123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220 |
- <!DOCTYPE html>
- <html lang="en">
- <head>
- <meta charset="UTF-8">
- <title>IPsec on FreeBSD | dn42 wiki</title>
- <meta name="viewport" content="width=device-width, initial-scale=1.0">
- <meta name="robots" content="index, follow">
- <meta name="keywords" content="dn42,wiki,routing,bgp">
- <link rel="canonical" href="https://dn42.obl.ong/howto/IPsec-on-FreeBSD.html">
- <link rel="icon" type="image/x-icon" href="/favicon.ico">
- <link rel="shortcut icon" type="image/x-icon" href="/favicon.ico">
- <link rel="author" type="text/html" href="/docs/people">
- <link rel="stylesheet" href="/css/normalize.css">
- <link rel="stylesheet" href="/css/simple.min.css">
- <link rel="stylesheet" href="/css/style.css">
- <link rel="stylesheet" href="/css/menu.css">
- </head>
-
- <body>
- <header>
- <b>dn42 wiki / IPsec on FreeBSD</b>
- <div id="dn42_header">
-
- <p><a href="/"><img src="/dn42.png" alt="dn42" /></a></p>
- </div>
- </header>
- <main>
- <h1 id="ipsec-on-freebsd">IPsec on FreeBSD</h1>
- <p>These instructions are for IPsec in transport mode not IPsec in tunnel mode. IPsec in tunnel mode requires a too tight coupling with the routing table for dynamic routing because the policies can only be specified based on source/destination address and protocol not based on interfaces.</p>
- <h2 id="requirements">Requirements</h2>
- <ul>
- <li>Root access to both endpoints.</li>
- <li>Static IPv4 addresses for both endpoints unless you want to write a small shell script as hook for racoon.</li>
- <li>At least one static IPv4 on at least one endpoint unless you hate yourself.</li>
- </ul>
- <h2 id="kernel-configuration">Kernel configuration</h2>
- <p>The FreeBSD GENERIC kernel lacks support for in-kernel IPsec processing. Add this two lines to your kernel config and (re-)build your own kernel.
- If you’re new to FreeBSD check Chapters <a href="http://www.freebsd.org/doc/handbook/ipsec.html">15.9.1</a> and <a href="http://www.freebsd.org/doc/handbook/kernelconfig.html">9</a> of the FreeBSD handbook.</p>
- <div class="language-conf highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">options</span> <span class="n">IPSEC</span> <span class="c">#IP security
- </span><span class="n">device</span> <span class="n">crypto</span>
- </code></pre></div></div>
- <p>Reboot into your new kernel.</p>
- <h2 id="userland-configuration">Userland configuration</h2>
- <p>Install the racoon daemon. It’s included in the <a href="http://www.freshports.org/security/ipsec-tools/">security/ipsec-tools</a> port.
- Racoon is pain in the ass to configure the first time because it’s error messages aren’t helping and the complexity of IPsec. Don’t let this stop you.</p>
- <div class="language-conf highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">path</span> <span class="n">pre_shared_key</span> <span class="s2">"/usr/local/etc/racoon/psk"</span>;
- <span class="n">path</span> <span class="n">certificate</span> <span class="s2">"/usr/local/etc/racoon/certs"</span>;
- <span class="n">log</span> <span class="n">info</span>;
- <span class="n">listen</span> {
- <span class="n">isakmp</span> <span class="n">a</span>.<span class="n">b</span>.<span class="n">c</span>.<span class="n">d</span> [<span class="m">500</span>];
- <span class="n">isakmp_natt</span> <span class="n">a</span>.<span class="n">b</span>.<span class="n">c</span>.<span class="n">d</span> [<span class="m">4500</span>];
- }
- <span class="n">padding</span> {
- <span class="n">strict_check</span> <span class="n">on</span>;
- }
- <span class="n">timer</span> {
- <span class="n">natt_keepalive</span> <span class="m">5</span> <span class="n">sec</span>;
- <span class="n">interval</span> <span class="m">3</span> <span class="n">sec</span>;
- <span class="n">phase1</span> <span class="m">45</span> <span class="n">sec</span>; <span class="c"># give embedded CPUs time to finish RSA operations
- </span> <span class="n">phase2</span> <span class="m">45</span> <span class="n">sec</span>;
- }
- <span class="n">remote</span> <span class="n">b</span>.<span class="n">c</span>.<span class="n">d</span>.<span class="n">e</span> [<span class="m">500</span>] {
- <span class="n">exchange_mode</span> <span class="n">main</span>;
- <span class="n">proposal_check</span> <span class="n">strict</span>;
- <span class="n">my_identifier</span> <span class="n">asn1dn</span>;
- <span class="n">peers_identifier</span> <span class="n">asn1dn</span>;
- <span class="n">lifetime</span> <span class="n">time</span> <span class="m">1</span> <span class="n">hour</span>;
- <span class="n">certificate_type</span> <span class="n">x509</span> <span class="s2">"self.crt"</span> <span class="s2">"self.key"</span>;
- <span class="n">peers_certfile</span> <span class="n">x509</span> <span class="s2">"peer.crt"</span>;
- <span class="n">ca_type</span> <span class="n">x509</span> <span class="s2">"ca.crt"</span>;
- <span class="n">verify_cert</span> <span class="n">on</span>;
- <span class="n">send_cert</span> <span class="n">off</span>; <span class="c"># neither send
- </span> <span class="n">send_cr</span> <span class="n">off</span>; <span class="c"># nor request a crt to be send
- </span>
- <span class="n">proposal</span> {
- <span class="n">encryption_algorithm</span> <span class="n">aes</span> <span class="m">256</span>;
- <span class="n">hash_algorithm</span> <span class="n">sha256</span>;
- <span class="n">authentication_method</span> <span class="n">rsasig</span>;
- <span class="n">dh_group</span> <span class="n">modp4096</span>;
- }
- }
- <span class="n">sainfo</span> (<span class="n">address</span> <span class="n">a</span>.<span class="n">b</span>.<span class="n">c</span>.<span class="n">d</span> <span class="n">gre</span> <span class="n">address</span> <span class="n">b</span>.<span class="n">c</span>.<span class="n">d</span>.<span class="n">e</span> <span class="n">gre</span>) {
- <span class="n">pfs_group</span> <span class="n">modp4096</span>;
- <span class="n">lifetime</span> <span class="n">time</span> <span class="m">1</span> <span class="n">hour</span>;
- <span class="n">encryption_algorithm</span> <span class="n">aes</span> <span class="m">256</span>;
- <span class="n">authentication_algorithm</span> <span class="n">hmac_sha1</span>;
- }
- </code></pre></div></div>
- <div id="menu-container" class="menu-container">
- <hr>
- <div id="menu" class="menu">
-
- <ul>
- <li><a href="/Home">Home</a>
- <ul>
- <li><a href="/howto/Getting-Started">Getting Started</a></li>
- <li><a href="/howto/Registry-Authentication">Registry Authentication</a></li>
- <li><a href="/howto/Address-Space">Address Space</a></li>
- <li><a href="/howto/BGP-communities">BGP communities</a></li>
- <li><a href="/FAQ">FAQ</a></li>
- </ul>
- </li>
- <li>How-To
- <ul>
- <li><a href="/howto/wireguard">Wireguard</a></li>
- <li><a href="/howto/openvpn">Openvpn</a></li>
- <li><a href="/howto/IPsec-with-PublicKeys">IPsec With Public Keys</a></li>
- <li><a href="/howto/tinc">Tinc</a></li>
- <li><a href="/howto/GRE-on-FreeBSD">GRE on FreeBSD</a></li>
- <li><a href="/howto/GRE-on-OpenBSD">GRE on OpenBSD</a></li>
- <li><a href="/howto/IPv6-Multicast">IPv6 Multicast (PIM-SM)</a></li>
- <li><a href="/howto/multicast">SSM Multicast</a></li>
- <li><a href="/howto/mpls">MPLS</a></li>
- <li><a href="/howto/Bird2">Bird2</a></li>
- <li><a href="/howto/frr">FRRouting</a></li>
- <li><a href="/howto/OpenBGPD">OpenBGPD</a></li>
- <li><a href="/howto/mikrotik">Mikrotik RouterOS</a></li>
- <li><a href="/howto/EdgeOS-Config">EdgeRouter</a></li>
- <li><a href="/howto/Static-routes-on-Windows">Static routes on Windows</a></li>
- <li><a href="/howto/networksettings">Universal Network Requirements</a></li>
- <li><a href="/howto/vyos1.4.x">VyOS</a></li>
- <li><a href="/howto/nixos">NixOS</a></li>
- </ul>
- </li>
- <li>Services
- <ul>
- <li><a href="/services/IRC">IRC</a></li>
- <li><a href="/services/Whois">Whois registry</a></li>
- <li><a href="/services/DNS">DNS</a></li>
- <li><a href="/services/IX-Collection">IX Collection</a></li>
- <li><a href="/services/Clearnet-Domains">Public DNS</a></li>
- <li><a href="/services/Looking-Glasses">Looking Glasses</a></li>
- <li><a href="/services/Automatic-Peering">Automatic Peering</a></li>
- <li><a href="/services/Repository-Mirrors">Repository Mirrors</a></li>
- <li><a href="/services/Distributed-Wiki">Distributed Wiki</a></li>
- <li><a href="/services/Certificate-Authority">Certificate Authority</a></li>
- <li><a href="/services/Route-Collector">Route Collector</a></li>
- </ul>
- </li>
- <li>Internal
- <ul>
- <li><a href="/internal/Internal-Services">Internal services</a></li>
- <li><a href="/internal/Interconnections">Interconnections</a></li>
- <li><a href="/internal/APIs">APIs</a></li>
- <li><a href="/internal/ShowAndTell">Show and Tell</a></li>
- <li><a href="/internal/Historical-Services">Historical services</a></li>
- </ul>
- </li>
- <li>Historical
- <ul>
- <li><a href="/historical/Bird">Bird 1</a></li>
- <li><a href="/historical/Quagga">Quagga</a></li>
- </ul>
- </li>
- <li>External Tools
- <ul>
- <li><a href="https://paste.dn42.us">Paste Board</a></li>
- <li><a href="https://git.dn42.dev">Git Repositories</a></li>
- </ul>
- </li>
- </ul>
- <hr />
- </div>
- </div>
- </main>
-
- <footer><div class="center">
- <div id="dn42_footer">
-
- <table>
- <tbody>
- <tr>
- <td>Hosted by: <a href="mailto:dn42@burble.com">BURBLE-MNT</a>, <a href="mailto:nurtic-vibe@grmml.net">GRMML-MNT</a>, <a href="mailto:xuu@dn42.us">XUU-MNT</a>, <a href="mailto:janeric@ortgies.it">JAN-MNT</a>, <a href="mailto:lare@lare.cc">LARE-MNT</a>, <a href="mailto:danny@saru.moe">SARU-MNT</a>, <a href="mailto:androw95220@gmail.com">ANDROW-MNT</a>, <a href="mailto:dn42@mk16.de">MARK22K-MNT</a></td>
- <td>Accessible via: <a href="https://wiki.dn42">dn42</a>, <a href="https://dn42.dev/">dn42.dev</a>, <a href="https://dn42.eu/">dn42.eu</a>, <a href="https://wiki.dn42.us/">wiki.dn42.us</a>, <a href="https://dn42.de/">dn42.de</a> (IPv6-only), <a href="https://dn42.cc/">dn42.cc</a> (wiki-ng), <a href="https://dn42.wiki/">dn42.wiki</a>, <a href="https://dn42.pp.ua/">dn42.pp.ua</a>, <a href="https://dn42.obl.ong/">dn42.obl.ong</a></td>
- </tr>
- </tbody>
- </table>
- </div>
- </div>
- </footer>
-
- </body>
- </html>
|