuntu 20.04 đã tải và cài đặt kèm: strongSwan 5.9.14
  • Một public IP — để đơn giản, gán trực tiếp vào VM thay vì dùng Floating IP
  • Một VM pfSense để debug (tuỳ chọn)

Bước 1: Cấu hình VPN Site-to-Site trên FPT Cloud Portal

Tạo Customer Gateway và VPN Connection cho thiết bị strongSwan trên FPT Cloud Portal. Xem chi tiết tại Tạo VPN Connection.

Bước 2: Cấu hình VPN cho strongSwan

Chạy các lệnh sau (thay tham số bằng giá trị thực tế của bạn):

Check strongSwan version
swanctl -v

Sửa file /etc/ipsec.conf theo mẫu sau:

config setup
charondebug="all"
uniqueids=yes

conn myvpn
type=tunnel
auto=start
keyexchange=ikev2
ike=aes256-sha256-modp2048
keyingtries=%forever
lifetime=3600s
dpddelay=30s
dpdtimeout=120s
dpdaction=restart
esp=aes256-sha256-modp2048
left=x.x.x.x //IP of strongSwan
leftsubnet=x.x.x.x/24 //Subnet of strongSwan
leftauth=psk
right=x.x.x.x // IP of the remote peer
rightsubnet=x.x.x.x/24 //Subnet of the remote peer
rightauth=psk
authby=secret
auto=start

Sửa file /etc/ipsec.secret theo mẫu sau:

x.x.x.x x.x.x.x : PSK "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"   // Pre-shared key

Lưu ý

  • strongSwan chạy dưới dạng dịch vụ nền trên Ubuntu. Bật multi-network trên CPU để đạt hiệu năng tốt nhất.
  • strongSwan chạy dưới dạng dịch vụ nền trên Ubuntu. Bật firewall và routing để cho phép kết nối.
  • Nếu chạy trên OpenStack của FCI, thêm Static route trên router với Destination là IP của peer và nexthop là IP LAN của strongSwan.

Xem thêm