diff --git a/source/manual/how-tos/images/btn_save.png b/source/manual/how-tos/images/btn_save.png deleted file mode 100644 index 18125e24e..000000000 Binary files a/source/manual/how-tos/images/btn_save.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec-rw-linux-eapmschap.PNG b/source/manual/how-tos/images/ipsec-rw-linux-eapmschap.PNG deleted file mode 100644 index 59f854b30..000000000 Binary files a/source/manual/how-tos/images/ipsec-rw-linux-eapmschap.PNG and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec-rw-w7-1.png b/source/manual/how-tos/images/ipsec-rw-w7-1.png deleted file mode 100644 index 0bff6c609..000000000 Binary files a/source/manual/how-tos/images/ipsec-rw-w7-1.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec-rw-w7-2.png b/source/manual/how-tos/images/ipsec-rw-w7-2.png deleted file mode 100644 index bad3245c9..000000000 Binary files a/source/manual/how-tos/images/ipsec-rw-w7-2.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec-rw-w7-cert.png b/source/manual/how-tos/images/ipsec-rw-w7-cert.png deleted file mode 100644 index 6329294e9..000000000 Binary files a/source/manual/how-tos/images/ipsec-rw-w7-cert.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec-rw-w7-eapmschap.png b/source/manual/how-tos/images/ipsec-rw-w7-eapmschap.png deleted file mode 100644 index 28331e501..000000000 Binary files a/source/manual/how-tos/images/ipsec-rw-w7-eapmschap.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_ipsec_lan_rule.png b/source/manual/how-tos/images/ipsec_ipsec_lan_rule.png deleted file mode 100644 index adb5324b9..000000000 Binary files a/source/manual/how-tos/images/ipsec_ipsec_lan_rule.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_road_vpn_p1a.png b/source/manual/how-tos/images/ipsec_road_vpn_p1a.png deleted file mode 100644 index a2b2db8c5..000000000 Binary files a/source/manual/how-tos/images/ipsec_road_vpn_p1a.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_rw_android_ikev2-cert.png b/source/manual/how-tos/images/ipsec_rw_android_ikev2-cert.png deleted file mode 100644 index b2aa21652..000000000 Binary files a/source/manual/how-tos/images/ipsec_rw_android_ikev2-cert.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_rw_android_ikev2-certeap.png b/source/manual/how-tos/images/ipsec_rw_android_ikev2-certeap.png deleted file mode 100644 index c65c95889..000000000 Binary files a/source/manual/how-tos/images/ipsec_rw_android_ikev2-certeap.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_rw_android_ikev2-mschap1.png b/source/manual/how-tos/images/ipsec_rw_android_ikev2-mschap1.png deleted file mode 100644 index f7e098d00..000000000 Binary files a/source/manual/how-tos/images/ipsec_rw_android_ikev2-mschap1.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_rw_android_ikev2-mschap2.png b/source/manual/how-tos/images/ipsec_rw_android_ikev2-mschap2.png deleted file mode 100644 index dae76a49e..000000000 Binary files a/source/manual/how-tos/images/ipsec_rw_android_ikev2-mschap2.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_rw_android_ikev2-mschap3.png b/source/manual/how-tos/images/ipsec_rw_android_ikev2-mschap3.png deleted file mode 100644 index fd3093e0f..000000000 Binary files a/source/manual/how-tos/images/ipsec_rw_android_ikev2-mschap3.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_rw_android_mutualpsk1.png b/source/manual/how-tos/images/ipsec_rw_android_mutualpsk1.png deleted file mode 100644 index a667514a1..000000000 Binary files a/source/manual/how-tos/images/ipsec_rw_android_mutualpsk1.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_rw_android_mutualpsk2.png b/source/manual/how-tos/images/ipsec_rw_android_mutualpsk2.png deleted file mode 100644 index 91fc6b8dd..000000000 Binary files a/source/manual/how-tos/images/ipsec_rw_android_mutualpsk2.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_rw_android_mutualrsa1.png b/source/manual/how-tos/images/ipsec_rw_android_mutualrsa1.png deleted file mode 100644 index ea1b90c95..000000000 Binary files a/source/manual/how-tos/images/ipsec_rw_android_mutualrsa1.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_rw_android_mutualrsa2.png b/source/manual/how-tos/images/ipsec_rw_android_mutualrsa2.png deleted file mode 100644 index ce2c70fe3..000000000 Binary files a/source/manual/how-tos/images/ipsec_rw_android_mutualrsa2.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_s2s_route_azure_conn.png b/source/manual/how-tos/images/ipsec_s2s_route_azure_conn.png deleted file mode 100644 index 90963f967..000000000 Binary files a/source/manual/how-tos/images/ipsec_s2s_route_azure_conn.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_s2s_route_azure_lng.png b/source/manual/how-tos/images/ipsec_s2s_route_azure_lng.png deleted file mode 100644 index 3a50bc4dd..000000000 Binary files a/source/manual/how-tos/images/ipsec_s2s_route_azure_lng.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_s2s_vpn_p1a_4.png b/source/manual/how-tos/images/ipsec_s2s_vpn_p1a_4.png deleted file mode 100644 index ef3e1859d..000000000 Binary files a/source/manual/how-tos/images/ipsec_s2s_vpn_p1a_4.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_s2s_vpn_p1a_apply.png b/source/manual/how-tos/images/ipsec_s2s_vpn_p1a_apply.png deleted file mode 100644 index b6f00432e..000000000 Binary files a/source/manual/how-tos/images/ipsec_s2s_vpn_p1a_apply.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_s2s_vpn_p1a_enable.png b/source/manual/how-tos/images/ipsec_s2s_vpn_p1a_enable.png deleted file mode 100644 index 0f3818f5a..000000000 Binary files a/source/manual/how-tos/images/ipsec_s2s_vpn_p1a_enable.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_s2s_vpn_p1a_success.png b/source/manual/how-tos/images/ipsec_s2s_vpn_p1a_success.png deleted file mode 100644 index c8d42876b..000000000 Binary files a/source/manual/how-tos/images/ipsec_s2s_vpn_p1a_success.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_s2s_vpn_p1b_4.png b/source/manual/how-tos/images/ipsec_s2s_vpn_p1b_4.png deleted file mode 100644 index a6c78bb3e..000000000 Binary files a/source/manual/how-tos/images/ipsec_s2s_vpn_p1b_4.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_status.png b/source/manual/how-tos/images/ipsec_status.png deleted file mode 100644 index 83573f516..000000000 Binary files a/source/manual/how-tos/images/ipsec_status.png and /dev/null differ diff --git a/source/manual/how-tos/images/ipsec_wan_rules.png b/source/manual/how-tos/images/ipsec_wan_rules.png deleted file mode 100644 index d89a68a65..000000000 Binary files a/source/manual/how-tos/images/ipsec_wan_rules.png and /dev/null differ diff --git a/source/manual/how-tos/images/opnsense_nat_binat_ipsec.png b/source/manual/how-tos/images/opnsense_nat_binat_ipsec.png deleted file mode 100644 index 550952f70..000000000 Binary files a/source/manual/how-tos/images/opnsense_nat_binat_ipsec.png and /dev/null differ diff --git a/source/manual/how-tos/images/osx-ipsec-conf1.png b/source/manual/how-tos/images/osx-ipsec-conf1.png deleted file mode 100644 index 400222bda..000000000 Binary files a/source/manual/how-tos/images/osx-ipsec-conf1.png and /dev/null differ diff --git a/source/manual/how-tos/images/osx-ipsec-conf2.png b/source/manual/how-tos/images/osx-ipsec-conf2.png deleted file mode 100644 index ef2b2cc49..000000000 Binary files a/source/manual/how-tos/images/osx-ipsec-conf2.png and /dev/null differ diff --git a/source/manual/how-tos/images/osx-ipsec-connected.png b/source/manual/how-tos/images/osx-ipsec-connected.png deleted file mode 100644 index ed077b7e1..000000000 Binary files a/source/manual/how-tos/images/osx-ipsec-connected.png and /dev/null differ diff --git a/source/manual/how-tos/images/osx-ipsec-new.png b/source/manual/how-tos/images/osx-ipsec-new.png deleted file mode 100644 index 2b389a4de..000000000 Binary files a/source/manual/how-tos/images/osx-ipsec-new.png and /dev/null differ diff --git a/source/manual/how-tos/ipsec-rw-android.rst b/source/manual/how-tos/ipsec-rw-android.rst deleted file mode 100644 index ec24680b6..000000000 --- a/source/manual/how-tos/ipsec-rw-android.rst +++ /dev/null @@ -1,88 +0,0 @@ -================================== -IPsec: Setup Android Remote Access -================================== - -.. contents:: Index - -Here you can see the configuration options for all compatible VPN types. -We assume that you are familiar with adding a new VPN connection. - -All screenshot were taken from Android version 7. - ----------------------------- -Step 1 - Install Certificate ----------------------------- - -For all RSA or IKEv2 related VPN configurations we need to install the Root CA and sometimes also -the client certificate. Please export it do your device in a secure way like with an USB stick or a -local file exchange service like Nextcloud. Under settings search for "cert" and you will be prompted for -**Install certificates**. Navigate to the download directory and install the Root CA and - when configured - -the client certificate. - ---------------------------- -Step 2 - Add VPN Connection ---------------------------- - -Add a new VPN connection via :menuselection:`Settings --> More --> VPN`, enter a **Name** and choose the type you need. -Under **Server address** use your FQDN of the Firewall. Also keep in mind that it has to match with the -CN of your certificate! Opening **Advanced options** you can set **DNS search domains**, **DNS servers** -or **Forwarding routes**, which is the network you configured in Phase2 of your mobile VPN. - -If you want to use IKEv2 you have to use the strongSwan app_ via App Store, as Android stock VPN only -supports IKEv1. - -.. _app: https://play.google.com/store/apps/details?id=org.strongswan.android - -See the following screenshots for the different VPN types: - ------------------- -Mutual PSK + XAuth ------------------- - -.. image:: images/ipsec_rw_android_mutualpsk1.png - :width: 60% - -.. image:: images/ipsec_rw_android_mutualpsk2.png - :width: 60% - ------------------- -Mutual RSA + XAuth ------------------- - -.. image:: images/ipsec_rw_android_mutualrsa1.png - :width: 60% - -.. image:: images/ipsec_rw_android_mutualrsa2.png - :width: 60% - ----------------------------------- -IKEv2 + EAP-MSCHAPv2 or EAP-RADIUS ----------------------------------- - -.. image:: images/ipsec_rw_android_ikev2-mschap1.png - :width: 60% - -.. image:: images/ipsec_rw_android_ikev2-mschap2.png - :width: 60% - -.. image:: images/ipsec_rw_android_ikev2-mschap3.png - :width: 60% - ---------------- -IKEv2 + EAP-TLS ---------------- - -For EAP-TLS choose RSA (local)+ EAP-TLS (remote) in your OPNsense configuration. - -.. image:: images/ipsec_rw_android_ikev2-cert.png - :width: 60% - ---------------------------------- -IKEv2 + Mutual RSA + EAP-MSCHAPv2 ---------------------------------- - -This is the most secure combination! - -.. image:: images/ipsec_rw_android_ikev2-certeap.png - :width: 60% - diff --git a/source/manual/how-tos/ipsec-rw-linux.rst b/source/manual/how-tos/ipsec-rw-linux.rst deleted file mode 100644 index 55a7de28f..000000000 --- a/source/manual/how-tos/ipsec-rw-linux.rst +++ /dev/null @@ -1,37 +0,0 @@ -================================ -IPsec: Setup Linux Remote Access -================================ - -.. contents:: Index - -Here you can see the configuration options for all compatible VPN types. -We assume that you are familiar with adding a new VPN connection. - -The tests were done with Ubuntu 18.04 and network-manager-stronswan installed, Ubuntu only supports -OpenVPN and PPTP with the default install. - -It can be installed using the following command on the command line: - -.. code-block:: sh - - apt install network-manager-strongswan - ------------------------------- -Step 1 - Download Certificate ------------------------------- - -Download the Root CA from the OPNsense Firewall since it is needed for all EAP types with IKEv2. - ---------------------------- -Step 2 - Add VPN Connection ---------------------------- - -Open the network manager and add a new VPN connection. Choose **IPSec/IKEv2**, enter a **Name** and set -the **Address** to the FQDN matching the one of the certificate at your Firewall. - ----------------------------------- -IKEv2 + EAP-MSCHAPv2 or EAP-RADIUS ----------------------------------- - -.. image:: images/ipsec-rw-linux-eapmschap.PNG - :width: 60% diff --git a/source/manual/how-tos/ipsec-rw-srv-eapradius.rst b/source/manual/how-tos/ipsec-rw-srv-eapradius.rst deleted file mode 100644 index de8778ef4..000000000 --- a/source/manual/how-tos/ipsec-rw-srv-eapradius.rst +++ /dev/null @@ -1,139 +0,0 @@ -========================================== -IPsec: Setup OPNsense for IKEv2 EAP-RADIUS -========================================== - -.. contents:: Index - -EAP-RADIUS via IKEv2 is nearly the same as EAP-MSCHAPv2, but authentication is done against a Radius instance. -We assume you have read the first part at -:doc:`ipsec-rw` - ----------------------------- -Step 1 - Create Certificates ----------------------------- - -For EAP-RADIUS with IKEv2 you need to create a Root CA and a server certificate for your Firewall. - -For more information read `Setup Self-Signed Certificate Chains `_ - ---------------------- -Step 2 - Setup Radius ---------------------- - -If you already have a local Radius server, add a new client with the IP address of your Firewall, -set a shared secret, go to OPNsense UI to :menuselection:`System --> Access --> Servers` and add a new instance: - -============================ ================ ==================================== - **Descriptive Name** Name *Give it a name* - **Type** Radius *This is what we want* - **Hostname or IP Address** Radius IP *Set the IP of your Radius server* - **Shared Secret** s3cureP4ssW0rd *Choose a secure password* -============================ ================ ==================================== - -When you do not have an own Radius instance just use the OPNsense plugin and follow this guide: -:doc:`freeradius` - ------------------------ -Step 3 - Mobile Clients ------------------------ -First we will need to setup the mobile clients network and authentication source. -Go to :menuselection:`VPN --> IPsec --> Mobile Clients` - -For our example will use the following settings: - -IKE Extensions --------------- -========================== ============== ================================================ - **Enable** checked *check to enable mobile clients* - **User Authentication** Nothing *As we use Radius, no need to select anything* - **Group Authentication** none *Leave on none* - **Virtual Address Pool** 10.10.0.0/24 *Enter the IP range for the remote clients* -========================== ============== ================================================ - -You can select other options, but we will leave them all unchecked for this example. - -**Save** your settings and select **Create Phase1** when it appears. -Then enter the Mobile Client Phase 1 setting. - -------------------------------- -Step 4 - Phase 1 Mobile Clients -------------------------------- - -Phase 1 General information ---------------------------- -========================== ============= ================================================== - **Connection method** default *default is 'Start on traffic'* - **Key Exchange version** V2 *only V2 is supported for EAP-RADIUS* - **Internet Protocol** IPv4 - **Interface** WAN *choose the interface connected to the internet* - **Description** MobileIPsec *freely chosen description* -========================== ============= ================================================== - -Phase 1 proposal (Authentication) ---------------------------------- -=========================== ==================== ============================================= - **Authentication method** EAP-RADIUS *This is the method we want here* - **My identifier** Distinguished Name *Set the FQDN you used within certificate* - **My Certificate** Certificate *Choose the certificate from dropdown list* -=========================== ==================== ============================================= - -Phase 1 proposal (Algorithms) ------------------------------ -========================== ================ ============================================ - **Encryption algorithm** AES *For our example we will use AES/256 bits* - **Hash algorithm** SHA1, SHA256 *SHA1 and SHA256 for compatibility* - **DH key group** 1024, 2048 bit *1024 and 2048 bit for compatibility* - **Lifetime** 28800 sec *lifetime before renegotiation* -========================== ================ ============================================ - -Advanced Options are fine by default. - -**Save** your settings. - -------------------------------- -Step 5 - Phase 2 Mobile Clients -------------------------------- - -Press the button *+* in front of the phase 1 entry to add a new phase 2. - -General information -------------------- -================= =============== ============================= - **Mode** Tunnel IPv4 *Select Tunnel mode* - **Description** MobileIPsecP2 *Freely chosen description* -================= =============== ============================= - -Local Network -------------- -=================== ============ ============================== - **Local Network** LAN subnet *Route the local LAN subnet* -=================== ============ ============================== - -Phase 2 proposal (SA/Key Exchange) ----------------------------------- -=========================== ============== ==================================================== - **Protocol** ESP *Choose ESP for encryption* - **Encryption algorithms** AES / 256 *For this example we use AES 256* - **Hash algorithms** SHA1, SHA256 *Same as before, mix SHA1 and SHA256* - **PFS Key group** off *Most mobile systems do not support PFS in Phase2* - **Lifetime** 3600 sec -=========================== ============== ==================================================== - -**Save** your settings and **Enable IPsec**, Select: - -.. image:: images/ipsec_s2s_vpn_p1a_enable.png - -.. Note:: - - If you already had IPsec enabled and added Road Warrior setup, it is important to - restart the whole service via services widget in the upper right corner of IPSec pages - or via :menuselection:`System --> Diagnostics --> Services --> Strongswan` since applying configuration only - reloads it, but a restart also loads the required modules of strongSwan. - ------------------------- -Step 6 - Add IPsec Users ------------------------- - -Go to your RADIUS management console and start adding users! -If you are using our FreeRADIUS plugin follow the official guide: -:doc:`freeradius` diff --git a/source/manual/how-tos/ipsec-rw-srv-eaptls.rst b/source/manual/how-tos/ipsec-rw-srv-eaptls.rst deleted file mode 100644 index 7e9ce2bd1..000000000 --- a/source/manual/how-tos/ipsec-rw-srv-eaptls.rst +++ /dev/null @@ -1,128 +0,0 @@ -======================================= -IPsec: Setup OPNsense for IKEv2 EAP-TLS -======================================= - -.. contents:: Index - -EAP-TLS via IKEv2 is based on client certificate authentication. -Be sure to install the client certificate on your enduser device. - ----------------------------- -Step 1 - Create Certificates ----------------------------- - -For EAP-TLS with IKEv2 you need to create a Root CA and a server certificate for your Firewall. - -For more information read `Setup Self-Signed Certificate Chains `_ - ------------------------ -Step 2 - Mobile Clients ------------------------ -First we will need to setup the mobile clients network and authentication source. -Go to :menuselection:`VPN --> IPsec --> Mobile Clients` - -For our example we will use the following settings: - -IKE Extensions --------------- -========================== ================ ============================================= - **Enable** checked *check to enable mobile clients* - **User Authentication** Local Database *For the example we use the Local Database* - **Group Authentication** none *Leave on none* - **Virtual Address Pool** 10.10.0.0/24 *Enter the IP range for the remote clients* -========================== ================ ============================================= - -You can select other options, but we will leave them all unchecked for this example. - -**Save** your settings and select **Create Phase1** when it appears. -Then enter the Mobile Client Phase 1 setting. - -------------------------------- -Step 3 - Phase 1 Mobile Clients -------------------------------- - -Phase 1 General information ---------------------------- -========================== ============= ================================================== - **Connection method** default *default is 'Start on traffic'* - **Key Exchange version** V2 *only V2 is supported for EAP-TLS* - **Internet Protocol** IPv4 - **Interface** WAN *choose the interface connected to the internet* - **Description** MobileIPsec *freely chosen description* -========================== ============= ================================================== - -Phase 1 proposal (Authentication) ---------------------------------- -=========================== ==================== ============================================= - **Authentication method** EAP-TLS *This is the method we want here* - **My identifier** Distinguished Name *Set the FQDN you used within certificate* - **My Certificate** Certificate *Choose the certificate from dropdown list* -=========================== ==================== ============================================= - -.. Note:: - - Some clients require RSA as remote like Strongswan Android App. If you encounter problem with - your client devices replace **Authentication method** to **RSA (local) + EAP-TLS (remote)** - -Phase 1 proposal (Algorithms) ------------------------------ -========================== ================ ============================================ - **Encryption algorithm** AES *For our example we will use AES/256 bits* - **Hash algorithm** SHA1, SHA256 *SHA1 and SHA256 for compatibility* - **DH key group** 1024, 2048 bit *1024 and 2048 bit for compatibility* - **Lifetime** 28800 sec *lifetime before renegotiation* -========================== ================ ============================================ - -Advanced Options are fine by default. - -**Save** your settings. - -------------------------------- -Step 3 - Phase 2 Mobile Clients -------------------------------- - -Press the button *+* in front of the phase 1 entry to add a new phase 2. - -General information -------------------- -================= =============== ============================= - **Mode** Tunnel IPv4 *Select Tunnel mode* - **Description** MobileIPsecP2 *Freely chosen description* -================= =============== ============================= - -Local Network -------------- -=================== ============ ============================== - **Local Network** LAN subnet *Route the local LAN subnet* -=================== ============ ============================== - -Phase 2 proposal (SA/Key Exchange) ----------------------------------- -=========================== ============== ==================================================== - **Protocol** ESP *Choose ESP for encryption* - **Encryption algorithms** AES / 256 *For this example we use AES 256* - **Hash algorithms** SHA1, SHA256 *Same as before, mix SHA1 and SHA256* - **PFS Key group** off *Most mobile systems do not support PFS in Phase2* - **Lifetime** 3600 sec -=========================== ============== ==================================================== - -**Save** your settings and **Enable IPsec**, Select: - -.. image:: images/ipsec_s2s_vpn_p1a_enable.png - - -.. Note:: - - If you already had IPsec enabled and added Road Warrior setup, it's important to - restart the whole service via services widget in the upper right corner of IPSec pages - or via :menuselection:`System --> Diagnostics --> Services --> Strongswan` since applying configuration only - reloads it, but a restart also loads the required modules of strongSwan. - ------------------------- -Step 4 - Add IPsec Users ------------------------- - -Go to :menuselection:`System --> Trust --> Certificates` and create a new client certificate. -Just click **Add**, choose your CA and probably increase the lifetime. Everything else besides -the CN can be left default. Give a **Common Name** and **Save**. Download the newly created -certificate as PKCS12 and export it to your end user device. diff --git a/source/manual/how-tos/ipsec-rw-srv-ikev1xauth.rst b/source/manual/how-tos/ipsec-rw-srv-ikev1xauth.rst deleted file mode 100644 index e5c8c5ff5..000000000 --- a/source/manual/how-tos/ipsec-rw-srv-ikev1xauth.rst +++ /dev/null @@ -1,231 +0,0 @@ -=========================================== -IPsec: Setup OPNsense for IKEv1 using XAuth -=========================================== - -.. contents:: Index - -XAuth was an addition to IKEv1 supporting user authentication credentials additionally to -pre-shared keys or certificates. There are three different types supported by OPNsense which -we will describe here. - -Mutual PSK + XAuth: You define a pre-shared key which is the same for every user and after securing -the channel the user authentication via XAuth comes into play. -Mutual RSA + XAuth: Instead of using a pre-shared key, every device needs a client certificate to secure -the connection plus XAuth for authentication. This is the most secure variant for IKEv1/XAuth but also -with the most work to do. -Hybrid RSA + XAuth: Hybrid RSA is the same as Mutual, without the need for a client certificate. Only -the server will be authenticated (like using HTTPS) to prevent man-in-the-middle attacks like with -Mutual PSK. It is more secure than PSK but does not need the complete roll-out process like with Mutual RSA. - -We assume you have read the first part at -:doc:`ipsec-rw` - ----------------------------------------------------- -Step 1 - Create Certificates (only for RSA variants) ----------------------------------------------------- - -For Mutual RSA + XAuth and Hybrid RSA + XAuth you need to create a Root CA and a server certificate -for your Firewall. - -For more information read `Setup Self-Signed Certificate Chains `_ - ------------------------ -Step 2 - Mobile Clients ------------------------ -First we will need to setup the mobile clients network and authentication source. -Go to :menuselection:`VPN --> IPsec --> Mobile Clients` - -For our example will use the following settings: - -IKE Extensions --------------- -========================== ================ ============================================= - **Enable** checked *check to enable mobile clients* - **User Authentication** Local Database *For the example we use the Local Database* - **Group Authentication** none *Leave on none* - **Virtual Address Pool** 10.10.0.0/24 *Enter the IP range for the remote clients* -========================== ================ ============================================= - -You can select other options, but we will leave them all unchecked for this example. - -**Save** your settings and select **Create Phase1** when it appears. -Then enter the Mobile Client Phase 1 setting. - -------------------------------- -Step 3 - Phase 1 Mobile Clients -------------------------------- - -Phase 1 General information ---------------------------- -========================== ============= ================================================== - **Connection method** default *default is 'Start on traffic'* - **Key Exchange version** V1 *XAuth only works on V1* - **Internet Protocol** IPv4 - **Interface** WAN *choose the interface connected to the internet* - **Description** MobileIPsec *freely chosen description* -========================== ============= ================================================== - -Phase 1 proposal (Authentication) ---------------------------------- -=========================== ==================== ========================================================================== - **Authentication method** XAuth *Choose one of the three available options* - **Negotiation mode** Main Mode *Use Main Mode here* - **My identifier** Distinguished Name *Set the FQDN you used within certificate, for PSK use "My IP address"* - **Pre-shared Key** Shared secret *For Mutual PSK + XAuth use this PSK, otherwise certificate below* - **My Certificate** Certificate *Choose the certificate from dropdown list, only valid for RSA variants* -=========================== ==================== ========================================================================== - -Phase 1 proposal (Algorithms) ------------------------------ -========================== ================ ============================================ - **Encryption algorithm** AES *For our example we will use AES/256 bits* - **Hash algorithm** SHA1, SHA256 *SHA1 and SHA256 for compatibility* - **DH key group** 1024, 2048 bit *1024 and 2048 bit for compatibility* - **Lifetime** 28800 sec *lifetime before renegotiation* -========================== ================ ============================================ - -Advanced Options are fine by default. - -**Save** your settings. - -------------------------------- -Step 3 - Phase 2 Mobile Clients -------------------------------- - -Press the button *+* in front of the phase 1 entry to add a new phase 2. - -General information -------------------- -================= =============== ============================= - **Mode** Tunnel IPv4 *Select Tunnel mode* - **Description** MobileIPsecP2 *Freely chosen description* -================= =============== ============================= - -Local Network -------------- -=================== ============ ============================== - **Local Network** LAN subnet *Route the local LAN subnet* -=================== ============ ============================== - -Phase 2 proposal (SA/Key Exchange) ----------------------------------- -=========================== ============== ==================================================== - **Protocol** ESP *Choose ESP for encryption* - **Encryption algorithms** AES / 256 *For this example we use AES 256* - **Hash algorithms** SHA1, SHA256 *Same as before, mix SHA1 and SHA256* - **PFS Key group** off *Most mobile systems do not support PFS in Phase2* - **Lifetime** 3600 sec -=========================== ============== ==================================================== - -**Save** your settings and **Enable IPsec**, Select: - -.. image:: images/ipsec_s2s_vpn_p1a_enable.png - - -.. Note:: - - If you already had IPsec enabled and added Road Warrior setup, it is important to - restart the whole service via services widget in the upper right corner of IPSec pages - or via :menuselection:`System --> Diagnostics --> Services --> Strongswan` since applying configuration only - reloads it, but a restart also loads the required modules of strongSwan. - ------------------------- -Step 4 - Add IPsec Users ------------------------- - -Go to :menuselection:`System --> Access --> Users` and press the **+** sign in the lower right corner -to add a new user. - -Enter the following into the form: - -=============== ========== - **User Name** expert - **Password** &test!9T -=============== ========== - -**Save** to apply. - ------------------------------------------------- -Step 5 - Add client certificate (for Mutual RSA) ------------------------------------------------- - -This step is only needed for Mutual RSA + XAuth! - -Go to :menuselection:`System --> Trust --> Certificates` and create a new client certificate. -Just click **Add**, choose your CA and probably increase the lifetime. Everything else besides -the CN can be left default. Give a **Common Name** and **Save**. Download the newly created -certificate as PKCS12 and export it to you enduser device. - - -------------------------- -Step 6 - Configure Client -------------------------- -To illustrate the client setup we will look at the configuration under macOS, including -some screenshots. The configurations for Android and iOS will be settings only. - -.. Note:: - Configuration samples listed here where created using latest macOS, iOS and - Android devices on time of publication in February 2016. - ----------------------- -Configure macOS Client ----------------------- - -Start with opening your network settings (:menuselection:`System Preferences --> Network)` and -Add a new network by pressing the + in the lower left corner. - -Now select **VPN** and **Cisco IPSec**, give your connection a name and press **Create**. - -.. image:: images/osx-ipsec-new.png - :width: 70% - -Now enter the details for our connection: - -.. image:: images/osx-ipsec-conf1.png - :width: 70% - -Next press **Authentication Settings** to add the group name and pre-shared key. - -.. image:: images/osx-ipsec-conf2.png - :width: 70% - -Press **OK** to save these settings and then **Apply** to apply them. - -Now test the connection by selecting it from the list and hit **Connect**. - -.. image:: images/osx-ipsec-connected.png - :width: 70% - -**Done** - --------------------- -Configure iOS Client --------------------- -To add a VPN connection on an iOS device go to :menuselection:`Settings --> General --> VPN`. -Select **Add VPN Configuration** chose **IPsec** and use the Following Settings: - -========================== ======================= ======================================== - **Description** IPsec OPNsense *Freely chosen description* - **Server** 172.18.0.164 *Our server address* - **Account** expert *Username of the remote account* - **Password** &test!9T *Leave blank to be prompted every time* - **Preshared IPsec-key** At4aDMOAOub2NwT6gMHA *Our PSK* -========================== ======================= ======================================== - ------------------------- -Configure Android Client ------------------------- -To add a VPN connection on an Android device go to :menuselection:`Settings --> Connections --> more networks`, -select **VPN**. Press the **+** in the top right corner to add a new VPN connection. - -Use the Following Settings: - -========================== ======================= ============================= - **Name** IPsec OPNsense *Freely chosen name* - **Type** IPSec Xauth PSK *As configured in OPNsense* - **Server address** 172.18.0.164 *Our server address* - **Preshared IPsec-key** At4aDMOAOub2NwT6gMHA *Our PSK* -========================== ======================= ============================= - -**Save** and try connecting. To connect enter Username and Password for the user -*expert* we created in this example. diff --git a/source/manual/how-tos/ipsec-rw-srv-mschapv2.rst b/source/manual/how-tos/ipsec-rw-srv-mschapv2.rst deleted file mode 100644 index c3c1dc404..000000000 --- a/source/manual/how-tos/ipsec-rw-srv-mschapv2.rst +++ /dev/null @@ -1,142 +0,0 @@ -============================================ -IPsec: Setup OPNsense for IKEv2 EAP-MSCHAPv2 -============================================ - -.. contents:: Index - -EAP-MSCHAPv2 via IKEv2 is the most compatible combination. -We assume you have read the first part at -:doc:`ipsec-rw` - ----------------------------- -Step 1 - Create Certificates ----------------------------- - -For EAP-MSCHAPv2 with IKEv2 you need to create a Root CA and a server certificate -for your Firewall. - -Go to :menuselection:`System --> Trust --> Authorities` and click **Add**. Give it a **Descriptive Name** and as **Method** -choose **Create internal Certificate Authority**. Increase the **Lifetime** and fill in the fields -matching your local values. Now go to :menuselection:`System --> Trust --> Certificates` and create a new certificate for -the Firewall itself. Important is to change the **Type** to server. The Common Name can be the hostname -of the Firewall and set as **Alternative Name** the FQDN your Firewall how it is known to the WAN side. -This is most important as your VPN will drop when the FQDN does not match the ones of the certificate. - -If you already have a CA roll out a server certificate and import -the CA itself via :menuselection:`System --> Trust --> Authorities` and the certificate with the key in -:menuselection:`System --> Trust --> Certificates`. - ------------------------ -Step 2 - Mobile Clients ------------------------ -First we will need to setup the mobile clients network and authentication source. -Go to :menuselection:`VPN --> IPsec --> Mobile Clients` - -For our example will use the following settings: - -IKE Extensions --------------- -========================== ================ ============================================= - **Enable** checked *check to enable mobile clients* - **User Authentication** Local Database *For the example we use the Local Database* - **Group Authentication** none *Leave on none* - **Virtual Address Pool** 10.10.0.0/24 *Enter the IP range for the remote clients* -========================== ================ ============================================= - -You can select other options, but we will leave them all unchecked for this example. - -**Save** your settings and select **Create Phase1** when it appears. -Then enter the Mobile Client Phase 1 setting. - -------------------------------- -Step 3 - Phase 1 Mobile Clients -------------------------------- - -Phase 1 General information ---------------------------- -========================== ============= ================================================== - **Connection method** default *default is 'Start on traffic'* - **Key Exchange version** V2 *only V2 is supported for EAP-MSCHAPv2* - **Internet Protocol** IPv4 - **Interface** WAN *choose the interface connected to the internet* - **Description** MobileIPsec *freely chosen description* -========================== ============= ================================================== - -Phase 1 proposal (Authentication) ---------------------------------- -=========================== ==================== ============================================= - **Authentication method** EAP-MSCHAPv2 *This is the method we want here* - **My identifier** Distinguished Name *Set the FQDN you used within certificate* - **My Certificate** Certificate *Choose the certificate from dropdown list* -=========================== ==================== ============================================= - -Phase 1 proposal (Algorithms) ------------------------------ -========================== ================ ============================================ - **Encryption algorithm** AES *For our example we will use AES/256 bits* - **Hash algorithm** SHA1, SHA256 *SHA1 and SHA256 for compatibility* - **DH key group** 1024, 2048 bit *1024 and 2048 bit for compatibility* - **Lifetime** 28800 sec *lifetime before renegotiation* -========================== ================ ============================================ - -Advanced Options are fine by default. - -**Save** your settings. - -------------------------------- -Step 3 - Phase 2 Mobile Clients -------------------------------- - -Press the button *+* in front of the phase 1 entry to add a new phase 2. - -General information -------------------- -================= =============== ============================= - **Mode** Tunnel IPv4 *Select Tunnel mode* - **Description** MobileIPsecP2 *Freely chosen description* -================= =============== ============================= - -Local Network -------------- -=================== ============ ============================== - **Local Network** LAN subnet *Route the local LAN subnet* -=================== ============ ============================== - -Phase 2 proposal (SA/Key Exchange) ----------------------------------- -=========================== ============== ==================================================== - **Protocol** ESP *Choose ESP for encryption* - **Encryption algorithms** AES / 256 *For this example we use AES 256* - **Hash algorithms** SHA1, SHA256 *Same as before, mix SHA1 and SHA256* - **PFS Key group** off *Most mobile systems do not support PFS in Phase2* - **Lifetime** 3600 sec -=========================== ============== ==================================================== - -**Save** your settings and **Enable IPsec**, Select: - -.. image:: images/ipsec_s2s_vpn_p1a_enable.png - - -.. Note:: - - If you already had IPsec enabled and added Road Warrior setup, it is important to - restart the whole service via services widget in the upper right corner of IPSec pages - or via :menuselection:`System --> Diagnostics --> Services --> Strongswan` since applying configuration only - reloads it, but a restart also loads the required modules of strongSwan. - ------------------------- -Step 4 - Add IPsec Users ------------------------- - -Go to :menuselection:`VPN --> IPsec --> Pre-Shared Keys` and press **Add**. - -Enter the following into the form: - -==================== ========== - **Identifier** expert - **Pre-Shared Key** &test!9T - **Type** EAP -==================== ========== - - -**Save** to apply and you are done here. diff --git a/source/manual/how-tos/ipsec-rw-srv-rsamschapv2.rst b/source/manual/how-tos/ipsec-rw-srv-rsamschapv2.rst deleted file mode 100644 index 83420c879..000000000 --- a/source/manual/how-tos/ipsec-rw-srv-rsamschapv2.rst +++ /dev/null @@ -1,136 +0,0 @@ -===================================================== -IPsec: Setup OPNsense for IKEv2 Mutual RSA + MSCHAPv2 -===================================================== - -.. contents:: Index - -Mutual RSA + MSCHAPv2 via IKEv2 is based on client certificate authentication combined with username -and password via MSCHAPv2. -Be sure that the client certificate is installed on your users device. - ----------------------------- -Step 1 - Create Certificates ----------------------------- - -For Mutual RSA + MSCHAPv2 with IKEv2 you need to create a Root CA and a server certificate -for your Firewall. - -For more information read `Setup Self-Signed Certificate Chains `_ - ------------------------ -Step 2 - Mobile Clients ------------------------ -First we will need to setup the mobile clients network and authentication source. -Go to :menuselection:`VPN --> IPsec --> Mobile Clients` - -For our example will use the following settings: - -IKE Extensions --------------- -========================== ================ ============================================= - **Enable** checked *check to enable mobile clients* - **User Authentication** Local Database *For the example we use the Local Database* - **Group Authentication** none *Leave on none* - **Virtual Address Pool** 10.10.0.0/24 *Enter the IP range for the remote clients* -========================== ================ ============================================= - -You can select other options, but we will leave them all unchecked for this example. - -**Save** your settings and select **Create Phase1** when it appears. -Then enter the Mobile Client Phase 1 setting. - -------------------------------- -Step 3 - Phase 1 Mobile Clients -------------------------------- - -Phase 1 General information ---------------------------- -========================== ============= ================================================== - **Connection method** default *default is 'Start on traffic'* - **Key Exchange version** V2 *only V2 is supported for this type* - **Internet Protocol** IPv4 - **Interface** WAN *choose the interface connected to the internet* - **Description** MobileIPsec *freely chosen description* -========================== ============= ================================================== - -Phase 1 proposal (Authentication) ---------------------------------- -=========================== ======================= ============================================ - **Authentication method** Mutual RSA + MSCHAPv2 *This is the method we want here* - **My identifier** Distinguished Name *Set the FQDN you used within certificate* - **My Certificate** Certificate *Choose the certificate from dropdown list* -=========================== ======================= ============================================ - - -Phase 1 proposal (Algorithms) ------------------------------ -========================== ================ ============================================ - **Encryption algorithm** AES *For our example we will use AES/256 bits* - **Hash algorithm** SHA1, SHA256 *SHA1 and SHA256 for compatibility* - **DH key group** 1024, 2048 bit *1024 and 2048 bit for compatibility* - **Lifetime** 28800 sec *lifetime before renegotiation* -========================== ================ ============================================ - -Advanced Options are fine by default. - -**Save** your settings. - -------------------------------- -Step 3 - Phase 2 Mobile Clients -------------------------------- - -Press the button *+* in front of the phase 1 entry to add a new phase 2. - -General information -------------------- -================= =============== ============================= - **Mode** Tunnel IPv4 *Select Tunnel mode* - **Description** MobileIPsecP2 *Freely chosen description* -================= =============== ============================= - -Local Network -------------- -=================== ============ ============================== - **Local Network** LAN subnet *Route the local LAN subnet* -=================== ============ ============================== - -Phase 2 proposal (SA/Key Exchange) ----------------------------------- -=========================== ============== ==================================================== - **Protocol** ESP *Choose ESP for encryption* - **Encryption algorithms** AES / 256 *For this example we use AES 256* - **Hash algorithms** SHA1, SHA256 *Same as before, mix SHA1 and SHA256* - **PFS Key group** off *Most mobile systems do not support PFS in Phase2* - **Lifetime** 3600 sec -=========================== ============== ==================================================== - -**Save** your settings and **Enable IPsec**, Select: - -.. image:: images/ipsec_s2s_vpn_p1a_enable.png - - -.. Note:: - - If you already had IPsec enabled and added Road Warrior setup, it is important to - restart the whole service via services widget in the upper right corner of IPSec pages - or via :menuselection:`System --> Diagnostics --> Services --> Strongswan` since applying configuration only - reloads it, but a restart also loads the required modules of strongSwan. - ------------------------- -Step 4 - Add IPsec Users ------------------------- - -Go to :menuselection:`System --> Trust --> Certificates` and create a new client certificate. -Just click **Add**, choose your CA and probably increase the lifetime. Everything else besides -the CN can be left default. Give a **Common Name** and **Save**. Download the newly created -certificate as PKCS12 and export it to you enduser device. - - -Switch to :menuselection:`VPN -> IPsec -> Pre-Shared Keys` and press **Add**. -Enter the following into the form: - -==================== ========== - **Identifier** expert - **Pre-Shared Key** &test!9T - **Type** EAP -==================== ========== diff --git a/source/manual/how-tos/ipsec-rw-w7.rst b/source/manual/how-tos/ipsec-rw-w7.rst deleted file mode 100644 index 10b93afe0..000000000 --- a/source/manual/how-tos/ipsec-rw-w7.rst +++ /dev/null @@ -1,63 +0,0 @@ -================================== -IPsec: Setup Windows Remote Access -================================== - -.. contents:: Index - -Here you can see the configuration options for all compatible VPN types. -We assume that you are familiar with adding a new VPN connection. - -The tests were done with Windows 7 and 10. - -All screenshot were taken from :menuselection:`Network and Sharing Center --> Change adapter settings`. - ---------------------------- -Step 1 - Install Certificte ---------------------------- - -Since Windows 7 also supports IKEv2 we need to install your Root Certificate Authority. -Hit the Windows Start button and type *mmc* in search box. Go to :menuselection:`File --> Add/Remove Snap-In`. -Choose :menuselection:`Certificates --> Add --> Computer account`. -Open **Certificate** and navigate to **Trusted Root Certificate Authorities**, right click, -**All taks** and import. Select the Root CA and install. - -If you are using client certificates for authentication (e.g EAP-TLS) use a PKCS12/PFX and install -it under **Personal** instead of **Trusted Root Certificate Authorities**. All included certificates -will be installed in the correct folders. - -.. image:: images/ipsec-rw-w7-cert.png - :width: 60% - ---------------------------- -Step 2 - Add VPN Connection ---------------------------- - -Add a new VPN connection via **Network and Sharing Center** and choose as **Internet Address** -the correct FQDN. This is imporatant when using certificates since the FQDN of your connection -and the one in the certificate has to match! -Then set a **Username** and **Password** and leave **Domain** empty. - -------------------- -Step 3 - Finetuning -------------------- - -Via **Network and Sharing Center** go to **Change adapter settings** and open the properties -of your newly created adapter. Check that the FQDN is correct: - -.. image:: images/ipsec-rw-w7-1.png - :width: 60% - -On tab **Networking** in IPv4 configuration under **Advanced** is the option **Use default gateway on remote network**. -If this option is enabled, all traffic will be sent through the VPN (if IPsec SA matches). When unchecked, you have -to set specific routes sent via VPN. - -.. image:: images/ipsec-rw-w7-2.png - :width: 60% - ----------------------------------- -IKEv2 + EAP-MSCHAPv2 or EAP-RADIUS ----------------------------------- - -.. image:: images/ipsec-rw-w7-eapmschap.png - :width: 60% - diff --git a/source/manual/how-tos/ipsec-rw.rst b/source/manual/how-tos/ipsec-rw.rst deleted file mode 100644 index f7605d0da..000000000 --- a/source/manual/how-tos/ipsec-rw.rst +++ /dev/null @@ -1,138 +0,0 @@ -================================================= -Road Warriors - Setup Remote Access -================================================= - -.. contents:: Index - ------ -Intro ------ - -Remote access to the company's infrastructure is one of most important and critical services exposed -to the internet. IPsec Mobile Clients offer mobile users (formerly known as Road Warriors) a solution -that is easy to setup and compatible with most current devices. - -With this guide we will show you how to configure the server side on OPNsense with the different -authentication methods e.g. - -* EAP-MSCHAPv2 -* Mutual-PSK + XAuth -* Mutual-RSA + XAuth -* ... - - -.. Note:: - - For the sample we will use a private ip for our WAN connection. - This requires us to disable the default block rule on WAN to allow private traffic. - To do so, go to :menuselection:`Interfaces --> [WAN]` and uncheck “Block private networks”. - *(Don't forget to save and apply)* - - .. image:: images/block_private_networks.png - ------------- -Sample Setup ------------- -All configuration examples are based on the following setup, please read this carefully -as all guides depend on it. - -**Company Network with Remote Client** - -.. nwdiag:: - :scale: 100% - - nwdiag { - - span_width = 90; - node_width = 180; - Internet [shape = "cisco.cloud"]; - fileserver [label="File Server",shape="cisco.fileserver",address="192.168.1.10"]; - fileserver -- switchlan; - - network LAN { - switchlan [label="",shape = "cisco.workgroup_switch"]; - label = " LAN"; - address ="192.168.1.x/24"; - fw1 [address="192.168.1.1/24"]; - } - - network WAN { - label = " WAN"; - fw1 [shape = "cisco.firewall", address="172.18.0.164"]; - Internet; - } - - network Remote { - Internet; - laptop [address="172.10.10.55 (WANIP),10.10.0.1 (IPsec)",label="Remote User",shape="cisco.laptop"]; - } - } - -Company Network ---------------- -==================== ============================= - **Hostname** fw1 - **WAN IP** 172.18.0.164 - **LAN IP** 192.168.1.0/24 - **LAN DHCP Range** 192.168.1.100-192.168.1.200 - **IPsec Clients** 10.10.0.0/24 -==================== ============================= - - ---------------------------- -Firewall Rules Mobile Users ---------------------------- -To allow IPsec Tunnel Connections, the following should be allowed on WAN. - -* Protocol ESP -* UDP Traffic on Port 500 (ISAKMP) -* UDP Traffic on Port 4500 (NAT-T) - -.. image:: images/ipsec_wan_rules.png - :width: 100% - -To allow traffic passing to your LAN subnet you need to add a rule to the IPsec -interface. - -.. image:: images/ipsec_ipsec_lan_rule.png - :width: 100% - ------------------ -VPN compatibility ------------------ - -In the next table you can see the existing VPN authentication mechanisms and which client -operating systems support it, with links to their configurations. -For Linux testing was done with Ubuntu 18.4 Desktop and *network-manager-strongswan* and -*libcharon-extra-plugins* installed. -As Android does not support IKEv2 yet we added notes for combinations with strongSwan -app installed to have a broader compatibility for all systems. -Mutual RSA and PSK without XAuth requires L2TP, since this legacy technology is -very error prone we will not cover it here. - -.. csv-table:: VPN combinations - :header: "VPN Method", "Win7", "Win10", "Linux", "Mac OS X", "IOS", "Android", "OPNsense config" - :widths: 40, 20, 20, 20, 20, 20, 20, 20 - - "IKEv1 Hybrid RSA + XAuth","N","N","N","tbd","tbd","N",":doc:`/manual/how-tos/ipsec-rw-srv-ikev1xauth`" - "IKEv1 Mutual RSA + XAuth","N","N","N","tbd","tbd","Y :doc:`/manual/how-tos/ipsec-rw-android`",":doc:`/manual/how-tos/ipsec-rw-srv-ikev1xauth`" - "IKEv1 Mutual PSK + XAuth","N","N","N","tbd","tbd","Y :doc:`/manual/how-tos/ipsec-rw-android`",":doc:`/manual/how-tos/ipsec-rw-srv-ikev1xauth`" - "IKEv2 EAP-TLS","N","N","N","tbd","tbd","Y :doc:`/manual/how-tos/ipsec-rw-android`",":doc:`/manual/how-tos/ipsec-rw-srv-eaptls`" - "IKEv2 RSA local + EAP remote","N","N","N","tbd","tbd","Y :doc:`/manual/how-tos/ipsec-rw-android`",":doc:`/manual/how-tos/ipsec-rw-srv-eaptls`" - "IKEv2 EAP-MSCHAPv2","Y :doc:`/manual/how-tos/ipsec-rw-w7`","Y :doc:`/manual/how-tos/ipsec-rw-w7`","Y :doc:`/manual/how-tos/ipsec-rw-linux`","Y","Y","Y :doc:`/manual/how-tos/ipsec-rw-android`",":doc:`/manual/how-tos/ipsec-rw-srv-mschapv2`" - "IKEv2 Mutual RSA + EAP-MSCHAPv2","N","N","N","tbd","tbd","Y :doc:`/manual/how-tos/ipsec-rw-android`",":doc:`/manual/how-tos/ipsec-rw-srv-rsamschapv2`" - "IKEv2 EAP-RADIUS","Y :doc:`/manual/how-tos/ipsec-rw-w7`","Y :doc:`/manual/how-tos/ipsec-rw-w7`","Y :doc:`/manual/how-tos/ipsec-rw-linux`","Y","Y","Y :doc:`/manual/how-tos/ipsec-rw-android`",":doc:`/manual/how-tos/ipsec-rw-srv-eapradius`" - ------------------ -List of examples ------------------ - -.. toctree:: - :maxdepth: 2 - :titlesonly: - - ipsec-rw-srv-eapradius - ipsec-rw-srv-eaptls - ipsec-rw-srv-ikev1xauth - ipsec-rw-srv-mschapv2 - ipsec-rw-srv-rsamschapv2 diff --git a/source/manual/how-tos/ipsec-s2s-binat.rst b/source/manual/how-tos/ipsec-s2s-binat.rst deleted file mode 100644 index 79f88e1c5..000000000 --- a/source/manual/how-tos/ipsec-s2s-binat.rst +++ /dev/null @@ -1,56 +0,0 @@ -================================= -IPSec - BINAT (NAT before IPSec) -================================= - - -.. nwdiag:: - :scale: 100% - - nwdiag { - - span_width = 90; - node_width = 180; - - network LANA { - label = " LAN Site A"; - address ="10.0.1.0/24"; - lana [label="Network A"]; - } - - network NATA { - label = " Tunnel network"; - address ="192.168.1.0/24"; - lana [label="Network A"]; - virtuala [label="Virtual net A", shape = cloud]; - } - - network NATB { - label = " Tunnel network"; - address ="192.168.2.0/24"; - virtuala [label="Virtual net A", shape = cloud] - virtualb [label="Virtual net B", shape = cloud]; - } - - network LANB { - label = " LAN Site B"; - virtualb [label="Virtual net B", shape = cloud]; - lanb [label="Network B"]; - } - - } - - -Assume company A has local LAN 10.0.1.0/24 and company B has local LAN 10.0.2.0/24. -Also we assume that on both sides the other networks are already in use, e.g. in company A the network 10.0.2.0/24 is used for Voice and in company B network 10.0.1.0/24 is used for Guest Wi-Fi. - -We have to define new networks for the Phase 2 with unused ones and create NAT entries to reach the final systems. - -To make it easier we create a Phase2 with company A using 192.168.1.0/24 as *Local Network* and 192.168.2.0/24 as *Remote Network* and with company B using 192.168.2.0/24 as *Local network* and 192.168.1.0/24 as *Remote Network*. -Now we need to add on each side the local LAN in the field "Manual SPD entries". So for company A we set 10.0.1.0/24 in the field and for B 10.0.2.0/24. -This allows the NAT process to speak with the Security Policy Database. - -Finally we have to create NAT entries since a client in LAN A (10.0.1.10) tries to reach 192.168.2.10, but this address has to be rewritten to 10.0.2.10 on Firewall B. - -Create the rule like in the screenshot and vice versa on Firewall A: - -.. image:: images/opnsense_nat_binat_ipsec.png diff --git a/source/manual/how-tos/ipsec-s2s-conn-route.rst b/source/manual/how-tos/ipsec-s2s-conn-route.rst index afaa492c7..41486929c 100644 --- a/source/manual/how-tos/ipsec-s2s-conn-route.rst +++ b/source/manual/how-tos/ipsec-s2s-conn-route.rst @@ -2,7 +2,7 @@ IPsec - Route based (VTI) PSK setup ==================================== -This example utilises the new options available in OPNsense 23.1 to setup a site to site tunnel in routed mode +This example uses the Connections interface to set up a site-to-site tunnel in routed mode between two OPNsense machines using a pre shared key. .. contents:: Index diff --git a/source/manual/how-tos/ipsec-s2s-conn.rst b/source/manual/how-tos/ipsec-s2s-conn.rst index f3c4ca086..31bf9df5f 100644 --- a/source/manual/how-tos/ipsec-s2s-conn.rst +++ b/source/manual/how-tos/ipsec-s2s-conn.rst @@ -2,7 +2,7 @@ IPsec - Policy based public key setup ======================================== -This example utilises the new options available in OPNsense 23.1 to setup a site to site tunnel in policy mode +This example uses the Connections interface to set up a site-to-site tunnel in policy mode between two OPNsense machines using key pairs. .. contents:: Index diff --git a/source/manual/how-tos/ipsec-s2s-route-azure.rst b/source/manual/how-tos/ipsec-s2s-route-azure.rst deleted file mode 100644 index 5207edffc..000000000 --- a/source/manual/how-tos/ipsec-s2s-route-azure.rst +++ /dev/null @@ -1,299 +0,0 @@ -================================================ -IPsec VTI - connect to Microsoft Azure -================================================ - -Microsoft Azure offers three VPN types: - -* policy-based (restricted to a single S2S connection) -* route-based -* route-based with BGP (not available in the virtual network gateway SKU "Basic") - -This how-to covers setting up a route-based S2S VPN. - ----------------- -Before you start ----------------- -Before starting with the configuration of an IPsec tunnel you need to have a -working OPNsense installation and an Azure virtual network setup with a unique -LAN IP subnets for each side of your connection (your local networks need to be -different from your remote networks). - -For setting up a Microsoft Azure virtual network and virtual network gateway -refer to the Microsoft Azure documentation: - -https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-site-to-site-resource-manager-portal - ------------- -Sample Setup ------------- -This sample configuration uses an OPNsense box and the basic Azure virtual network -gateway, with the following configuration: - -OPNsense --------- -==================== ============================= - **Hostname** OPNsense - **WAN IP** 1.2.3.4 - **LAN Network** 192.168.1.1/24 -==================== ============================= - -| - ------------------------------ - -Azure ------ - -====================================== ============================= - **Hostname** Azure - **Virtual Network Gateway Public IP** 4.3.2.1 - **Virtual Network Address Space** 192.168.2.0/24 -====================================== ============================= - -| - ------------------------------ - ------------------------ -Firewall Rules OPNsense ------------------------ -To allow IPsec tunnel connections, the following should be allowed on WAN for on -sites (under :menuselection:`Firewall --> Rules --> WAN`): - -* Protocol ESP -* UDP Traffic on port 500 (ISAKMP) -* UDP Traffic on port 4500 (NAT-T) - -.. image:: images/ipsec_wan_rules.png - :width: 100% - -.. Note:: - - You can further limit the traffic by the source IP of the remote host. - -------------------------- -Step 1 - Phase 1 OPNsense -------------------------- -(Under :menuselection:`VPN --> IPsec --> Tunnel Settings` Press **+**) -We will use the following settings: - -General information -------------------- -========================= ============== ====================================================== -**Connection method** Respond only -**Key Exchange version** V2 -**Internet Protocol** IPv4 -**Interface** WAN *Choose the interface connected to the internet* -**Remote gateway** 4.3.2.1 *The public IP address of your Azure virtual network* -**Description** IPsec Azure *Freely chosen description* -========================= ============== ====================================================== - - -Phase 1 proposal (Authentication) ---------------------------------- -=========================== ====================== ====================================== - **Authentication method** Mutual PSK *Using a Pre-shared Key* - **My identifier** My IP address *Simple identification for fixed IP* - **Peer identifier** Peer IP address *Simple identification for fixed IP* - **Pre-Shared Key** At4aDMOAOub2NwT6gMHA *Random key*. **CREATE YOUR OWN!** -=========================== ====================== ====================================== - -Phase 1 proposal (Algorithms) ------------------------------ -========================== =============== =========================================== - **Encryption algorithm** AES 256 *refer to Azure docs for details* - **Hash algorithm** SHA256 - **DH key group** 2 (1024 bit) - **Lifetime** 28800 sec *Lifetime before renegotiation* -========================== =============== =========================================== - -.. Note:: - - Possible parameters are listed here: - https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-devices - - -Advanced Options ----------------- -======================= =========== ======================================================== -**Install Policy** Unchecked *This has to be unchecked since we want plain routing* -**Disable Rekey** Unchecked *Renegotiate when connection is about to expire* -**Disable Reauth** Unchecked *For IKEv2 only re-authenticate peer on rekeying* -**NAT Traversal** Disable *For IKEv2 NAT traversal is always enabled* -**Dead Peer Detection** Unchecked -======================= =========== ======================================================== - - -Save your setting by pressing: - -.. image:: images/btn_save.png - - -------------------------- -Step 2 - Phase 2 OPNsense -------------------------- - -Press the button *+* in front of the phase 1 entry to add a new phase 2. - -As we do not define a local and remote network, we just use tunnel addresses, -you might already know from OpenVPN. In this example we use ``10.111.1.1`` and -``10.111.1.2``. These will be the gateway addresses used for routing - -General information -------------------- -======================= =================== ============================= - **Mode** Route-based *Select Route-based* - **Description** Azure VNET *Freely chosen description* -======================= =================== ============================= - -Tunnel Network --------------- -======================= ================== ===================== - **Local Address** Local Tunnel IP *Set IP 10.111.1.1* - **Remote Address** Remote Tunnel IP *Set IP 10.111.1.2* -======================= ================== ===================== - -Phase 2 proposal (SA/Key Exchange) ----------------------------------- -========================== =========== =================================== -**Protocol** ESP *Choose ESP for encryption* -**Encryption algorithms** AES / 256 *refer to Azure docs for details* -**Hash algorithms** SHA256 -**PFS Key group** off *Not supported* -**Lifetime** 27000 sec -========================== =========== =================================== - -Save your settings by pressing: - -.. image:: images/btn_save.png - ------------------------------ - -Enable IPsec for OPNsense, select: - -.. image:: images/ipsec_s2s_vpn_p1a_enable.png - -Save: - -.. image:: images/btn_save.png - -And apply changes: - -.. image:: images/ipsec_s2s_vpn_p1a_apply.png - :width: 100% - ------------------- - -.. image:: images/ipsec_s2s_vpn_p1a_success.png - :width: 100% - -------------------------- -Step 3 - Set MSS Clamping -------------------------- -(Under :menuselection:`Interfaces --> IPsec Azure`) -We will use the following settings: - -Setup -------------------- -=================================== ====================== ================================================== -**MSS** 1350 *Required* -=================================== ====================== ================================================== - -Leave the other settings as per default. - -Save: - -.. image:: images/btn_save.png - -**You are almost done configuring OPNsense (only some firewall settings remain, which will be addressed later).** -**We will now proceed setting up Azure.** - ------------------------------ - -------------------------------------------- -Step 4 - Azure: Setup local network gateway -------------------------------------------- -(Under `All resources` press **+ Add**, then search and **Create** `Local network gateway`) -We will use the following settings: - -Setup -------------------- -=================================== ====================== ================================================== -**Name** lng.opnsense *Freely chosen name* -**IP address** 1.2.3.4 *The public IP address of your remote OPNsense* -**Address space** 192.168.1.0/24 *LAN Network* -**Address space** 10.111.1.1/32 *Local Tunnel IP* -=================================== ====================== ================================================== - -Press the button that says 'Create': - -.. image:: images/ipsec_s2s_route_azure_lng.png - ------------------------------------- -Step 5 - Azure: Setup VPN connection ------------------------------------- -(Under `All resources --> Virtual network gateway --> Connections` Press **+ Add**) -We will use the following settings: - -General setup -------------------- -=================================== ====================== ================================================== -**Name** vpn.opnsense *Freely chosen name* -**Connection type** Site-to-site (IPsec) -**Virtual network gateway** vpn.gw *Select virtual network gateway* -**Local network gateway** lng.opnsense *Select local network gateway* -**Shared Key (PSK)** At4aDMOAOub2NwT6gMHA *Random key*. **CREATE YOUR OWN!** -=================================== ====================== ================================================== - -Press the button that says 'OK': - -.. image:: images/ipsec_s2s_route_azure_conn.png - ------------------------ -Firewall Rules OPNsense ------------------------ - -To allow traffic passing to your LAN subnet you need to add a rule to the IPsec -interface (under :menuselection:`Firewall --> Rules --> IPsec`). - -.. image:: images/ipsec_ipsec_lan_rule.png - :width: 100% - ------------------- -IPsec Tunnel Ready ------------------- - -The tunnel should now be up and routing the both networks. -Go to :menuselection:`VPN --> IPsec --> Status Overview` to see current status. - ------------------------- -Step 6 - Define Gateways ------------------------- - -Now that you have the VPN up and running you have to set up a gateway. -Go to :menuselection:`System --> Gateways --> Configuration` and add a new gateway. - -OPNsense --------- -================= ============ =============================================================== - **Name** VPNGW *Set a name for your gateway* - **Interface** IPSEC1000 *Choose the IPsec interface* - **IP Address** 10.111.1.2 *Set the peer IP address* - **Far Gateway** Checked *This has to be checked as it is a point-to-point connection* -================= ============ =============================================================== - --------------------------- -Step 7 - Add Static Routes --------------------------- - -When the gateway is set up you can add a route for the Azure virtual network pointing to the new gateway. -Go to :menuselection:`System --> Routes --> Configuration`. - -Route OPNsense --------------- -===================== ================ ============================= - **Network Address** 192.168.2.0/24 *Azure virtual network* - **Gateway** VPNGW *Select the VPN gateway* -===================== ================ ============================= - -Now you are all set! diff --git a/source/manual/how-tos/ipsec-s2s-route.rst b/source/manual/how-tos/ipsec-s2s-route.rst deleted file mode 100644 index 92608d74c..000000000 --- a/source/manual/how-tos/ipsec-s2s-route.rst +++ /dev/null @@ -1,489 +0,0 @@ -================================= -IPsec VTI - Route based setup -================================= - -Most Site-to-Site VPNs are policy-based, which means you define a local and a remote -network (or group of networks). Only traffic matching the defined policy is pushed into the -VPN tunnel. As the demands for more complex and fault tolerant VPN scenarios have grown over the -years, most major router vendors implemented a kind of VPN, the route-based IPSec. - -The difference is that local and remote network is just 0.0.0.0/0, so anything can travel -through the tunnel, it just needs a route. A new Virtual Tunnel Interface (VTI) has to be used -for this. - -There are two benefits for this kind of VPN: - -First, you can set up two tunnels to the same gateway and failover when one line goes down. -Second, you can run dynamic routing protocols over the tunnel to create more redundant, -or software-defined networks. - -.. Note:: - - For a stable setup, we highly advise using standard IPv4 / IPv6 addresses, although the web interface allows the - use of fully qualified domain names (e.g. my.own.domain.xyz), this will have side affects - (the tunnel device won't react on name changes for example). - - ----------------- -Before you start ----------------- -Before starting with the configuration of an IPsec tunnel you need to have a -working OPNsense installation with a unique LAN IP subnet for each side of your -connection (your local network needs a different one than the remote network). - ------------- -Sample Setup ------------- -For the sample configuration we use two OPNsense boxes to simulate a site to site -tunnel, with the following configuration: - -.. sidebar:: Network Site A - - .. nwdiag:: - :scale: 100% - - nwdiag { - - span_width = 90; - node_width = 180; - Internet [shape = "cisco.cloud"]; - pclana [label="PC Site A",shape="cisco.pc"]; - pclana -- switchlana; - - network LANA { - switchlana [label="",shape = "cisco.workgroup_switch"]; - label = " LAN Site A"; - address ="192.168.1.x/24"; - fw1 [address="192.168.1.1/24"]; - tunnel [label=" IPsec Tunnel",shape = cisco.cloud]; - } - - network WANA { - label = " WAN Site A"; - fw1 [shape = "cisco.firewall", address="1.2.3.4/24"]; - Internet; - } - - } - -Site A ------- -==================== ============================= - **Hostname** fw1 - **WAN IP** 1.2.3.4/24 - **LAN IP** 192.168.1.1/24 - **LAN DHCP Range** 192.168.1.100-192.168.1.200 -==================== ============================= - -| -| -| -| - ------------------------------ - -.. sidebar:: Network Site B - - .. nwdiag:: - :scale: 100% - - nwdiag { - - span_width = 90; - node_width = 180; - Internet [shape = "cisco.cloud"]; - pclanb [label="PC Site B",shape="cisco.pc"]; - pclanb -- switchlanb; - - network LANB { - label = " LAN Site B"; - address ="192.168.2.x/24"; - fw2 [address="192.168.2.1/24"]; - tunnel [label=" IPsec Tunnel",shape = cisco.cloud]; - switchlanb [label="",shape = "cisco.workgroup_switch"]; - } - - network WANB { - label = " WAN Site B"; - fw2 [shape = "cisco.firewall", address="4.3.2.1/24"]; - Internet; - } - - } - -Site B ------- - -==================== ============================= - **Hostname** fw2 - **WAN IP** 4.3.2.1/24 - **LAN Net** 192.168.2.0/24 - **LAN DHCP Range** 192.168.2.100-192.168.2.200 -==================== ============================= - -| -| -| -| - ------------------------------ - - -Full Network Diagram Including IPsec Tunnel -------------------------------------------- - -.. nwdiag:: - :scale: 100% - :caption: IPsec Site-to-Site tunnel network - - nwdiag { - - span_width = 90; - node_width = 180; - Internet [shape = "cisco.cloud"]; - pclana [label="PC Site A",shape="cisco.pc"]; - pclana -- switchlana; - - network LANA { - switchlana [label="",shape = "cisco.workgroup_switch"]; - label = " LAN Site A"; - address ="192.168.1.x/24"; - fw1 [address="192.168.1.1/24"]; - tunnel [label=" IPsec Tunnel",shape = cisco.cloud]; - } - - network WANA { - label = " WAN Site A"; - fw1 [shape = "cisco.firewall", address="1.2.3.4/24"]; - Internet; - } - - network WANB { - label = " WAN Site B"; - fw2 [shape = "cisco.firewall", address="4.3.2.1/24"]; - Internet; - } - - network LANB { - label = " LAN Site B"; - address ="192.168.2.x/24"; - fw2 [address="192.168.2.1/24"]; - tunnel; - switchlanb [label="",shape = "cisco.workgroup_switch"]; - } - pclanb [label="PC Site B",shape="cisco.pc"]; - pclanb -- switchlanb; - - } - ---------------------------------------- -Firewall Rules Site A & Site B (part 1) ---------------------------------------- -To allow IPsec tunnel connections, the following should be allowed on WAN for on -sites (under :menuselection:`Firewall --> Rules --> WAN`): - -* Protocol ESP -* UDP Traffic on port 500 (ISAKMP) -* UDP Traffic on port 4500 (NAT-T) - -.. image:: images/ipsec_wan_rules.png - :width: 100% - -.. Note:: - - You can further limit the traffic by the source IP of the remote host. - ------------------------ -Step 1 - Phase 1 Site A ------------------------ -(Under :menuselection:`VPN --> IPsec --> Tunnel Settings` Press **+**) -We will use the following settings: - -General information -------------------- -========================= ============= ================================================== -**Connection method** default *Default is “Start on traffic”* -**Key Exchange version** V2 -**Internet Protocol** IPv4 -**Interface** WAN *Choose the interface connected to the internet* -**Remote gateway** 4.3.2.1 *The public IP address of your remote OPNsense* -**Description** Site B *Freely chosen description* -========================= ============= ================================================== - - -Phase 1 proposal (Authentication) ---------------------------------- -=========================== ====================== ====================================== - **Authentication method** Mutual PSK *Using a Pre-shared Key* - **My identifier** My IP address *Simple identification for fixed IP* - **Peer identifier** Peer IP address *Simple identification for fixed IP* - **Pre-Shared Key** At4aDMOAOub2NwT6gMHA *Random key*. **CREATE YOUR OWN!** -=========================== ====================== ====================================== - - -Phase 1 proposal (Algorithms) ------------------------------ -========================== =============== =========================================== - **Encryption algorithm** AES *For our sample we will use AES/256 bits* - **Hash algorithm** SHA512 *Use a strong hash like SHA512* - **DH key group** 14 (2048 bit) *2048 bit should be sufficient* - **Lifetime** 28800 sec *Lifetime before renegotiation* -========================== =============== =========================================== - - -Advanced Options ----------------- -======================= =========== ======================================================== -**Install Policy** Unchecked *This has to be unchecked since we want plain routing* -**Disable Rekey** Unchecked *Renegotiate when connection is about to expire* -**Disable Reauth** Unchecked *For IKEv2 only re-authenticate peer on rekeying* -**NAT Traversal** Disabled *For IKEv2 NAT traversal is always enabled* -**Dead Peer Detection** Unchecked -======================= =========== ======================================================== - - -Save your setting by pressing: - -.. image:: images/btn_save.png - - ------------------------ -Step 2 - Phase 2 Site A ------------------------ - -Press the button *+* in front of the phase 1 entry to add a new phase 2. - -As we do not define a local and remote network, we just use tunnel addresses, -you might already know from OpenVPN. In this example we use ``10.111.1.1`` and -``10.111.1.2``. These will be the gateway addresses used for routing - -General information -------------------- -======================= ================== ============================= - **Mode** Route-based *Select Route-based* - **Description** Local LAN Site B *Freely chosen description* -======================= ================== ============================= - -Tunnel Network --------------- -======================= ================== ===================== - **Local Address** Local Tunnel IP *Set IP 10.111.1.1* - **Remote Address** Remote Tunnel IP *Set IP 10.111.1.2* -======================= ================== ===================== - -Phase 2 proposal (SA/Key Exchange) ----------------------------------- - -========================== ================ ======================================= -**Protocol** ESP *Choose ESP for encryption* -**Encryption algorithms** AES / 256 *For the sample we use AES 256* -**Hash algorithms** SHA512 *Choose a strong hash like SHA512* -**PFS Key group** 14 (2048 bit) *Not required but enhanced security* -**Lifetime** 3600 sec -========================== ================ ======================================= - -Save your settings by pressing: - -.. image:: images/btn_save.png - ------------------------------ - -Enable IPsec for Site A, select: - -.. image:: images/ipsec_s2s_vpn_p1a_enable.png - -Save: - -.. image:: images/btn_save.png - -And apply changes: - -.. image:: images/ipsec_s2s_vpn_p1a_apply.png - :width: 100% - ------------------- - -.. image:: images/ipsec_s2s_vpn_p1a_success.png - :width: 100% - -**You are almost done configuring Site A (only some firewall settings remain, which will be addressed later).** -**We will now proceed setting up Site B.** - ------------------------------ - ------------------------ -Step 3 - Phase 1 Site B ------------------------ -(Under :menuselection:`VPN --> IPsec --> Tunnel Settings` Press **+**) -We will use the following settings: - -General information -------------------- -========================= ============= ================================================== -**Connection method** Default *Default is 'Start on traffic'* -**Key Exchange version** V2 -**Internet Protocol** IPv4 -**Interface** WAN *Choose the interface connected to the internet* -**Remote gateway** 1.2.3.4 *The public IP address of your remote OPNsense* -**Description** Site A *Freely chosen description* -========================= ============= ================================================== - - -Phase 1 proposal (Authentication) ---------------------------------- -=========================== ====================== ====================================== - **Authentication method** Mutual PSK *Using a Pre-shared Key* - **My identifier** My IP address *Simple identification for fixed ip* - **Peer identifier** Peer IP address *Simple identification for fixed ip* - **Pre-Shared Key** At4aDMOAOub2NwT6gMHA *Random key*. **CREATE YOUR OWN!** -=========================== ====================== ====================================== - - -Phase 1 proposal (Algorithms) ------------------------------ -========================== =============== =========================================== - **Encryption algorithm** AES *For our sample we will use AES/256 bits* - **Hash algorithm** SHA512 *Use a strong hash like SHA512* - **DH key group** 14 (2048 bit) *2048 bit should be sufficient* - **Lifetime** 28800 sec *Lifetime before renegotiation* -========================== =============== =========================================== - - -Advanced Options ----------------- -======================= =========== ======================================================== -**Install Policy** Unchecked *This has to be unchecked since we want plain routing* -**Disable Rekey** Unchecked *Renegotiate when connection is about to expire* -**Disable Reauth** Unchecked *For IKEv2 only re-authenticate peer on rekeying* -**NAT Traversal** Disabled *For IKEv2 NAT traversal is always enabled* -**Dead Peer Detection** Unchecked -======================= =========== ======================================================== - - -Save your setting by pressing: - -.. image:: images/btn_save.png - - ------------------------ -Step 4 - Phase 2 Site B ------------------------ - -Press the button *+* in front of the phase 1 entry to add a new phase 2. - -General information -------------------- -======================= ================== ============================= - **Mode** Route-based *Select Route-based* - **Description** Local LAN Site A *Freely chosen description* -======================= ================== ============================= - -Tunnel Network --------------- -======================= ================== ===================== - **Local Address** Local Tunnel IP *Set IP 10.111.1.2* - **Remote Address** Remote Tunnel IP *Set IP 10.111.1.1* -======================= ================== ===================== - - -Phase 2 proposal (SA/Key Exchange) ----------------------------------- -=========================== =============== ======================================= -**Protocol** ESP *Choose ESP for encryption* -**Encryption algorithms** AES / 256 *For the sample we use AES 256* -**Hash algorithms** SHA512 *Choose a strong hash like SHA512* -**PFS Key group** 14 (2048 bit) *Not required but enhanced security* -**Lifetime** 3600 sec -=========================== =============== ======================================= - - -Save your setting by pressing: - -.. image:: images/btn_save.png - ------------------------------ - -Enable IPsec for Site B, Select: - -.. image:: images/ipsec_s2s_vpn_p1a_enable.png - -Save: - -.. image:: images/btn_save.png - -And apply changes: - -.. image:: images/ipsec_s2s_vpn_p1a_apply.png - :width: 100% - ------------------------------ - -.. image:: images/ipsec_s2s_vpn_p1a_success.png - :width: 100% - ---------------------------------------- -Firewall Rules Site A & Site B (part 2) ---------------------------------------- - -To allow traffic passing to your LAN subnet you need to add a rule to the IPsec -interface (under :menuselection:`Firewall --> Rules --> IPsec`). - -.. image:: images/ipsec_ipsec_lan_rule.png - :width: 100% - ------------------- -IPsec Tunnel Ready ------------------- - -The tunnel should now be up and routing the both networks. -Go to :menuselection:`VPN --> IPsec --> Status Overview` to see current status. - ------------------------- -Step 5 - Define Gateways ------------------------- - -Now that you have the VPN up and running you have to set up a gateway. -Go to :menuselection:`System --> Gateways --> Configuration` and add a new gateway. - -Gateway Site-A --------------- -================= ============ =============================================================== - **Name** VPNGW *Set a name for your gateway* - **Interface** IPSEC1000 *Choose the IPsec interface* - **IP Address** 10.111.1.2 *Set the peer IP address* - **Far Gateway** Checked *This has to be checked as it is a point-to-point connection* -================= ============ =============================================================== - -Gateway Site-B --------------- -================= ============ =============================================================== - **Name** VPNGW *Set a name for your gateway* - **Interface** IPSEC1000 *Choose the IPsec interface* - **IP Address** 10.111.1.1 *Set the peer IP address* - **Far Gateway** checked *This has to be checked as it is a point-to-point connection* -================= ============ =============================================================== - --------------------------- -Step 5 - Add Static Routes --------------------------- - -When gateways are set up you can add a route for the remote network pointing to the new gateway. -On Site-A add a route to Site-B and vice versa. -Go to :menuselection:`System --> Routes --> Configuration`. - -Route Site-A ------------- -===================== ================ ============================= - **Network Address** 192.168.2.0/24 *Set the network of Site-B* - **Gateway** VPNGW *Select the VPN gateway* -===================== ================ ============================= - -Gateway Site-B ---------------- -===================== ================ ============================= - **Network Address** 192.168.1.0/24 *Set the network of Site-A* - **Gateway** VPNGW *Select the VPN gateway* -===================== ================ ============================= - - -Now you are all set! diff --git a/source/manual/how-tos/ipsec-s2s.rst b/source/manual/how-tos/ipsec-s2s.rst deleted file mode 100644 index 0de78dc39..000000000 --- a/source/manual/how-tos/ipsec-s2s.rst +++ /dev/null @@ -1,506 +0,0 @@ -================================ -IPsec - Site to Site tunnel -================================ - -Site to site VPNs connect two locations with static public IP addresses and allow -traffic to be routed between the two networks. This is most commonly used to -connect an organization's branch offices back to its main office, so branch users -can access network resources in the main office. - ----------------- -Before you start ----------------- -Before starting with the configuration of an IPsec tunnel you need to have a -working OPNsense installation with a unique LAN IP subnet for each side of your -connection (your local network need to be different than that of the remote network). - -.. Note:: - - For the sample we will use a private IP for our WAN connection. - This requires us to disable the default block rule on wan to allow private traffic. - To do so, go to :menuselection:`Interfaces --> [WAN]` and uncheck “Block private networks”. - *(Dont forget to save and apply)* - - .. image:: images/block_private_networks.png - ------------------------------ - ------------- -Sample Setup ------------- -For the sample configuration we use two OPNsense boxes to simulate a site to site -tunnel, with the following configuration: - -.. sidebar:: Network Site A - - .. nwdiag:: - :scale: 100% - - nwdiag { - - span_width = 90; - node_width = 180; - Internet [shape = "cisco.cloud"]; - pclana [label="PC Site A",shape="cisco.pc"]; - pclana -- switchlana; - - network LANA { - switchlana [label="",shape = "cisco.workgroup_switch"]; - label = " LAN Site A"; - address ="192.168.1.x/24"; - fw1 [address="192.168.1.1/24"]; - tunnel [label=" IPsec Tunnel",shape = cisco.cloud]; - } - - network WANA { - label = " WAN Site A"; - fw1 [shape = "cisco.firewall", address="172.10.1.1/24"]; - Internet; - } - - } - -Site A ------- -==================== ============================= - **Hostname** fw1 - **WAN IP** 172.10.1.1/24 - **LAN Net** 192.168.1.0/24 - **LAN IP** 192.168.1.1/24 - **LAN DHCP Range** 192.168.1.100-192.168.1.200 -==================== ============================= - -| -| -| -| - ------------------------------ - -.. sidebar:: Network Site B - - .. nwdiag:: - :scale: 100% - - nwdiag { - - span_width = 90; - node_width = 180; - Internet [shape = "cisco.cloud"]; - pclanb [label="PC Site B",shape="cisco.pc"]; - pclanb -- switchlanb; - - network LANB { - label = " LAN Site B"; - address ="192.168.2.x/24"; - fw2 [address="192.168.2.1/24"]; - tunnel [label=" IPsec Tunnel",shape = cisco.cloud]; - switchlanb [label="",shape = "cisco.workgroup_switch"]; - } - - network WANB { - label = " WAN Site B"; - fw2 [shape = "cisco.firewall", address="172.10.2.1/24"]; - Internet; - } - - } - -Site B ------- - -==================== ============================= - **Hostname** fw2 - **WAN IP** 172.10.2.1/24 - **LAN Net** 192.168.2.0/24 - **LAN IP** 192.168.2.1/24 - **LAN DHCP Range** 192.168.2.100-192.168.2.200 -==================== ============================= - -| -| -| -| - ------------------------------ - - -Full Network Diagram Including IPsec Tunnel -------------------------------------------- - -.. nwdiag:: - :scale: 100% - :caption: IPsec Site-to-Site tunnel network - - nwdiag { - - span_width = 90; - node_width = 180; - Internet [shape = "cisco.cloud"]; - pclana [label="PC Site A",shape="cisco.pc"]; - pclana -- switchlana; - - network LANA { - switchlana [label="",shape = "cisco.workgroup_switch"]; - label = " LAN Site A"; - address ="192.168.1.x/24"; - fw1 [address="192.168.1.1/24"]; - tunnel [label=" IPsec Tunnel",shape = cisco.cloud]; - } - - network WANA { - label = " WAN Site A"; - fw1 [shape = "cisco.firewall", address="172.10.1.1/24"]; - Internet; - } - - network WANB { - label = " WAN Site B"; - fw2 [shape = "cisco.firewall", address="172.10.2.1/24"]; - Internet; - } - - network LANB { - label = " LAN Site B"; - address ="192.168.2.x/24"; - fw2 [address="192.168.2.1/24"]; - tunnel; - switchlanb [label="",shape = "cisco.workgroup_switch"]; - } - pclanb [label="PC Site B",shape="cisco.pc"]; - pclanb -- switchlanb; - - } - ---------------------------------------- -Firewall Rules Site A & Site B (part 1) ---------------------------------------- -To allow IPsec Tunnel Connections, the following should be allowed on WAN for on -sites (under :menuselection:`Firewall --> Rules --> WAN`): - -* Protocol ESP -* UDP Traffic on Port 500 (ISAKMP) -* UDP Traffic on Port 4500 (NAT-T) - -.. image:: images/ipsec_wan_rules.png - :width: 100% - -.. Note:: - - You can further limit the traffic by the source IP of the remote host. - ------------------------ -Step 1 - Phase 1 Site A ------------------------ -(Under :menuselection:`VPN --> IPsec --> Tunnel Settings` Press **+**) -We will use the following settings: - -General information -------------------- -========================= ============= ================================================ -**Connection method** default *default is 'Start on traffic'* -**Key Exchange version** V2 -**Internet Protocol** IPv4 -**Interface** WAN *choose the interface connected to the internet* -**Remote gateway** 172.10.2.1 *the public IP address of your remote OPNsense* -**Description** Site B *freely chosen description* -========================= ============= ================================================ - - -Phase 1 proposal (Authentication) ---------------------------------- -=========================== ====================== ====================================== - **Authentication method** Mutual PSK *Using a Pre-shared Key* - **My identifier** My IP address *Simple identification for fixed ip* - **Peer identifier** Peer IP address *Simple identification for fixed ip* - **Pre-Shared Key** At4aDMOAOub2NwT6gMHA *Random key*. **CREATE YOUR OWN!** -=========================== ====================== ====================================== - - -Phase 1 proposal (Algorithms) ------------------------------ -========================== =============== =========================================== - **Encryption algorithm** AES *For our sample we will Use AES/256 bits* - **Hash algorithm** SHA512 *Use a strong hash like SHA512* - **DH key group** 14 (2048 bit) *2048 bit should be sufficient* - **Lifetime** 28800 sec *lifetime before renegotiation* -========================== =============== =========================================== - - -Advanced Options ----------------- -======================= =========== =================================================== -**Disable Rekey** Unchecked *Renegotiate when connection is about to expire* -**Disable Reauth** Unchecked *For IKEv2 only re-authenticate peer on rekeying* -**NAT Traversal** Disabled *For IKEv2 NAT traversal is always enabled* -**Dead Peer Detection** Unchecked -======================= =========== =================================================== - - -Save your setting by pressing: - -.. image:: images/btn_save.png - -Now you should see the following screen: - -.. image:: images/ipsec_s2s_vpn_p1a_4.png - :width: 100% - - ------------------------ -Step 2 - Phase 2 Site A ------------------------ - -Press the button *+* in front of the phase 1 entry to add a new phase 2. - -General information -------------------- -======================= ================== ============================= - **Mode** Tunnel IPv4 *Select Tunnel mode* - **Description** Local LAN Site B *Freely chosen description* -======================= ================== ============================= - -Local Network -------------- -======================= ================== ============================== - **Local Network** LAN subnet *Route the local LAN subnet* -======================= ================== ============================== - -Remote Network --------------- -============== =============== ========================== - **Type** Network *Route a remote network* - **Address** 192.168.2.0/24 *The remote LAN subnet* -============== =============== ========================== - - -Phase 2 proposal (SA/Key Exchange) ----------------------------------- -=========================== =============== ======================================= -**Protocol** ESP *Choose ESP for encryption* -**Encryption algorithms** AES / 256 *For the sample we use AES 256* -**Hash algorithms** SHA512 *Choose a strong hash like SHA512* -**PFS Key group** 14 (2048 bit) *Not required but enhanced security* -**Lifetime** 3600 sec -=========================== =============== ======================================= - -Save your setting by pressing: - -.. image:: images/btn_save.png - ------------------------------ - -Enable IPsec for Site A, Select: - -.. image:: images/ipsec_s2s_vpn_p1a_enable.png - -Save: - -.. image:: images/btn_save.png - -And Apply changes: - -.. image:: images/ipsec_s2s_vpn_p1a_apply.png - :width: 100% - ------------------- - -.. image:: images/ipsec_s2s_vpn_p1a_success.png - :width: 100% - -**You are almost done configuring Site A (only some firewall settings remain, which we'll address later).** -**We will now proceed setting up Site B.** - ------------------------------ - ------------------------ -Step 3 - Phase 1 Site B ------------------------ -(Under :menuselection:`VPN --> IPsec --> Tunnel Settings` Press **+**) -We will use the following settings: - -General information -------------------- -========================= ============= ================================================ -**Connection method** default *default is 'Start on traffic'* -**Key Exchange version** V2 -**Internet Protocol** IPv4 -**Interface** WAN *choose the interface connected to the internet* -**Remote gateway** 172.10.1.1 *the public IP address of your remote OPNsense* -**Description** Site A *freely chosen description* -========================= ============= ================================================ - - -Phase 1 proposal (Authentication) ---------------------------------- -=========================== ====================== ====================================== - **Authentication method** Mutual PSK *Using a Pre-shared Key* - **My identifier** My IP address *Simple identification for fixed ip* - **Peer identifier** Peer IP address *Simple identification for fixed ip* - **Pre-Shared Key** At4aDMOAOub2NwT6gMHA *Random key*. **CREATE YOUR OWN!** -=========================== ====================== ====================================== - - -Phase 1 proposal (Algorithms) ------------------------------ -========================== =============== =========================================== - **Encryption algorithm** AES *For our sample we will Use AES/256 bits* - **Hash algorithm** SHA512 *Use a strong hash like SHA512* - **DH key group** 14 (2048 bit) *2048 bit should be sufficient* - **Lifetime** 28800 sec *lifetime before renegotiation* -========================== =============== =========================================== - - -Advanced Options ----------------- -======================= =========== =================================================== -**Disable Rekey** Unchecked *Renegotiate when connection is about to expired* -**Disable Reauth** Unchecked *For IKEv2 only re-authenticate peer on rekeying* -**NAT Traversal** Disable *For IKEv2 NAT traversal is always enabled* -**Dead Peer Detection** Unchecked -======================= =========== =================================================== - - -Save your setting by pressing: - -.. image:: images/btn_save.png - -Now you should see the following screen: - -.. image:: images/ipsec_s2s_vpn_p1b_4.png - :width: 100% - - ------------------------ -Step 4 - Phase 2 Site B ------------------------ - -Press the button *+* in front of the phase 1 entry to add a new phase 2. - -General information -------------------- -======================= ================== ============================= - **Mode** Tunnel IPv4 *Select Tunnel mode* - **Description** Local LAN Site A *Freely chosen description* -======================= ================== ============================= - - -Local Network -------------- -======================= ================== ============================== - **Local Network** LAN subnet *Route the local LAN subnet* -======================= ================== ============================== - -Remote Network --------------- -============== =============== ========================== - **Type** Network *Route a remote network* - **Address** 192.168.1.0/24 *The remote LAN subnet* -============== =============== ========================== - - -Phase 2 proposal (SA/Key Exchange) ----------------------------------- -=========================== =============== ======================================= -**Protocol** ESP *Choose ESP for encryption* -**Encryption algorithms** AES / 256 *For the sample we use AES 256* -**Hash algorithms** SHA512 *Choose a strong hash like SHA512* -**PFS Key group** 14 (2048 bit) *Not required but enhanced security* -**Lifetime** 3600 sec -=========================== =============== ======================================= - - -Save your setting by pressing: - -.. image:: images/btn_save.png - ------------------------------ - -Enable IPsec for Site B, Select: - -.. image:: images/ipsec_s2s_vpn_p1a_enable.png - :width: 100% - -Save: - -.. image:: images/btn_save.png - -And Apply changes: - -.. image:: images/ipsec_s2s_vpn_p1a_apply.png - :width: 100% - ------------------------------ - -.. image:: images/ipsec_s2s_vpn_p1a_success.png - :width: 100% - ---------------------------------------- -Firewall Rules Site A & Site B (part 2) ---------------------------------------- - -To allow traffic passing to your LAN subnet you need to add a rule to the IPsec -interface (under :menuselection:`Firewall --> Rules --> IPsec`). - -.. image:: images/ipsec_ipsec_lan_rule.png - :width: 100% - ------------------- -IPsec Tunnel Ready ------------------- - -The tunnel should now be up and routing the both networks. -Go to :menuselection:`VPN --> IPsec --> Status Overview` to see current status. -Press on the **(i)** to see the details of the phase 2 tunnel(s), like this: - -.. image:: images/ipsec_status.png - :width: 100% - -.. Note:: - - If the tunnel did not come up, try to restart the service on both ends. - --------------------- -Sample configuration --------------------- -For test purposes we used two OPNsense boxes integrated into one unit and a -cross-cable between the WAN ports. - -To route traffic the WAN interfaces have been configured to use a /16 segment and -they are each others default gateway. Other than that the sample is equal to this -how-to. - -Configuration Site A - :download:`Config.xml Site A ` - -Configuration Site B - :download:`Config.xml Site B ` - ----------------- -Trouble shooting ----------------- - -Phase 1 won't come up ---------------------- -That is a difficult one. First check you firewall rules to see if you allow the -right ports and protocols (ESP, UDP 500 & UDP 4500) for the WAN interface. - -Check your ipsec log to see if that reveals a possible cause. - -Common issues are unequal settings. Both ends must use the -same PSK and encryption standard. - -Phase 1 works but no phase 2 tunnels are connected ---------------------------------------------------- - -Did you set the correct local and remote networks. A common mistake is to fill in -the IP address of the remote host instead of its network ending with **x.x.x.0** - -Common issues are unequal settings. Both ends must use the same encryption standard. - - -.. Note:: - - If you are testing locally with your pc connected to one of the two test boxes - as in the sample configuration, then make sure you have no other network - connections (Wi-Fi, for example). diff --git a/source/manual/how-tos/resources/config-OPNsense-ipsec-Site-A.xml b/source/manual/how-tos/resources/config-OPNsense-ipsec-Site-A.xml deleted file mode 100644 index e7680ebb8..000000000 --- a/source/manual/how-tos/resources/config-OPNsense-ipsec-Site-A.xml +++ /dev/null @@ -1,618 +0,0 @@ - - - 11.2 - opnsense - - - Disable the pf ftp proxy handler. - debug.pfftpproxy - default - - - Increase UFS read-ahead speeds to match current state of hard drives and NCQ. More information here: http://ivoras.sharanet.org/blog/tree/2010-11-19.ufs-read-ahead.html - vfs.read_max - default - - - Set the ephemeral port range to be lower. - net.inet.ip.portrange.first - default - - - Drop packets to closed TCP ports without returning a RST - net.inet.tcp.blackhole - default - - - Do not send ICMP port unreachable messages for closed UDP ports - net.inet.udp.blackhole - default - - - Randomize the ID field in IP packets (default is 0: sequential IP IDs) - net.inet.ip.random_id - default - - - - Source routing is another way for an attacker to try to reach non-routable addresses behind your box. - It can also be used to probe for information about your internal networks. These functions come enabled - as part of the standard FreeBSD core system. - - net.inet.ip.sourceroute - default - - - - Source routing is another way for an attacker to try to reach non-routable addresses behind your box. - It can also be used to probe for information about your internal networks. These functions come enabled - as part of the standard FreeBSD core system. - - net.inet.ip.accept_sourceroute - default - - - - Redirect attacks are the purposeful mass-issuing of ICMP type 5 packets. In a normal network, redirects - to the end stations should not be required. This option enables the NIC to drop all inbound ICMP redirect - packets without returning a response. - - net.inet.icmp.drop_redirect - default - - - - This option turns off the logging of redirect packets because there is no limit and this could fill - up your logs consuming your whole hard drive. - - net.inet.icmp.log_redirect - default - - - Drop SYN-FIN packets (breaks RFC1379, but nobody uses it anyway) - net.inet.tcp.drop_synfin - default - - - Enable sending IPv4 redirects - net.inet.ip.redirect - default - - - Enable sending IPv6 redirects - net.inet6.ip6.redirect - default - - - Enable privacy settings for IPv6 (RFC 4941) - net.inet6.ip6.use_tempaddr - default - - - Prefer privacy addresses and use them over the normal addresses - net.inet6.ip6.prefer_tempaddr - default - - - Generate SYN cookies for outbound SYN-ACK packets - net.inet.tcp.syncookies - default - - - Maximum incoming/outgoing TCP datagram size (receive) - net.inet.tcp.recvspace - default - - - Maximum incoming/outgoing TCP datagram size (send) - net.inet.tcp.sendspace - default - - - IP Fastforwarding - net.inet.ip.fastforwarding - default - - - Do not delay ACK to try and piggyback it onto a data packet - net.inet.tcp.delayed_ack - default - - - Maximum outgoing UDP datagram size - net.inet.udp.maxdgram - default - - - Handling of non-IP packets which are not passed to pfil (see if_bridge(4)) - net.link.bridge.pfil_onlyip - default - - - Set to 0 to disable filtering on the incoming and outgoing member interfaces. - net.link.bridge.pfil_member - default - - - Set to 1 to enable filtering on the bridge interface - net.link.bridge.pfil_bridge - default - - - Allow unprivileged access to tap(4) device nodes - net.link.tap.user_open - default - - - Randomize PIDs (see src/sys/kern/kern_fork.c: sysctl_kern_randompid()) - kern.randompid - default - - - Maximum size of the IP input queue - net.inet.ip.intr_queue_maxlen - default - - - Disable CTRL+ALT+Delete reboot from keyboard. - hw.syscons.kbd_reboot - default - - - Enable TCP extended debugging - net.inet.tcp.log_debug - default - - - Set ICMP Limits - net.inet.icmp.icmplim - default - - - TCP Offload Engine - net.inet.tcp.tso - default - - - UDP Checksums - net.inet.udp.checksum - default - - - Maximum socket buffer size - kern.ipc.maxsockbuf - default - - - - normal - OPNsense - localdomain - - - admins - System Administrators - system - 1999 - 0 - page-all - - - root - System Administrator - system - admins - $6$$Y8Et6wWDdXO2tJZRabvSfQvG2Lc8bAS6D9COIsMXEJ2KjA27wqDuAyd/CdazBQc3H3xQX.JXMKxJeRz2OqTkl. - 0 - user-shell-access - - 2000 - 2000 - Europe/Amsterdam - 300 - 0.nl.pool.ntp.org - - https - 56b9fb5b8286f - - - yes - 1 - - - - hadp - hadp - hadp - - monthly - - - 115200 - serial - - enabled - 1 - 1 - - 1 - - - - em1 - - 1 - - 1 - 172.10.1.1 - 16 - GW - - - 1 - em0 - 192.168.1.1 - 24 - track6 - 64 - - - wan - 0 - - - - - - - - - - 192.168.1.100 - 192.168.1.199 - - - - - - - - - - - - - - - - public - - - - - - - - - - - - - - - automatic - - - - - pass - wan - inet - keep state - IPsec ESP - IPsec Tunnels - esp - - 1 - - - wanip - - - root@192.168.2.100 - - /firewall_rules_edit.php made changes - - - root@192.168.1.100 - - /firewall_rules_edit.php made changes - - - - pass - wan - inet - keep state - IPsec ISAKMP - IPsec Tunnels - tcp/udp - - 1 - - - wanip - 500 - - - root@192.168.1.100 - - /firewall_rules_edit.php made changes - - - root@192.168.1.100 - - /firewall_rules_edit.php made changes - - - - pass - wan - inet - keep state - IPsec NAT-T - IPsec Tunnels - tcp/udp - - 1 - - - wanip - 4500 - - - root@192.168.1.100 - - /firewall_rules_edit.php made changes - - - root@192.168.1.100 - - /firewall_rules_edit.php made changes - - - - pass - inet - Default allow LAN to any rule - lan - - lan - - - - - - - pass - inet6 - Default allow LAN IPv6 to any rule - lan - - lan - - - - - - - pass - enc0 - inet - keep state - Allow IPsec traffic to LAN net - IPsec Tunnels - - 1 - - - lan - - - root@192.168.2.100 - - /firewall_rules_edit.php made changes - - - root@192.168.1.100 - - /firewall_rules_edit.php made changes - - - - - - - - - 1,31 - 0-5 - * - * - * - root - adjkerntz -a - - - 1 - 3 - 1 - * - * - root - /usr/local/etc/rc.update_bogons - - - */60 - * - * - * - * - root - /usr/local/sbin/expiretable -v -t 3600 sshlockout - - - 1 - 1 - * - * - * - root - /usr/local/etc/rc.dyndns.update - - - */60 - * - * - * - * - root - /usr/local/sbin/expiretable -v -t 3600 virusprot - - - 30 - 12 - * - * - * - root - /usr/local/etc/rc.update_urltables - - - - - - - - - - - ICMP - icmp - ICMP - - - - TCP - tcp - Generic TCP - - - - HTTP - http - Generic HTTP - - / - - 200 - - - - HTTPS - https - Generic HTTPS - - / - - 200 - - - - SMTP - send - Generic SMTP - - - 220 * - - - - - system_information-container:col1:show,captive_portal_status-container:col1:close,carp_status-container:col1:close,cpu_graphs-container:col1:close,gateways-container:col1:close,interface_statistics-container:col1:close,interface_list-container:col2:show,ipsec-container:col2:close,load_balancer_status-container:col2:close,log-container:col2:close,picture-container:col2:close,rss-container:col2:close,services_status-container:col2:close,traffic_graphs-container:col2:close - - - root@192.168.2.100 - - /firewall_rules_edit.php made changes - - - 56b9fb5b8286f - webConfigurator default - LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUZiekNDQTFlZ0F3SUJBZ0lKQVB5WVgzRGRzUUJTTUEwR0NTcUdTSWIzRFFFQkN3VUFNRTR4Q3pBSkJnTlYKQkFZVEFrNU1NUlV3RXdZRFZRUUlEQXhhZFdsa0xVaHZiR3hoYm1ReEZUQVRCZ05WQkFjTURFMXBaR1JsYkdoaApjbTVwY3pFUk1BOEdBMVVFQ2d3SVQxQk9jMlZ1YzJVd0hoY05NVFl3TWpBNU1UUTBORFE1V2hjTk1UY3dNakE0Ck1UUTBORFE1V2pCT01Rc3dDUVlEVlFRR0V3Sk9UREVWTUJNR0ExVUVDQXdNV25WcFpDMUliMnhzWVc1a01SVXcKRXdZRFZRUUhEQXhOYVdSa1pXeG9ZWEp1YVhNeEVUQVBCZ05WQkFvTUNFOVFUbk5sYm5ObE1JSUNJakFOQmdrcQpoa2lHOXcwQkFRRUZBQU9DQWc4QU1JSUNDZ0tDQWdFQTNTR2Yvd29vWHQzSDhvUVNLaHNLMis5QTNISHVRWUNzCjB0eS9HaWFNVTN2Z3pKTVVrdWtlelk4YStEQzFnS2pRVkoyMUpFQmVHL2g4eE9VOHM5aWQvTSs5VE5LSEVFRGQKb0poMnZjYjBzZmJtdDgycEFHVDJEanNkRVNEeDErYnNoMktMNEJ2MzQ3N3ZaS0d2UUJWRktncjlVNEtxbS94awpNU09EYUl3ZHgxTVcvVEtNeE53aDhSMkpZVUUzMWN6bkFhcXE0eG5BMGVXWjhyWXAyMmhCbkQxaXdMN1cvWVNuCnprWnhLaVorbjdjUENwVTBod09SblFvOFduYWpvcmFxT0ZkMFJGSTl1bktOQ1k2aEhZUmZ5UHV5WnJxM3dhcEgKTU8xL0EwMWsrK2dBQTNsUW5NdGNVbUpZckRySFpPUGlGQmFaaVkxN0szaTJuNlYrVG9qU1R3L283cjlNMTJTOApaQW9IWCt1d2lvOUwyOW1EYXl0SWpjakl5SzZ6R3hzSWI5QkpxM3JOSFJ4WjBpZUlrVloxN3p0clduaWlMQTB6CnJiMmFWNnJNR3lKQm45WHNST0lHZDF2ajlKdkdFd3hScjhtYXJsSGh1bDZQQ0pFT29VYTBvZkd4bzVhaGZLV1oKNjVkNmhMREVJZHZvU1NCcXNzZ1N3Y2d6a1NOUDdlWmFNYjRBdGlTWFBWa3J3SG5yOHlWVU5jejhYVGhGbk14NwpQb2szNHk0SHZOV091bDdaZzJYUFN3dElUNmxUcFFrajQ4MFJ3UW55aXZJcUFGOEwrM2hMMTRHYXVHVWdzQ2ZaCnlTeFNiMXRMSUhnL0oyYlhESUdsVWdONjh5ZXFjR1FyS3FoQWhvQVVQSUpab0p0cldMZ1FEYm5XYWRlV3IyNzcKTUdNdTlGb3JtM2tDQXdFQUFhTlFNRTR3SFFZRFZSME9CQllFRk13RXRIU0VjRTBWOW80YmYyRTZWbjVtaTFvcQpNQjhHQTFVZEl3UVlNQmFBRk13RXRIU0VjRTBWOW80YmYyRTZWbjVtaTFvcU1Bd0dBMVVkRXdRRk1BTUJBZjh3CkRRWUpLb1pJaHZjTkFRRUxCUUFEZ2dJQkFEaWVpNnMzRElPcnd3NERldXlzYlJValNRSFlyQUl6SHhmNW9ETU4KOGVpYkwyR25DVTZDZENPamJIMVQwMVg4dVVNVTNVaDZIWGJnQ3RESnE1QjduMzNXaDZ1WkxCRkZ1Rkl6L29lWAptTWIxbGZJVEhnTXZuc3FzM3RiU09VQkpiU1RwSGtGeWVnbWFUUE5Nd1ltcWw1VEVlbXNjakMyTTkzL0NIWSt3ClFGU2hpTWVUbUhkdnBQcW0xMkI1SUZOL2x3Qk04REE1dGFVRHJxVytObXVWaE9sdVhKdGlmZlZmSllLNm1LVzcKSFBXYjAzODdzaGpmNDFNeXJodjJMRlU5ZWFsd2t6QmRFNXVpU0ljT1VURFVyQlJaaFpuNDVtVHA3ZnJEeHM2NwplaWE2dzVtZ1VQTElvNndkUlFUbEZtdEU2MmlQdjRsTFFKUFZ0aUFEb1hFTXhVVHBRR2JlRGtZZHU0RFRodGtKCkU5TGV3SjlyOElBUmE0VDMxVUdoRkxzNDJnTTU2bzNWWWJCNDhIc0RVTElRVW83YmxGNENPejRsMmwvRUZpRVUKVlRVMWIrZ3pFMUZLYTdlcUJFNTYvWHczSUQ2d1Vrc1hmYWZsQlI1Y3huUVV1S3dhMnZsdEtNL3o3bFZhc2ZZUQpZRnhTYTlLWnc1MDRyODVLUW9PTmxHMktFeWhZWXhsQ3N6NWR4MlpxMGdUL1cvL1BnbmVFSGpTWE9CR1NvL1dLCnJSejQ2QU4zSUlqMTBIdEx6K1JQQ1VTODAyalJybmRVbjlOeVlsY243cWVEUmFhcm4rWkFjdFludU90ZjdiOUcKaUhJSW9PYTJ6MHZMSnErZW5pOVErbFQxcmc1SXA1S0JwRE0xRWlTU3FyKytZNWhCeGcvSkFlS0Qvc1d4eTZTVAptSkVQCi0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K - LS0tLS1CRUdJTiBQUklWQVRFIEtFWS0tLS0tCk1JSUpRZ0lCQURBTkJna3Foa2lHOXcwQkFRRUZBQVNDQ1N3d2dna29BZ0VBQW9JQ0FRRGRJWi8vQ2loZTNjZnkKaEJJcUd3cmI3MERjY2U1QmdLelMzTDhhSm94VGUrRE1reFNTNlI3Tmp4cjRNTFdBcU5CVW5iVWtRRjRiK0h6RQo1VHl6MkozOHo3MU0wb2NRUU4yZ21IYTl4dlN4OXVhM3pha0FaUFlPT3gwUklQSFg1dXlIWW92Z0cvZmp2dTlrCm9hOUFGVVVxQ3YxVGdxcWIvR1F4STROb2pCM0hVeGI5TW96RTNDSHhIWWxoUVRmVnpPY0JxcXJqR2NEUjVabnkKdGluYmFFR2NQV0xBdnRiOWhLZk9SbkVxSm42ZnR3OEtsVFNIQTVHZENqeGFkcU9pdHFvNFYzUkVVajI2Y28wSgpqcUVkaEYvSSs3Sm11cmZCcWtjdzdYOERUV1Q3NkFBRGVWQ2N5MXhTWWxpc09zZGs0K0lVRnBtSmpYc3JlTGFmCnBYNU9pTkpQRCtqdXYwelhaTHhrQ2dkZjY3Q0tqMHZiMllOckswaU55TWpJcnJNYkd3aHYwRW1yZXMwZEhGblMKSjRpUlZuWHZPMnRhZUtJc0RUT3R2WnBYcXN3YklrR2YxZXhFNGdaM1crUDBtOFlUREZHdnlacXVVZUc2WG84SQprUTZoUnJTaDhiR2pscUY4cFpucmwzcUVzTVFoMitoSklHcXl5QkxCeURPUkkwL3Q1bG94dmdDMkpKYzlXU3ZBCmVldnpKVlExelB4ZE9FV2N6SHMraVRmakxnZTgxWTY2WHRtRFpjOUxDMGhQcVZPbENTUGp6UkhCQ2ZLSzhpb0EKWHd2N2VFdlhnWnE0WlNDd0o5bkpMRkp2VzBzZ2VEOG5adGNNZ2FWU0EzcnpKNnB3WkNzcXFFQ0dnQlE4Z2xtZwptMnRZdUJBTnVkWnAxNWF2YnZzd1l5NzBXaXViZVFJREFRQUJBb0lDQUdoV3RGSzNyVUxON01sT2JlKzJJTktUCnVvd0pxZno0UlJPZG13SXd6Q2VjSFA4S0t6d0NpVWsreTkvdHc4WjRZUXg3K1h1b2IzOU5LVG9TWENrVC9iL0wKR2F3RTdqdktENGoyUjVqV0pxRk9PYURpaG1xc09MbVFSTy9QRnEzanhSbEFjM1dFWE52MlBLakQ3WmdVTVRWYwpTQm0rWHRnSktCRlRpMjZxSm1ibG1zUlB0TUl5aUVWbnhXbkJSeUkzYzR5Q3hlMHdPcDRQY3l0bHJxeGJMaElWCm1PSVBhZ3ZuS3ZLV3BGRGFKd2NmYmhaMVBucXlRV1BTNzVWVHczUkVNbDh4VEtmc0VqcEdVS3dBdzU3VTFnbFUKVWVKTkdlVmtmZ0RsSHZnazdaQTY4TDZ5NEVtTFh2MTBjQmljQjNkZ1cwMVZPSThCMWVzMkl4MkREZXpxZkNoMwpLMEdseitDWGVzMFhIL014UnYrUXR6L3lNVHdTUTd0Zys3Z3gyekh0ejVMaXFrTXNIRDR0K1dBSkVYcFlSRjB4CnhZMmJ2V3hDY2JBdmhuL0ZReStHRlY3NjhBODh6ODE2Wk1NV3Q0NUdQZHNmeU1ZK1ZPOG92eTJpdW4rNEVaNy8KY2JmaHpIWmMxdWVOd2xrcFZaUjdtZ2lpeWNmVXFjNU1PUklxckJ0R3JUVVlKNnBSUHphUG9DdHBXeGozcUNzUApDaWpVM2RIcUE1K0gxRkFaQldWY3dQK1J4aFJ1aW9qblJtRVdIeW85SWYzaDIwVHVKdlNRWFJmTHMxakRzR01kCmdhbURTcnZsenNLVWkyRTFKeTRzSk8rL0ZFanduWHV0R2lFV01WcjN3MmJzMW1sNUdGdHdYZXVhV0o3cXdhblUKbDBtZG9MMk9RMGNNbHJra1g3eHhBb0lCQVFENlp6UUk3azlIdGJXMDFWaC9FWEtiWEdwck96SVR6NWJhc0dwTwoyRHNNSEoxWUs1TU1LeUQ2YXFWUDNrNTMveWI1cGdZTmlqMzZlWnNQd1QyRmc2VmMrQXFrUnQ3RnZBM3B5R1ZlCkp1K3BOSWp0S1BIRTNIMWowb0xML1l4bWdIenpUT3B5eTlHRS9PRmMwK043c1dRUlJCcnFBbHlBcDJLYkEwaVgKSlhRd1p5VGNsNTg4VHNzdE01TFpZRFpKZGhzcURvaDN2Ty9YTWp5Ry9DTUFRakZDMWIrb093dWpJOGdYeU4zMQpVOXN4UDBLVmZNL0ZGS0lodDZKRVdQWnh3Um12anZCcmtLV3AzSllQdENlckxvbWxNRzJQMXA0ZWFMemJWdUFoCmNiSDQ1WWZWSmFGbTJvcEtPS1dIMXdWY2hLeGJ4WnNNSThOZFJqQ3MyVEtQQWxDdEFvSUJBUURpRXU0QmxhT2cKNnY0Vzl2TTQrbEVyT0xZMHVrUm5pV2lzSjdVYzlkK2s4VHNJMmdGTWNFY1JveWtsZ1RoN1B6N1NnaFpzOEhsYQptQk5oaWN4NElLeTY4S1VjZGZQZDAvMzBWQmNkSmNQdGtJY3JXMlJzaXJ3N25QeHZ1S01qcWRVNmhnSkU0MnI5CmlPRFVtZDk5ZEpSbnUzZGhhVjNpSkVaMjdudE1NZGdGelJIaTFoK1Zob012aUE5NjlPZ2YvK1E0SkNYd3ZDVksKRkNjUFk3SVlGZm9vWmExWDIwR09HL2I0TEVRSzF3Tml0eW5WRUp4QWxuVjloY2VYbjJNY291aU9Qdk9CRnd3YQpIRG1Ja21rWWw5Qlhkd21jMGJrWVJTcElmTFFvSnU5bkZwZFhGcU1hKzFxSzUyTDRsdGNUWWhUcGhzU3JzR3dzCk1SV3JFL1BTRHZOOUFvSUJBR0pNSnpvbVN3c01neE5FK1NPUXR0dlVVSlpkdTQvWld3L29WeU15Y1NPVkRCTnoKcjVzRVIwTG1vSlNVNFZycjErSUMwYmQ1QUZHV2NVK2kvVUt2WmpmenkwR243SVhWQitVeFhORzBHVHJrTzZoVgovV3JaWDRQVFBMTlZpa3NtdjJaSFdIWE9HeWJJbXJOMUhvVU5Jd3BBSVF5aDlxd3VpVi91encwK2o3ajhsSlRnCkZJdDVKdnRNbHFZc3hjTGEwVmtXTVc1SHhpTkZQa3VES1Q1TnZjYk40Qm5yYStzVC9kV1FiY21EckxWTmJ4YjkKMHhZN3ZsWGNINkFUQ0ZPcGlTckl3d3FHMHZHMmZWWVcwOGU0VWlKOXUxVE8zRzExa2tYTWVkbkhKeVZjL1pDbgo0QTlmVlJCRDRuOUw0bmZxUVRzWmZIOHNmdUhienZuYm5hUlVOVlVDZ2dFQkFLckZROVljay9LOUw5eG5CSWtZCnhQR1NNRWlhSDR2YVJ5QXNDbXBxN0ZvckFyNEg5NDBuRHZncXVLMGs5R1pjK3ZhRzM2dkE1dHBoSDlyQS9ad00KaW8zWHM5RlE1RHEvcFFqSDhJSExBanBVdjFZbi9pN2ppWmE2V2hHR2RtMDlIOTNLVnJKMDIxL1M0b3FXQlRVKwpOOUEzMHREWmg5cUlMbFl1aFNLa1VCcnBza1lZR3RtWE4wZFRUdVpCVTRyQWdFTk1Rd0NiRHN2cmR5bnYxQnJQCmx4eW0yWThSQjI3eWZ0Y3VrT05qVWFKaTI0MmZzM2d5YjJPM0IzTG9LalQ2ZGhMbFNJbE53STJFbm8wa2s1REoKTk02dEU2eksyemVUSDRLTCtJYVFDcTFqYWtTVnkvVll3eWREN0FYOTQwODMrcllBWUZXVXVkR1Q3bHRCZ2g4OQp2ZjBDZ2dFQURhdXJSNDlLR3k0bDR2bDVQYnQweFE4bGRvc25GYlFhVHhrVDJiNU9EL3RYUVJVM3ZZbXE0ejVBCjR5ejFTbkFmc0lDWWNMazBUYTdHLzkwdjNQTFJjQW5wQWU0eERiRGRJQTQ1anpLWG1RYy9mNTBER2l4WDBuUWQKK3RTNXVyWHVtK01PQi84RnA1Q01kaWxSTDdBSDE3czNvait0QWxxcHV4MHo0cXNQR2dWdlRFbTZJSnh4RmVXMAo0cnVad0QvZVUrN1FaNWx6cVphUEcwTkhzblgrem1odHlMS1ozRmtWZStkVXVUQ3ZVSjJkVXl4OVdJUEhpWS9iCjBhTHV0Sk1DT1lxT1J4a0JqZDNiU3dmNk9zZ1RYUDcyRTN1ZzZzQVRtdGtkZ3lPOHRKc001QlgxUE42RWdOU2gKUFM2dFVvanZKbzJtMDlORkx2ZFdHWlU4QVAxaVZBPT0KLS0tLS1FTkQgUFJJVkFURSBLRVktLS0tLQo= - - - - - ikev2 - wan - main - inet - myaddress - peeraddress - - aes - 256 - - sha512 - 14 - 28800 - At4aDMOAOub2NwT6gMHA - pre_shared_key - Site B - off - - 172.10.2.1 - 1 - - - 1 - 56ba1241e5d1c - tunnel - 14 - 3600 - Local LAN Site B - esp - - lan - - - network -
192.168.2.0
- 24 -
- - aes - 256 - - hmac_sha512 -
- 1 -
- - - wan - 172.10.2.1 - GW - 1 - inet - - Remote Gateway - - - - 1 - - -
diff --git a/source/manual/how-tos/resources/config-OPNsense-ipsec-Site-B.xml b/source/manual/how-tos/resources/config-OPNsense-ipsec-Site-B.xml deleted file mode 100644 index 0179242e7..000000000 --- a/source/manual/how-tos/resources/config-OPNsense-ipsec-Site-B.xml +++ /dev/null @@ -1,642 +0,0 @@ - - - 11.2 - opnsense - - - Disable the pf ftp proxy handler. - debug.pfftpproxy - default - - - Increase UFS read-ahead speeds to match current state of hard drives and NCQ. More information here: http://ivoras.sharanet.org/blog/tree/2010-11-19.ufs-read-ahead.html - vfs.read_max - default - - - Set the ephemeral port range to be lower. - net.inet.ip.portrange.first - default - - - Drop packets to closed TCP ports without returning a RST - net.inet.tcp.blackhole - default - - - Do not send ICMP port unreachable messages for closed UDP ports - net.inet.udp.blackhole - default - - - Randomize the ID field in IP packets (default is 0: sequential IP IDs) - net.inet.ip.random_id - default - - - - Source routing is another way for an attacker to try to reach non-routable addresses behind your box. - It can also be used to probe for information about your internal networks. These functions come enabled - as part of the standard FreeBSD core system. - - net.inet.ip.sourceroute - default - - - - Source routing is another way for an attacker to try to reach non-routable addresses behind your box. - It can also be used to probe for information about your internal networks. These functions come enabled - as part of the standard FreeBSD core system. - - net.inet.ip.accept_sourceroute - default - - - - Redirect attacks are the purposeful mass-issuing of ICMP type 5 packets. In a normal network, redirects - to the end stations should not be required. This option enables the NIC to drop all inbound ICMP redirect - packets without returning a response. - - net.inet.icmp.drop_redirect - default - - - - This option turns off the logging of redirect packets because there is no limit and this could fill - up your logs consuming your whole hard drive. - - net.inet.icmp.log_redirect - default - - - Drop SYN-FIN packets (breaks RFC1379, but nobody uses it anyway) - net.inet.tcp.drop_synfin - default - - - Enable sending IPv4 redirects - net.inet.ip.redirect - default - - - Enable sending IPv6 redirects - net.inet6.ip6.redirect - default - - - Enable privacy settings for IPv6 (RFC 4941) - net.inet6.ip6.use_tempaddr - default - - - Prefer privacy addresses and use them over the normal addresses - net.inet6.ip6.prefer_tempaddr - default - - - Generate SYN cookies for outbound SYN-ACK packets - net.inet.tcp.syncookies - default - - - Maximum incoming/outgoing TCP datagram size (receive) - net.inet.tcp.recvspace - default - - - Maximum incoming/outgoing TCP datagram size (send) - net.inet.tcp.sendspace - default - - - IP Fastforwarding - net.inet.ip.fastforwarding - default - - - Do not delay ACK to try and piggyback it onto a data packet - net.inet.tcp.delayed_ack - default - - - Maximum outgoing UDP datagram size - net.inet.udp.maxdgram - default - - - Handling of non-IP packets which are not passed to pfil (see if_bridge(4)) - net.link.bridge.pfil_onlyip - default - - - Set to 0 to disable filtering on the incoming and outgoing member interfaces. - net.link.bridge.pfil_member - default - - - Set to 1 to enable filtering on the bridge interface - net.link.bridge.pfil_bridge - default - - - Allow unprivileged access to tap(4) device nodes - net.link.tap.user_open - default - - - Randomize PIDs (see src/sys/kern/kern_fork.c: sysctl_kern_randompid()) - kern.randompid - default - - - Maximum size of the IP input queue - net.inet.ip.intr_queue_maxlen - default - - - Disable CTRL+ALT+Delete reboot from keyboard. - hw.syscons.kbd_reboot - default - - - Enable TCP extended debugging - net.inet.tcp.log_debug - default - - - Set ICMP Limits - net.inet.icmp.icmplim - default - - - TCP Offload Engine - net.inet.tcp.tso - default - - - UDP Checksums - net.inet.udp.checksum - default - - - Maximum socket buffer size - kern.ipc.maxsockbuf - default - - - - normal - OPNsense - localdomain - - admins - System Administrators - system - 1999 - 0 - page-all - - - root - System Administrator - system - admins - $6$$Y8Et6wWDdXO2tJZRabvSfQvG2Lc8bAS6D9COIsMXEJ2KjA27wqDuAyd/CdazBQc3H3xQX.JXMKxJeRz2OqTkl. - 0 - user-shell-access - - 2000 - 2000 - Europe/Amsterdam - - 0.nl.pool.ntp.org - - https - 56b0bd0633772 - - - yes - 1 - - - - hadp - hadp - hadp - - monthly - - - 115200 - serial - - enabled - 1 - 1 - - en_US - none - none - none - none - 1 - - - - em1 - WAN - 1 - - 1 - 172.10.2.1 - 16 - WANGW - - - 1 - em0 - LAN - 192.168.2.1 - 24 - track6 - - 0 - - - - - - - - - 1 - - 192.168.2.100 - 192.168.2.199 - - - - - - - 192.168.2.1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - public - - - - - - - - - - - - - - - automatic - - - - - pass - wan - inet - keep state - IPsec ESP - IPsec Tunnels - esp - - 1 - - - wanip - - - root@192.168.2.100 - - /firewall_rules_edit.php made changes - - - root@192.168.2.100 - - /firewall_rules_edit.php made changes - - - - pass - wan - inet - keep state - IPsec ISAKMP - IPsec Tunnels - udp - - 1 - - - wanip - 500 - - - root@192.168.2.100 - - /firewall_rules_edit.php made changes - - - root@192.168.2.100 - - /firewall_rules_edit.php made changes - - - - pass - wan - inet - keep state - IPsec NAT-T - IPsec Tunnels - udp - - 1 - - - wanip - 4500 - - - root@192.168.2.100 - - /firewall_rules_edit.php made changes - - - root@192.168.2.100 - - /firewall_rules_edit.php made changes - - - - pass - inet - Default allow LAN to any rule - lan - - lan - - - - - - - pass - inet6 - Default allow LAN IPv6 to any rule - lan - - lan - - - - - - - pass - enc0 - inet - keep state - IPSec Allow Access to LAN Net - IPsec Tunnels - - 1 - - - lan - - - root@192.168.2.100 - - /firewall_rules_edit.php made changes - - - root@192.168.2.100 - - /firewall_rules_edit.php made changes - - - - - - - - - 1,31 - 0-5 - * - * - * - root - adjkerntz -a - - - 1 - 3 - 1 - * - * - root - /usr/local/etc/rc.update_bogons - - - */60 - * - * - * - * - root - /usr/local/sbin/expiretable -v -t 3600 sshlockout - - - 1 - 1 - * - * - * - root - /usr/local/etc/rc.dyndns.update - - - */60 - * - * - * - * - root - /usr/local/sbin/expiretable -v -t 3600 virusprot - - - 30 - 12 - * - * - * - root - /usr/local/etc/rc.update_urltables - - - - - - - - - - - ICMP - icmp - ICMP - - - - TCP - tcp - Generic TCP - - - - HTTP - http - Generic HTTP - - / - - 200 - - - - HTTPS - https - Generic HTTPS - - / - - 200 - - - - SMTP - send - Generic SMTP - - - 220 * - - - - - system_information-container:col1:show,captive_portal_status-container:col1:close,carp_status-container:col1:close,cpu_graphs-container:col1:close,gateways-container:col1:close,interface_statistics-container:col1:close,interface_list-container:col2:show,ipsec-container:col2:close,load_balancer_status-container:col2:close,log-container:col2:close,picture-container:col2:close,rss-container:col2:close,services_status-container:col2:close,traffic_graphs-container:col2:close - - - root@192.168.2.100 - - /system_gateways_edit.php made changes - - - 56b0bd0633772 - webConfigurator default - LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUZiekNDQTFlZ0F3SUJBZ0lKQUtFRFdCN2RacjdsTUEwR0NTcUdTSWIzRFFFQkN3VUFNRTR4Q3pBSkJnTlYKQkFZVEFrNU1NUlV3RXdZRFZRUUlEQXhhZFdsa0xVaHZiR3hoYm1ReEZUQVRCZ05WQkFjTURFMXBaR1JsYkdoaApjbTVwY3pFUk1BOEdBMVVFQ2d3SVQxQk9jMlZ1YzJVd0hoY05NVFl3TWpBeU1UUXlPRE13V2hjTk1UY3dNakF4Ck1UUXlPRE13V2pCT01Rc3dDUVlEVlFRR0V3Sk9UREVWTUJNR0ExVUVDQXdNV25WcFpDMUliMnhzWVc1a01SVXcKRXdZRFZRUUhEQXhOYVdSa1pXeG9ZWEp1YVhNeEVUQVBCZ05WQkFvTUNFOVFUbk5sYm5ObE1JSUNJakFOQmdrcQpoa2lHOXcwQkFRRUZBQU9DQWc4QU1JSUNDZ0tDQWdFQXJOcG93a3ZIUnhrZ1hTbHQxRmhOL3RCZnRRRW05OElnClU3ZG5SdjhQVk5IVWVnaHRnZjlGL3ZyV3V0cEJ0MzkvQWY2bk45WG5tRjdqUGVBZU5PRXN4VVhBKzFwZ0FsNFgKYlJQdm1seHZJU2lnZDRKR21KMnJHNE14cGM1T1pMbzZaTzgzNDIwZzRLVGFMSUs2L0ptY1YrUFc4dWJxLzJzTQpVcy9Cc0lERUxWUGlzRUJzc08vczE0UmRWZ1RvVG03Q1dzRVFEUlRBd3RpOVVCbVZEWmFKVDd6NDJpTXdaQm9uClNVc05MRTkvVWg5aVYzWlRrSXM0UDdNOVBUc3ZtM2M3QzFhNUZIbkozaVNQR09NaUNjSERzVnRvbUc5ckR2ejAKNFk1Nkd2akorTnJzVG5WcE9yTTBMUEdUYzUvVkdLWkd6R1lOcFR1NG1zS0hIYXFzeEowd2Z0L2JYNWVZSTVBcQpBWEVGcFNJZldpVnQ5eTZ0Wlg2V3JuZFRrdGY0MHJHU2VleFBhdUNycW1nNjhaTTQ3T0lubEJZa2Y1SnRTT1BjCmtKd0dSWjgyL1ZBcG9LY2Izb2M2dlJ6OThnUk9jcXp6anV4WjhJN2lUemRzdFNFQ2NtT0xMR29ObGM1TkFyNVUKNGJndzVLRURSVFV1OGxtYUQ5bFVKUkFrdG93SGYvRUsyVDNrMTNJR2tJZGNDWTN5TWpEcU9KdktKWWZMdU5CMQpvVGJWWUI2ajlxMzc3MjVxYVhubG9SaXV0N3cxWktKVXZJUGFXMXlsK3p6RndMU3ZtbndvcFdLVFlqamlOZmVJCm5Pazdob0ZVYzg3Q1o2MXluMk9FS2JaWlZ6L1k5TElFM2E0UHNZT0FrYVdnekhKQVlyMTNucVYxWW9WYkdqeHEKY25SMUZUSTNCSWtDQXdFQUFhTlFNRTR3SFFZRFZSME9CQllFRkZBK0o5UlNIZ1JKeW1XMmFnVUQvUmhPWnhFNQpNQjhHQTFVZEl3UVlNQmFBRkZBK0o5UlNIZ1JKeW1XMmFnVUQvUmhPWnhFNU1Bd0dBMVVkRXdRRk1BTUJBZjh3CkRRWUpLb1pJaHZjTkFRRUxCUUFEZ2dJQkFJelFDSDJES1luM0puaDBUVWFNejZBbmZtcHFKbDNra0VsKzhqYXYKelFqZ1RIQmJSSzRiQTZWNmRwUXZKOWhlS1pDRGVubVM3QWxaMlB4MWp5UFdTQllCRkc1MTNIQWF1NjVjWXdJUApPb2Myb0NzZzg3eFlnbXRMZ1ZJbk1VYkdtenFuUmdXQTdzclBJZ3ZKNDJCZWhuU29nRlBpVW1hbnRaYTNkYVVVCkg1OTNsME0xRkpTWm9WbUxMZkx2aEtXdUN6ZWp0RWFaYmdtS1dhNHBnZ3Y5NG93NEt3YjlsRVdVNnl4emNjU0QKbTc2K2JzTHRia2lVYTFKdTJjbFRyaG1WWVZkZ1loamlsV0tEdUx6UHJXNnorZHF6Tkk1d3YzRHJ2SHF0Tm5aTgpaNjBBWmsrUlpHZHhYM0lFazRWeUVKeG9hUXI2UkxhU0J2cTYxMk9NYmFMaERteWJvbHBNRW9sR28zRFRURmt4CkN3cE8ybkx4ZStYTjNNc3VMZWMwUWRaeGE2OE1Ca2ZuUFVEcENYSWdvSHhJNzBtUUt0QmVkUUg4RjJwNkNsUG4KeDFpREpWOGhJM2Z4TWpGOUR3OE12TC9XWkxRMUVOWXlzQjZoeHFtVWJpcXlNcDhuT1NtdmQrb3dmOW9Ub1FGcwpOdTQxOVEwejNER1NlSXlxZGdDdWdzZnE2eGtwbTQ1bnBKbnlRN1FuY3EvdFgyNjY2UTc3eVlLdTd2ZmFiMUxrCkljZ0dkRGl2cVFyZDVpa1FCVHZYSmFiVkE2cFlZaFdxcENKUVRGL3N6cW9vNzNTbVFGbWJrdWRBMG42dHpLb1MKK1A2ZEJBV0gybml6bkI3RFJKWno5L2R2aU9LWHVHN010K09GN2lGWk9Na0xqZGtVbC9QS0lQZ25XZ1JSUDM3QQozU3FlCi0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K - LS0tLS1CRUdJTiBQUklWQVRFIEtFWS0tLS0tCk1JSUpSQUlCQURBTkJna3Foa2lHOXcwQkFRRUZBQVNDQ1M0d2dna3FBZ0VBQW9JQ0FRQ3MybWpDUzhkSEdTQmQKS1czVVdFMyswRisxQVNiM3dpQlR0MmRHL3c5VTBkUjZDRzJCLzBYKyt0YTYya0czZjM4Qi9xYzMxZWVZWHVNOQo0QjQwNFN6RlJjRDdXbUFDWGhkdEUrK2FYRzhoS0tCM2drYVluYXNiZ3pHbHprNWt1anBrN3pmamJTRGdwTm9zCmdycjhtWnhYNDlieTV1ci9hd3hTejhHd2dNUXRVK0t3UUd5dzcrelhoRjFXQk9oT2JzSmF3UkFORk1EQzJMMVEKR1pVTmxvbFB2UGphSXpCa0dpZEpTdzBzVDM5U0gySlhkbE9RaXpnL3N6MDlPeStiZHpzTFZya1VlY25lSkk4WQo0eUlKd2NPeFcyaVliMnNPL1BUaGpub2ErTW40MnV4T2RXazZzelFzOFpOem45VVlwa2JNWmcybE83aWF3b2NkCnFxekVuVEIrMzl0Zmw1Z2prQ29CY1FXbEloOWFKVzMzTHExbGZwYXVkMU9TMS9qU3NaSjU3RTlxNEt1cWFEcngKa3pqczRpZVVGaVIva20xSTQ5eVFuQVpGbnpiOVVDbWdweHZlaHpxOUhQM3lCRTV5clBPTzdGbndqdUpQTjJ5MQpJUUp5WTRzc2FnMlZ6azBDdmxUaHVERGtvUU5GTlM3eVdab1AyVlFsRUNTMmpBZC84UXJaUGVUWGNnYVFoMXdKCmpmSXlNT280bThvbGg4dTQwSFdoTnRWZ0hxUDJyZnZ2Ym1wcGVlV2hHSzYzdkRWa29sUzhnOXBiWEtYN1BNWEEKdEsrYWZDaWxZcE5pT09JMTk0aWM2VHVHZ1ZSenpzSm5yWEtmWTRRcHRsbFhQOWowc2dUZHJnK3hnNENScGFETQpja0JpdlhlZXBYVmloVnNhUEdweWRIVVZNamNFaVFJREFRQUJBb0lDQVFDWENvYnQrTythVmY5c3lNM2E5b3E0CjlmWWJvWFVlbkRoSlR3TGxDKzJtclhBZ2JvcmFSR2t5cEpmTVVQbUowZFAydDBJQlRWNEJUREQvbVg1cnNMUEIKY2ZGdThncmhKcjBMcUpiL2FIUUhJb3dOd2YzVVVEbjdZWW1abkF2dWdyaVNDR0xxelNva2dvak95akdBbHU0Qgo4dXFaK0dReWFxVXJHN1hoZUxOejlGQXF1VEVBNzdZaW9OdzZWVEYxajkwdkZuTGpLMVpCTE1sSVhBSmVERVBTCk5JdXplWHBJam4zejBxd2hJeHBiZFdjbWpCUDdRMXdVZFpnMmtDaEtqa1krNHpuNUJXNzdPVEQ5aTBQc0NLL3EKbzdoak0wRDJxTjJHMTB3bGsyNVJrV05hTDhpUzdaTFREd2xNeU1hWnNubzlFNVFxNVdPcmYvNDNVek9DM3VSSApHWlhLNHB6eUZBQU5tSkdlRTUvNm5yM3Ntd0EvbnhMcGNDSUJMbDlvTDg4clVaYXhZeXdCWm41VjZSbzFSVUN6CkRzZytmaE5xbjlVc1pUdXZwQUQ4ekxkVXVuUTQvK09aS3pEbHRwOWhTNEU4MHpXNDMyVUcxb2lKMG5TYXdJOWUKTFJGNWt5bE55SUhaSG5BRWVxZlVacTR2MWhFbmhVUEFKc0tRVjhvNmQ3cDJDdGFoZUYxdnVrM0QzV3RNdWs2NQpQN1h0bktCL2xCUjE3ai9neUdYS0pUc1BIWENURGZuVGxZZU5IZktiMmxZRHZjMnh5N29aZjZ5bWlRbUZ3bVJTCmt6OTFndDFSbVZaVHQ0Z2VRN0VpaVZScjVxdTc3enZxcjlTOXg5NUNOK0NZZFVoWGdXREMxVEZXdVRCaGxPclMKOENHQ3EzMW12Q25WS1NBQlh3ak1BUUtDQVFFQTJiMGo5dG45MXR2VnRCb0NXd3FDL216N3FCTWFkM0ZPTXFvMAprSCtmeFRWYk1ocC8wOEhWYXFmL2F3VTREVXNhNitFa0RJSm9vZkg4NG1BWmVvZXFyRlZJc2xQdkZiNDEzZSt1CmtNOXJxSjZ6Yk5LQ2YyVU5WTTF0ZjRMRkdjNnNuOTBXdGJzY2U3V2VuRFI2Um9ITjgzbHRvMmY4YWEyVW5EaGUKT2dJUEZhb0lJblBJeG8xQ1NSWDloc0dZZ0VObVUydmtVSzNyRXJSMnVlTy8xQ3ZrMjRLUVJVUEdwaDA2cU8zNQp6dGZKZi9naUJ2QThWdHdkYzkzUHVkTE90STBNNVVKNDNSMWpkdjFUN0lHelR4TFZiL2tJcWdXdkk4Mm04TEpTClE0L0hsK1l6Mk1pNUZ2cUJXeFdXN05jT2xsU1hmYTllUkQ1TE1rT3g5MFdZRDRMZ0NRS0NBUUVBeXpvY3JIN3oKeURNa0RQN3E5QysxMHJrYWE1Z0laWlpmcTBMOUExSStDUlJNWitaVGZZcGlZaTNVcHJPZ1lMdHlCMEpvbU9jNApmSWdabk93MFhHOTd4dUZpeWVTdFlGelEyYjJsa0E1ejE1WUNxUTBUNkYyalVsVkFFQXdNS1FTTEpITlo2ZXNsCkFHZkhVa0FPUllNS0JMZmhnVHRQRk5GUTlZT0F2QlNzcC92TmdMZXNUanpLZW10Tk5vZUsxa2ZQMkMwemFiekwKQkNndDR3UEo3UW1WZ2dEbnBCRStWbE1meE1TckhBcUpGNmJKblZKNk5jdWhqK1FzQkJXZFFmL2NJc1pSL2psdQpvT1EwRC9ycThxTkxIUkNLcEpwNWZ1Mk55SlZBZHVScmd0aVhFNHBROVpCTGtVSXRwOUdic0llQjNFcHAvbDd0Cmd0WnlPbFRqdGVzZ2dRS0NBUUVBb0FuL1p5OHUvait5d1ova1gxcElrZzAwbzRMM0R4ZSs3RXBpUEZzeDZkZWYKNGlITUZxNy8yRmNHeTNpWWpGekp1dHBPanN0RGNOVFdsT1VobFFnbWtHaFcrSXZzelVSemYxN3VKZzN2Q1k4cwpQaTQwTU1Mcm00c3FrbkJod3VnL3hYalJlbDIvUDhac2dFK3FHQ3pNWGNyQXBUeUhNSDJmSDN2bTlpZ1JRbEVwCmpYa2c5NTlZT3pQb2xxV3hHNFZ1cnA0OHdIZzBzaGptc3hjTkpqdmxDTnJjZzZ5ZlUvVmo2a3FRTkZJekR0WW8KM0lTek5QeXd3VHNsdFdXVy9PbzNza0s3WjNwMFl6OHI4a2dhcldJZ2N4N09HWG40RXc3VFIxTXFWL0pVTi9mQgozL01ZNkNUVDgwalpGOWV5SnhpaUNJVmZlalYzTzhpNkJBK3BCcTJoVVFLQ0FRQk5heGZkUm9lTDdwOS9LK1ZKCm5KdEJhUzU5YW05WWM4NkNLWVRGTFNGZ3lCRExTOXptYUQ5T2MzTWRCalRFWk9QdGpBallwc3pIOC9qOTVLV1YKeVFwNEd3aE5MUVkzUFdSNmJscVI1RStSQXg2RVUrMFBpZ3hib3dwQ2tyUlhNOW5seXVPbnp1SkxvejAxUWgydApzVnV4ckhNRmpoaDBMOEVOcGtqMlhWSGd0SFgyNFFHTTFHKzE3d1o5RFdtQWM5N2oxV1JPbFpNcFJEMG16Qnl5ClpnSkVnaCs4U3ExYXFWUGkyNkRyajcvbCtLMjVkdUFEZWsxVHlYSlRKQURDVWJ3RXExUTA2cUFRUHA3dXI0R3QKYVRPR0lQVVArNkRwRDRvQnJZbmZRT2tMOFlLcitQY2FkUnUwZkdkMEZNK2draDZRVXZESjdGUENrZnIxNmJ6TgpZb01CQW9JQkFRQ0YrLzZzL0hmemExYStoL3lCNFRacmw1V28wekdTMkp1WEd1YUpHaGxWZ1RldTFzTDBCKzcwClYwTzRYS3E4OW16MW5BaE5RcEZaWDZDU0RyWHFaWXEwV1hDdVppYkVkUEdMc3hYR0kzNk5xb1Voa2FQR0ZobEkKU1JOSzNPZk54cUNaYVpIRWd1MUgwdWRCZEdvV3IzcXI5cWp2MXQ5d1FtdE8xOVBDN1ZzaUMvV2VmV1Rtb3JKcApxcnhQOUtOVXBqVUNUbzE1eVB6c0NNcld1OWp0Y0NFK2pVOXMwY0IzQUQwcW5UZzZJTTlCVXg4UFlhdWV4QTJOCmF1d3orZnB1bDA2OEJTbW15bGFFdmlTeWpLYUlvdVpIQ3RZYU9lYzJGK1ZNVWliL0s3d1JEQ3JtY1VSZUdZTXoKUmpKODZMVmFaWlQyZkM4UnY3T1JEVWtpMS84a3p5ckYKLS0tLS1FTkQgUFJJVkFURSBLRVktLS0tLQo= - - - - - wan - 172.10.1.1 - WANGW - 1 - inet - - Remote Gateway - - - - 1 - - - - - 1 - ikev2 - wan - main - inet - myaddress - peeraddress - - aes - 256 - - sha512 - 14 - 28800 - At4aDMOAOub2NwT6gMHA - pre_shared_key - Site A - off - - 172.10.1.1 - - - 1 - 56bafc7ad40cd - tunnel - 14 - 3600 - Local LAN Site A - esp - - lan - - - network -
192.168.1.0
- 24 -
- - aes - 256 - - hmac_sha512 -
- 1 -
-
diff --git a/source/manual/vpnet.rst b/source/manual/vpnet.rst index e47bcd3b4..9120f014f 100644 --- a/source/manual/vpnet.rst +++ b/source/manual/vpnet.rst @@ -38,29 +38,17 @@ will describe different usecases and provide some examples in this chapter. General context ................................. -The IPsec module incorporates different functions, which are grouped into various menu items. Since the start of our -project we have been offering IPsec features based on the legacy :code:`ipsec.conf` format, which we are migrating to -`swantcl.conf `__ as of version 23.1. While -migrating the existing featureset we came to the conclusion that the world has changed quite a bit and in order to -offer better (api) access to the featureset available we decided to plan for deprecation of the legacy "Tunnel settings" as they -have existed since we started. No timeline has been set, only a feature freeze on tunnels using the "Tunnel settings" menu item. +The IPsec module incorporates different functions, which are grouped into various menu items. IPsec configurations +are managed using Connections and the :code:`swanctl.conf` format. One of the main goals for the long run is to better align the gui components so they reflect the reality underneath, as we use `strongswan `__, our aim is to follow their terminology more closely than we previously did. -The following functions are available in the menu (as of OPNsense 23.1): +The following functions are available in the menu: * Connections - * New configuration tool offering access to the connections and pools sections of the :code:`swanctl` configuration - -* Tunnel Settings - - * Legacy IPsec configuration tool - -* Mobile Clients - - * Offering access to various options of the `attr `__ plugin and pool configurations for legacy tunnels + * Configuration tool offering access to the connections and pools sections of the :code:`swanctl` configuration * Pre-Shared Keys @@ -70,7 +58,7 @@ The following functions are available in the menu (as of OPNsense 23.1): * For public key authentication collect public and private keys. -* Advanced Settings +* Mobile & Advanced Settings * Define passthrough networks (to exclude from kernel traps), logging options and some generic options @@ -92,7 +80,7 @@ The following functions are available in the menu (as of OPNsense 23.1): * Virtual Tunnel Interfaces - * Edit or create new :code:`if_ipsec(4)` interfaces and show the ones created by legacy tunnels + * Edit or create new :code:`if_ipsec(4)` interfaces * Log File @@ -318,9 +306,7 @@ a "kernel route" is installed as well, which traps traffic before normal routing Firewall rules ................................. -When using the legacy tunnels and :code:`Disable Auto-added VPN rules` is not checked in :menuselection:`VPN --> IPsec --> Advanced Settings` -some automatic firewall rules are created for remote hosts connecting to this one. -The new connections feature does not offer this and (WAN) rules have to be specified manually in order to connect to IPsec on this host. +Connections do not add WAN rules automatically, so these have to be specified manually in order to connect to IPsec on this host. The relevant protocols and ports for IPsec are the following: @@ -387,8 +373,8 @@ Route based (VTI) Route based, also known as VTI, tunnels are using a virtual interface known as :code:`if_ipsec(4)`, which can be found under :menuselection:`VPN -> IPsec -> Virtual Tunnel Interfaces`. This links two ends of the communication for routing purposes -after which normal routing applies. The "(Install) Policies" checkmark needs to be disabled in this case for the child (phase 1 in the legacy tunnel configuration) -definition. Usually the communication policy (phase 2 or child) is set to match all traffic (either :code:`0.0.0.0/0` for IPv4 or :code:`::/0` for IPv6). +after which normal routing applies. The "(Install) Policies" checkmark needs to be disabled in this case for the child +definition. Usually the communication policy is set to match all traffic (either :code:`0.0.0.0/0` for IPv4 or :code:`::/0` for IPv6). So the same example as the policy based option would need (static) routes for the destinations in question (:code:`192.168.1.0/24` needs a route to :code:`192.168.2.0/24` and vice versa), peering happens over a small network in another subnet (for example :code:`10.0.0.1` <-> :code:`10.0.0.2`) @@ -444,20 +430,18 @@ Road Warriors / Mobile users IPsec may also be used to service remote workers connecting to OPNsense from various clients, such as Windows, MacOS, iOS and Android. The type of client usually determines the authentication scheme(s) being used. -In case clients should be offered default settings, these can be configured from :menuselection:`VPN -> IPsec -> Mobile Clients`. -Pool options (Virtual IPvX Address Pool) on this page will be used by the legacy tunnel configuration only, when using the new connections -module one may configure different pools per connection. +Address pools for mobile clients can be configured per connection on the ``Pools`` tab in +:menuselection:`VPN -> IPsec -> Connections`. .. note:: - If you are configuring Radius authentication using the new Connections module, make sure to select the relevant Radius servers - in :menuselection:`VPN -> IPsec -> Mobile Clients` under Radius (eap-radius). This pool of servers will be shared across - all connections. This option will not be visible if you have legacy Radius authentication methods configured. + If you are configuring Radius authentication, make sure to select the relevant Radius servers in + :menuselection:`VPN -> IPsec -> Mobile & Advanced Settings` under Radius (eap-radius). This pool of servers will be shared across + all connections. -The examples section contains various options available in OPNsense. When using the new "connections" option available -as of OPNsense 23.1, different `examples from Strongswan `__ -are usually quite easy to implement as we follow the `swantcl.conf `__ -format quite closely in the new module. +The examples section contains various options available in OPNsense. Different +`examples from Strongswan `__ +are usually quite easy to implement as Connections follow the :code:`swanctl.conf` format closely. ................................. Examples @@ -465,7 +449,7 @@ Examples This paragraph offers examples for some commonly used implementation scenarios. -New > 23.1 (:menuselection:`VPN -> IPsec -> Connections`) +Connections (:menuselection:`VPN -> IPsec -> Connections`) ------------------------------------------------------------------------------ .. toctree:: @@ -480,34 +464,9 @@ New > 23.1 (:menuselection:`VPN -> IPsec -> Connections`) .. Tip:: - The number of examples for the new module on our end is limited, but for inspiration it's often a good + The number of examples on our end is limited, but for inspiration it's often a good idea to walkthrough the examples provided by `Strongswan `__. - Quite some swanctl.conf examples are easy to implement in our new module as we do follow the same terminology. - -Legacy (:menuselection:`VPN -> IPsec -> Tunnel Settings`) ------------------------------------------------------------------------------- - - -.. toctree:: - :maxdepth: 2 - :titlesonly: - - how-tos/ipsec-s2s - how-tos/ipsec-s2s-binat - how-tos/ipsec-s2s-route - how-tos/ipsec-s2s-route-azure - how-tos/ipsec-rw - - -The following client setup examples are available in our documentation: - -.. toctree:: - :maxdepth: 2 - :titlesonly: - - how-tos/ipsec-rw-android - how-tos/ipsec-rw-linux - how-tos/ipsec-rw-w7 + Quite some swanctl.conf examples are easy to implement as we do follow the same terminology. .. Note::