<description>Foruseinpublic areas.You donottrust the other computers on networks tonotharm your computer.Only selected incoming connections are accepted.</description>
Jan 5 13:08:36 05[NET] received packet: from 114.240.134.250[500] to 47.88.25.41[500] (604 bytes)
Jan 5 13:08:36 05[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(REDIR_SUP) N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) ]
Jan 5 13:08:36 05[IKE] 114.240.134.250 is initiating an IKE_SA
Jan 5 13:08:36 05[IKE] remote host is behind NAT
Jan 5 13:08:36 05[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(MULT_AUTH) ]
Jan 5 13:08:36 05[NET] sending packet: from 47.88.25.41[500] to 114.240.134.250[500] (448 bytes)
Jan 5 13:08:36 12[NET] received packet: from 114.240.134.250[4500] to 47.88.25.41[4500] (512 bytes)
Jan 5 13:08:36 12[ENC] parsed IKE_AUTH request 1 [ IDi N(INIT_CONTACT) N(MOBIKE_SUP) IDr CPRQ(ADDR DHCP DNS MASK ADDR6 DHCP6 DNS6) N(ESP_TFC_PAD_N) N(NON_FIRST_FRAG) SA TSi TSr ]
Jan 5 13:08:36 12[CFG] looking for peer configs matching 47.88.25.41[vpn.mumov.com]…114.240.134.250[keensting]
Jan 5 13:08:36 12[CFG] selected peer config ‘ikev2-eap’
Jan 5 13:08:36 12[IKE] initiating EAP_IDENTITY method (id 0x00)
Jan 5 13:08:36 12[IKE] received ESP_TFC_PADDING_NOT_SUPPORTED, not using ESPv3 TFC padding
Jan 5 13:08:36 12[IKE] peer supports MOBIKE
Jan 5 13:08:36 12[IKE] authentication of ‘vpn.mumov.com’ (myself) with RSA signature successful
Jan 5 13:08:36 12[IKE] sending end entity cert “C=CN, O=Mumov, CN=vpn.mumov.com”
Jan 5 13:08:36 12[ENC] generating IKE_AUTH response 1 [ IDr CERT AUTH EAP/REQ/ID ]
Jan 5 13:08:36 12[ENC] splitting IKE message with length of 1216 bytes into 3 fragments
Jan 5 13:08:36 12[ENC] generating IKE_AUTH response 1 [ EF(1/3) ]
Jan 5 13:08:36 12[ENC] generating IKE_AUTH response 1 [ EF(2/3) ]
Jan 5 13:08:36 12[ENC] generating IKE_AUTH response 1 [ EF(3/3) ]
Jan 5 13:08:36 12[NET] sending packet: from 47.88.25.41[4500] to 114.240.134.250[4500] (532 bytes)
Jan 5 13:08:36 12[NET] sending packet: from 47.88.25.41[4500] to 114.240.134.250[4500] (532 bytes)
Jan 5 13:08:36 12[NET] sending packet: from 47.88.25.41[4500] to 114.240.134.250[4500] (292 bytes)
Dec 27 13:38:28 05[CFG] received stroke: add connection ‘ikev2-eap’
Dec 27 13:38:28 05[CFG] adding virtual IP address pool 10.1.0.0/16
Dec 27 13:38:28 05[LIB] opening ‘/etc/strongswan/ipsec.d/certs/server.cert.pem’ failed: No such file or directory
Dec 27 13:38:28 05[LIB] building CRED_CERTIFICATE – ANY failed, tried 1 builders
Dec 27 13:38:28 05[CFG] loading certificate from ‘server.cert.pem’ failed
Dec 27 13:38:28 05[CFG] CA certificate “C=CN, O=ITnmg, CN=ITnmg StrongSwan CA” not found, discarding CA constraint
Dec 27 13:38:28 05[CFG] added configuration ‘ikev2-eap’
Dec 27 13:40:18 14[NET] received packet: from 27.149.199.7[7130] to 47.90.77.159[500] (604 bytes)
Dec 27 13:40:18 14[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(REDIR_SUP) N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) ]
Dec 27 13:40:18 14[IKE] 27.149.199.7 is initiating an IKE_SA
Dec 27 13:40:18 14[IKE] remote host is behind NAT
Dec 27 13:40:18 14[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(MULT_AUTH) ]
Dec 27 13:40:18 14[NET] sending packet: from 47.90.77.159[500] to 27.149.199.7[7130] (448 bytes)
Dec 27 13:40:18 09[NET] received packet: from 27.149.199.7[7131] to 47.90.77.159[4500] (496 bytes)
Dec 27 13:40:18 09[ENC] parsed IKE_AUTH request 1 [ IDi N(INIT_CONTACT) N(MOBIKE_SUP) IDr CPRQ(ADDR DHCP DNS MASK ADDR6 DHCP6 DNS6) N(ESP_TFC_PAD_N) N(NON_FIRST_FRAG) SA TSi TSr ]
Dec 27 13:40:18 09[CFG] looking for peer configs matching 47.90.77.159[vpn.itnmg.net]…27.149.199.7[10.17.128.255]
Dec 27 13:40:18 09[CFG] selected peer config ‘ikev2-eap’
Dec 27 13:40:18 09[IKE] initiating EAP_IDENTITY method (id 0x00)
Dec 27 13:40:18 09[IKE] received ESP_TFC_PADDING_NOT_SUPPORTED, not using ESPv3 TFC padding
Dec 27 13:40:18 09[IKE] peer supports MOBIKE
Dec 27 13:40:18 09[IKE] no private key found for ‘vpn.itnmg.net’
Dec 27 13:40:18 09[ENC] generating IKE_AUTH response 1 [ N(AUTH_FAILED) ]
Dec 27 13:40:18 09[NET] sending packet: from 47.90.77.159[4500] to 27.149.199.7[7131] (80 bytes)
您好….
这个是 leftid 的问题吗
no private key found for ‘vpn.itnmg.net’
Dec 27 13:17:53 05[NET] received packet: from 124.72.170.209[500] to 47.90.77.159[500] (604 bytes)
Dec 27 13:17:53 05[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(REDIR_SUP) N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) ]
Dec 27 13:17:53 05[IKE] no IKE config found for 47.90.77.159…124.72.170.209, sending NO_PROPOSAL_CHOSEN
Dec 27 13:17:53 05[ENC] generating IKE_SA_INIT response 0 [ N(NO_PROP) ]
Dec 27 13:17:53 05[NET] sending packet: from 47.90.77.159[500] to 124.72.170.209[500] (36 bytes)
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
经测试,IKEV2是有时能用有时不能用,有时连上一段时间后会断线
看一下你到vps的网络是否稳定
完全按照你的方法来做,但是Win7下面还是会提示809错误,就算连上也很容易断开。
你win10有问题没?我搭建出来是win10连上1分钟就自动断开,win7完美运行
经测试是有时能用有时不能用,win7和ios都一样
你是不是配置l2tp了? 我那上都写l2tp已经废弃了.
我只是完完全全的IKEV2而已啊。另外,奇怪的是,我使用rightsourceip = 192.168.x.0/24,但怎么Win7连上后子网掩码是255.255.255.255?
网段不要和你的 vps, 本地局域网相同, 改一下网段试试.
我知道,现在想问,XL2TPD的VPN客户端互联怎么做?连上一个L2TP客户端就多一个PPP网卡
iOS连接IKEV2需要填本地ID,本地ID可以随便填。IKEV2可能会和443端口的AnyConnect或HTTPS服务产生冲突。
本地id不是必需的,如果你有耐心,可以完全按照我的配置试一下。
iOS设备连接不上,Windows可以
经测试 iOS设备一定要填本地ID,浪费不少时间才发现卡在这里。
这玩意也被和谐了吗
Windows 7下面连接提示809错误。
原来是配置不对,谢谢了!
这位兄弟,你跟你刚好是反的,我除了win10,ios,mac,win7全部没问题,我win10连1分钟就准时断开,没查到原因
ipsec命令如何生成服务器证书的请求呢,只需要证书请求文件即可,不要CA
不明白你的意思, CA是根证书, 如果是从证书机构买的证书就不需要导入证书.
用ipsec命令生成VPN服务器的证书请求,再将证书请求文件交给CA。应该是ipsec pki –req
写得好详细啊,最近一直在折腾这个,一直没成功,
楼主知不知道ipsec的日志在哪里?我server建好之后,win10客户端这边一连就报错,我想看下请求有没有到server,和返回的具体错误是什么,看不到日志根本没法查
这个就不太清楚了,问一下谷歌吧。其实 strongswan 本身的日志已经很详细了,配置里还可以指定输出日志的详细成度。
哇,非常谢谢楼主这么长时间的文章还这么快的回复
话说strongswan的日志是输出在哪的?详细程度的参数又是哪个?我都搜了好久都没找到,我每次都是ipsec start –nofork在终端上一直打印日志看的,感觉很不方便;
另外,我按照你的方法,已经搭建成功了,但是win10下只能连接1分钟,到了1分钟不管做什么都会自己断开,我尝试修改了很多keylife、time这些相关的参数,但是没有效果,楼主有什么建议没?
还有就是ios和mac os端我也试了,这两个需要填remote id,我不知道具体是填哪个,我尝试填了server.cert.pem和ca.cert.pem里面CN的内容,但是还是不能连,vpn开关点一下就关了,server上收到一个192.168.1.10 is initiating an IKE_SA,然后就没动静了,还希望楼主能指导下
看来你没有认真的看完,再看一遍,日志设置和left id都有说。
嗯,left id我刚刚看到了,我一直以为我填的就是本机ip,结果是%any
那楼主对win10下1分钟自动断开这个问题有什么建议没?可能是哪个参数或者原因导致的呢?
哦,对了,还有strongswan的日志输出和debug等级是在哪儿修改的?
刚刚发现win7不会自动断开=。=,公司3个win10都是1分钟准时断,想查原因
# increase default loglevel for all daemon subsystems
default = 1
这个是配置日志详细度, 具体的数值goole一下.
win10的你看一下有没有按照我最后的配置方法做. 比如证书, dns配置.
呃。。。。楼主我又来了,经过一天的折腾,现在就是除了win10各种系统都正常了,win10我按照你的方法改pem后缀导入证书,还是1分钟就挂了
因为其他系统都没问题了,所以我就几乎没有从server端的参数去排查了,我感觉还是像win10又什么安全设置之类的导致了这个问题,我查win10的系统日志,里面提示断开连接 原因代码829,我去ms官网去查,微软的解释是vpn server的网络问题,但这个应该不可能,所以现在win10这个依然找不到什么方法可参考,还希望楼主能帮忙分析下
Jan 5 13:08:36 05[NET] received packet: from 114.240.134.250[500] to 47.88.25.41[500] (604 bytes)
Jan 5 13:08:36 05[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(REDIR_SUP) N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) ]
Jan 5 13:08:36 05[IKE] 114.240.134.250 is initiating an IKE_SA
Jan 5 13:08:36 05[IKE] remote host is behind NAT
Jan 5 13:08:36 05[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(MULT_AUTH) ]
Jan 5 13:08:36 05[NET] sending packet: from 47.88.25.41[500] to 114.240.134.250[500] (448 bytes)
Jan 5 13:08:36 12[NET] received packet: from 114.240.134.250[4500] to 47.88.25.41[4500] (512 bytes)
Jan 5 13:08:36 12[ENC] parsed IKE_AUTH request 1 [ IDi N(INIT_CONTACT) N(MOBIKE_SUP) IDr CPRQ(ADDR DHCP DNS MASK ADDR6 DHCP6 DNS6) N(ESP_TFC_PAD_N) N(NON_FIRST_FRAG) SA TSi TSr ]
Jan 5 13:08:36 12[CFG] looking for peer configs matching 47.88.25.41[vpn.mumov.com]…114.240.134.250[keensting]
Jan 5 13:08:36 12[CFG] selected peer config ‘ikev2-eap’
Jan 5 13:08:36 12[IKE] initiating EAP_IDENTITY method (id 0x00)
Jan 5 13:08:36 12[IKE] received ESP_TFC_PADDING_NOT_SUPPORTED, not using ESPv3 TFC padding
Jan 5 13:08:36 12[IKE] peer supports MOBIKE
Jan 5 13:08:36 12[IKE] authentication of ‘vpn.mumov.com’ (myself) with RSA signature successful
Jan 5 13:08:36 12[IKE] sending end entity cert “C=CN, O=Mumov, CN=vpn.mumov.com”
Jan 5 13:08:36 12[ENC] generating IKE_AUTH response 1 [ IDr CERT AUTH EAP/REQ/ID ]
Jan 5 13:08:36 12[ENC] splitting IKE message with length of 1216 bytes into 3 fragments
Jan 5 13:08:36 12[ENC] generating IKE_AUTH response 1 [ EF(1/3) ]
Jan 5 13:08:36 12[ENC] generating IKE_AUTH response 1 [ EF(2/3) ]
Jan 5 13:08:36 12[ENC] generating IKE_AUTH response 1 [ EF(3/3) ]
Jan 5 13:08:36 12[NET] sending packet: from 47.88.25.41[4500] to 114.240.134.250[4500] (532 bytes)
Jan 5 13:08:36 12[NET] sending packet: from 47.88.25.41[4500] to 114.240.134.250[4500] (532 bytes)
Jan 5 13:08:36 12[NET] sending packet: from 47.88.25.41[4500] to 114.240.134.250[4500] (292 bytes)
Dec 27 13:38:28 05[CFG] received stroke: add connection ‘ikev2-eap’
Dec 27 13:38:28 05[CFG] adding virtual IP address pool 10.1.0.0/16
Dec 27 13:38:28 05[LIB] opening ‘/etc/strongswan/ipsec.d/certs/server.cert.pem’ failed: No such file or directory
Dec 27 13:38:28 05[LIB] building CRED_CERTIFICATE – ANY failed, tried 1 builders
Dec 27 13:38:28 05[CFG] loading certificate from ‘server.cert.pem’ failed
Dec 27 13:38:28 05[CFG] CA certificate “C=CN, O=ITnmg, CN=ITnmg StrongSwan CA” not found, discarding CA constraint
Dec 27 13:38:28 05[CFG] added configuration ‘ikev2-eap’
Dec 27 13:40:18 14[NET] received packet: from 27.149.199.7[7130] to 47.90.77.159[500] (604 bytes)
Dec 27 13:40:18 14[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(REDIR_SUP) N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) ]
Dec 27 13:40:18 14[IKE] 27.149.199.7 is initiating an IKE_SA
Dec 27 13:40:18 14[IKE] remote host is behind NAT
Dec 27 13:40:18 14[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(MULT_AUTH) ]
Dec 27 13:40:18 14[NET] sending packet: from 47.90.77.159[500] to 27.149.199.7[7130] (448 bytes)
Dec 27 13:40:18 09[NET] received packet: from 27.149.199.7[7131] to 47.90.77.159[4500] (496 bytes)
Dec 27 13:40:18 09[ENC] parsed IKE_AUTH request 1 [ IDi N(INIT_CONTACT) N(MOBIKE_SUP) IDr CPRQ(ADDR DHCP DNS MASK ADDR6 DHCP6 DNS6) N(ESP_TFC_PAD_N) N(NON_FIRST_FRAG) SA TSi TSr ]
Dec 27 13:40:18 09[CFG] looking for peer configs matching 47.90.77.159[vpn.itnmg.net]…27.149.199.7[10.17.128.255]
Dec 27 13:40:18 09[CFG] selected peer config ‘ikev2-eap’
Dec 27 13:40:18 09[IKE] initiating EAP_IDENTITY method (id 0x00)
Dec 27 13:40:18 09[IKE] received ESP_TFC_PADDING_NOT_SUPPORTED, not using ESPv3 TFC padding
Dec 27 13:40:18 09[IKE] peer supports MOBIKE
Dec 27 13:40:18 09[IKE] no private key found for ‘vpn.itnmg.net’
Dec 27 13:40:18 09[ENC] generating IKE_AUTH response 1 [ N(AUTH_FAILED) ]
Dec 27 13:40:18 09[NET] sending packet: from 47.90.77.159[4500] to 27.149.199.7[7131] (80 bytes)
您好….
这个是 leftid 的问题吗
no private key found for ‘vpn.itnmg.net’
绑定你自己的域名, 生成你自己的证书, 不要用我的.
Dec 27 13:06:58 00[DMN] Starting IKE charon daemon (strongSwan 5.4.0, Linux 3.10.0-123.9.3.el7.x86_64, x86_64)
Dec 27 13:06:58 00[LIB] openssl FIPS mode(2) – enabled
Dec 27 13:06:58 00[CFG] loading ca certificates from ‘/etc/strongswan/ipsec.d/cacerts’
Dec 27 13:06:58 00[CFG] loading aa certificates from ‘/etc/strongswan/ipsec.d/aacerts’
Dec 27 13:06:58 00[CFG] loading ocsp signer certificates from ‘/etc/strongswan/ipsec.d/ocspcerts’
Dec 27 13:06:58 00[CFG] loading attribute certificates from ‘/etc/strongswan/ipsec.d/acerts’
Dec 27 13:06:58 00[CFG] loading crls from ‘/etc/strongswan/ipsec.d/crls’
Dec 27 13:06:58 00[CFG] loading secrets from ‘/etc/strongswan/ipsec.secrets’
Dec 27 13:06:58 00[LIB] opening ‘/etc/strongswan/ipsec.d/private/server.key.pem’ failed: No such file or directory
Dec 27 13:06:58 00[LIB] building CRED_PRIVATE_KEY – RSA failed, tried 10 builders
Dec 27 13:06:58 00[CFG] loading private key from ‘/etc/strongswan/ipsec.d/private/server.key.pem’ failed
Dec 27 13:06:58 00[CFG] loaded IKE secret for %any
Dec 27 13:06:58 00[CFG] loaded EAP secret for liyuyang
Dec 27 13:06:58 00[CFG] loaded EAP secret for xujinghong
Dec 27 13:06:58 00[CFG] loaded EAP secret for user1_xauth
Dec 27 13:06:58 00[LIB] loaded plugins: charon aes des rc2 sha2 sha1 md4 md5 random nonce x509 revocation constraints acert pubkey pkcs1 pkcs8 pkcs12 pgp dnskey sshkey pem openssl gcrypt fips-prf gmp xcbc cmac hmac ctr ccm gcm curl attr kernel-netlink resolve socket-default farp stroke vici updown eap-identity eap-md5 eap-gtc eap-mschapv2 eap-tls eap-ttls eap-peap xauth-generic xauth-eap xauth-pam xauth-noauth dhcp
Dec 27 13:06:58 00[JOB] spawning 16 worker threads
您好请问这样的运行有错误是吧
我的客户端连接不上
Dec 27 13:17:53 05[NET] received packet: from 124.72.170.209[500] to 47.90.77.159[500] (604 bytes)
Dec 27 13:17:53 05[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(REDIR_SUP) N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) ]
Dec 27 13:17:53 05[IKE] no IKE config found for 47.90.77.159…124.72.170.209, sending NO_PROPOSAL_CHOSEN
Dec 27 13:17:53 05[ENC] generating IKE_SA_INIT response 0 [ N(NO_PROP) ]
Dec 27 13:17:53 05[NET] sending packet: from 47.90.77.159[500] to 124.72.170.209[500] (36 bytes)
然后登陆的时候这样……….大概是什么原因呢?