{"id":150,"date":"2010-04-17T23:32:14","date_gmt":"2010-04-18T08:32:14","guid":{"rendered":"\/blog\/?p=150"},"modified":"2023-09-21T09:39:19","modified_gmt":"2023-09-21T00:39:19","slug":"openbsd-ipsec-vpn","status":"publish","type":"post","link":"https:\/\/hasu0707.duckdns.org\/blog\/?p=150","title":{"rendered":"OpenBSD IPSec VPN"},"content":{"rendered":"\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">#############<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># IPsec VPN #<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">#############<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Scenariu:<\/FONT><\/SPAN><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Code:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; A.B.C.D &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; X.Y.Z.T<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[ Gateway A ] ---------- { INTERNET } ---------- [ Gateway B ]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp; | &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; |<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp; | 192.168.0.1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; | 192.168.1.1<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp; | &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; |<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp; | &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; |<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; ( LAN A ) &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ( LAN B )<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; 192.168.0.0\/24 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.1.1\/24<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Gateway A = FreeBSD sau OpenBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Gateway B = FreeBSD sau OpenBSD<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">*************************************<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">* Creare tunel intre LAN A si LAN B *<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">*************************************<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+ Gateway A +<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">FreeBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Manual:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ifconfig gif0 tunnel A.B.C.D X.Y.Z.T mtu 1500<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ifconfig gif0 inet 192.168.0.1 192.168.1.1 netmask 255.255.255.255<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">route add -net 192.168.1.0\/24 192.168.1.1<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Automat:<\/FONT><\/SPAN><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">In rc.conf se adauga:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">gifconfig_gif0=\"A.B.C.D X.Y.Z.T mtu 1500\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ifconfig_gif0=\"inet 192.168.0.1 192.168.1.1 netmask 0xffffffff\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">static_routes=\"vpn\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">route_vpn=\"192.168.1.0 192.168.1.1 netmask 0xffffff00\"<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">OpenBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Manual:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ifconfig gif0 tunnel A.B.C.D X.Y.Z.T mtu 1500<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ifconfig gif0 inet 192.168.0.1 192.168.1.1 netmask 255.255.255.255<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">route add -net 192.168.1.0\/24 192.168.1.1<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Automat:<\/FONT><\/SPAN><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Se creaza in \/etc fisierul hostname.gif0 si se adauga:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">up create<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">up tunnel A.B.C.D X.Y.Z.T mtu 1500<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">up inet 192.168.0.1 192.168.1.1 netmask 255.255.255.255<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">!\/sbin\/route add -net 192.168.1.0\/24 192.168.1.1<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+ Gateway B +<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">FreeBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Manual:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ifconfig gif0 tunnel X.Y.Z.T A.B.C.D mtu 1500<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ifconfig gif0 inet 192.168.1.1 192.168.0.1 netmask 255.255.255.255<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">route add -net 192.168.0.0\/24 192.168.0.1<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Automat:<\/FONT><\/SPAN><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">In rc.conf se adauga:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">gifconfig_gif0=\"X.Y.Z.T A.B.C.D mtu 1500\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ifconfig_gif0=\"inet 192.168.1.1 192.168.0.1 netmask 0xffffffff\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">static_routes=\"vpn\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">route_vpn=\"192.168.0.0 192.168.0.1 netmask 0xffffff00\"<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">OpenBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Manual:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ifconfig gif0 tunnel X.Y.Z.T A.B.C.D mtu 1500<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ifconfig gif0 inet 192.168.1.1 192.168.0.1 netmask 255.255.255.255<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">route add -net 192.168.0.0\/24 192.168.0.1<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Automat:<\/FONT><\/SPAN><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Se creaza in \/etc fisierul hostname.gif0 si se adauga:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">up create<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">up tunnel X.Y.Z.T A.B.C.D mtu 1500<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">up inet 192.168.1.1 192.168.0.1 netmask 255.255.255.255<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">!\/sbin\/route add -net 192.168.0.0\/24 192.168.0.1<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">*************************************<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">*(2) IPsec cu schimb manual de chei *<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">*************************************<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Algoritmul de criptare a traficului este 3DES iar cel de autentificare a gateway-urilor intre ele<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">este SHA1.<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+ Gateway A +<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">FreeBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Se creaza in \/etc fisierul ipsec.conf si se adauga:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cheile de autentificare si criptare intre cele doua gateway-uri<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">add A.B.C.D X.Y.Z.T esp 0x1000 -E 3des-cbc 0xCHEIE_CRIPTARE -A hmac-sha1 0xCHEIE_AUTENTIFICARE;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">add X.Y.Z.T A.B.C.D esp 0x1001 -E 3des-cbc 0xCHEIE_CRIPTARE -A hmac-sha1 0xCHEIE_AUTENTIFICARE;<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># criptare IPsec a traficului LAN A - LAN B<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># any inseamna criptare oricarui trafic ( tcp, udp, etc)<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">spdadd 192.168.0.0\/24 192.168.1.0\/24 any -P out ipsec esp\/tunnel\/A.B.C.D-X.Y.Z.T\/require;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">spdadd 192.168.1.0\/24 192.168.0.0\/24 any -P in ipsec esp\/tunnel\/X.Y.Z.T-A.B.C.D\/require;<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># criptare IPsec a traficului Gateway A - Gateway B<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># any inseamna criptare oricarui trafic ( tcp, udp, etc)<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">spdadd A.B.C.D X.Y.Z.T any -P out ipsec esp\/tunnel\/A.B.C.D-X.Y.Z.T\/require;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">spdadd X.Y.Z.T A.B.C.D any -P in ipsec esp\/tunnel\/X.Y.Z.T-A.B.C.D\/require;<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Atentie !!!<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">CHEIE_CRIPTARE este un string format din 48 de litere si cifre (3DES foloseste o cheie pe 192 de biti = 48 * 4 biti)<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">CHEIE_AUTENTIFICARE este un string format din 40 de litere si cifre (SHA1 foloseste o cheie pe 160 de biti = 40 * 4 biti)<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Ambele string-uri trebuie sa fie identice pe cele doua gateway-uri.<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\"0x\" este folosit pentru compatibilitatea cu OpenBSD care foloseste cheile in sistem hexa decimal.<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Pentru generarea cheilor se poate folosi openssl.<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Generare CHEIE_CRIPTARE:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl rand 24 | hexdump -e '24\/1 \"%02x\"'<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Generare CHEIE_AUTENTIFICARE:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl rand 20 | hexdump -e '20\/1 \"%02x\"'<\/SPAN><\/FONT><\/P>\n<P><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Se adauga in \/etc\/rc.conf:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ipsec_enable=\"YES\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ipsec_file=\"\/etc\/ipsec.conf\"<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">OpenBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Se creaza directorul ipsec in \/etc in care se vor crea cheile de autentificare si criptare<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">si script-ul de creare a SAD-urilor si SPD-urilor.<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># mkdir \/etc\/ipsec<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chown root.wheel \/etc\/ipsec<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/etc\/ipsec<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># touch ipsec<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 500 ipsec<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">In fisierul ipsec se adauga:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm new esp -src A.B.C.D -dst X.Y.Z.T -forcetunnel -spi 1000 -enc 3des -auth sha1 \\<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; -keyfile \/etc\/ipsec\/enc_key \\<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; -authkeyfile \/etc\/ipsec\/auth_key<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm new esp -src X.Y.Z.T -dst A.B.C.D -forcetunnel -spi 1001 -enc 3des -auth sha1 \\<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; -keyfile \/etc\/ipsec\/enc_key \\<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; -authkeyfile \/etc\/ipsec\/auth_key<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -transport esp -src A.B.C.D -dst X.Y.Z.T -bypass -out -addr A.B.C.D\/32 X.Y.Z.T\/32<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -transport esp -src A.B.C.D -dst X.Y.Z.T -bypass -in -addr X.Y.Z.T\/32 A.B.C.D\/32<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src A.B.C.D -dst X.Y.Z.T -require -out -addr A.B.C.D\/32 X.Y.Z.T\/32<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src A.B.C.D -dst X.Y.Z.T -require -in -addr X.Y.Z.T\/32 A.B.C.D\/32<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src A.B.C.D -dst X.Y.Z.T -require -out -addr A.B.C.D\/32 192.168.1.0\/24<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src A.B.C.D -dst X.Y.Z.T -require -in -addr 192.168.1.0\/24 A.B.C.D\/32<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src A.B.C.D -dst X.Y.Z.T -require -out -addr 192.168.0.0\/24 X.Y.Z.T\/32<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src A.B.C.D -dst X.Y.Z.T -require -in -addr X.Y.Z.T\/32 192.168.0.0\/24<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src A.B.C.D -dst X.Y.Z.T -require -out -addr 192.168.0.0\/24 192.168.1.0\/24<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src A.B.C.D -dst X.Y.Z.T -require -in -addr 192.168.1.0\/24 192.168.0.0\/24<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Se genereaza cheile.<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Generare cheie criptare:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl rand 24 | hexdump -e '24\/1 \"%02x\"' &gt; \/etc\/ipsec\/enc_key<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Generare cheie autentificare:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl rand 20 | hexdump -e '20\/1 \"%02x\"' &gt; \/etc\/ipsec\/auth_key<\/SPAN><\/FONT><\/P>\n<P><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Se seteaza permisiunile:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chown root.wheel \/etc\/ipsec\/enc_key<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chown root.wheel \/etc\/ipsec\/auth_key<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 600 \/etc\/ipsec\/enc_key<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 600 \/etc\/ipsec\/auth_key<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Observatie !<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Ca alternativa OpenBSD pune la dispozitie un script (\/usr\/share\/ipsec\/rc.vpn) ce seteaza la rulare SAD-urile si SPD-urile.<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Acest script trebuie modificat conform nevoilor si va inlocui script-ul \/etc\/ipsec\/ipsec creat anterior.<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+ Gateway B +<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">FreeBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Se creaza in \/etc fisierul ipsec.conf si se adauga:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cheile de autentificare si criptare intre cele doua gateway-uri<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">add A.B.C.D X.Y.Z.T esp 0x1000 -E 3des-cbc 0xCHEIE_CRIPTARE -A hmac-sha1 0xCHEIE_AUTENTIFICARE;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">add X.Y.Z.T A.B.C.D esp 0x1001 -E 3des-cbc 0xCHEIE_CRIPTARE -A hmac-sha1 0xCHEIE_AUTENTIFICARE;<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># criptare IPsec a traficului LAN B - LAN A<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># any inseamna criptare oricarui trafic ( tcp, udp, etc)<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">spdadd 192.168.1.0\/24 192.168.0.0\/24 any -P out ipsec esp\/tunnel\/X.Y.Z.T-A.B.C.D\/require;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">spdadd 192.168.0.0\/24 192.168.1.0\/24 any -P in ipsec esp\/tunnel\/A.B.C.D-X.Y.Z.T\/require;<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># criptare IPsec a traficului Gateway B - Gateway A<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># any inseamna criptare oricarui trafic ( tcp, udp, etc)<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">spdadd X.Y.Z.T A.B.C.D any -P out ipsec esp\/tunnel\/X.Y.Z.T-A.B.C.D\/require;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">spdadd A.B.C.D X.Y.Z.T any -P in ipsec esp\/tunnel\/A.B.C.D-X.Y.Z.T\/require;<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Se adauga in \/etc\/rc.conf:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ipsec_enable=\"YES\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ipsec_file=\"\/etc\/ipsec.conf\"<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Atentie !!!<\/FONT><\/SPAN><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">CHEIE_CRIPTARE si CHEIE_AUTENTIFICARE trebuie sa coincida cu cele de pe Gateway A.<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">0x1000 si 0x1001 reprezinta parametri SPI si trebuie sa coincida cu cei de pe Gateway A pentru<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">aceeasi directie a treficului (de ex. 0x1000 pentru Gateway A - Gateway B si 0x1001 invers).<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">OpenBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Se creaza directorul ipsec in \/etc si fiserele ipsec, enc_key si auth_key.<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># mkdir \/etc\/ipsec<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chown root.wheel \/etc\/ipsec<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/etc\/ipsec<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># touch ipsec enc_key auth_key<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 500 ipsec<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">In fisierul ipsec se adauga:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm new esp -src X.Y.Z.T -dst A.B.C.D -forcetunnel -spi 1001 -enc 3des -auth sha1 \\<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; -keyfile \/etc\/ipsec\/enc_key \\<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; -authkeyfile \/etc\/ipsec\/auth_key<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm new esp -src A.B.C.D -dst X.Y.Z.T -forcetunnel -spi 1000 -enc 3des -auth sha1 \\<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; -keyfile \/etc\/ipsec\/enc_key \\<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; -authkeyfile \/etc\/ipsec\/auth_key<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -transport esp -src X.Y.Z.T -dst A.B.C.D -bypass -out -addr X.Y.Z.T\/32 A.B.C.D\/32<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -transport esp -src X.Y.Z.T -dst A.B.C.D -bypass -in -addr A.B.C.D\/32 X.Y.Z.T\/32<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src X.Y.Z.T -dst A.B.C.D -require -out -addr X.Y.Z.T\/32 A.B.C.D\/32<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src X.Y.Z.T -dst A.B.C.D -require -in -addr A.B.C.D\/32 X.Y.Z.T\/32<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src X.Y.Z.T -dst A.B.C.D -require -out -addr X.Y.Z.T\/32 192.168.0.0\/24<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src X.Y.Z.T -dst A.B.C.D -require -in -addr 192.168.0.0\/24 X.Y.Z.T\/32<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src X.Y.Z.T -dst A.B.C.D -require -out -addr 192.168.1.0\/24 A.B.C.D\/32<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src X.Y.Z.T -dst A.B.C.D -require -in -addr A.B.C.D\/32 192.168.1.0\/24<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src X.Y.Z.T -dst A.B.C.D -require -out -addr 192.168.1.0\/24 192.168.0.0\/24<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">\/sbin\/ipsecadm flow -proto esp -src X.Y.Z.T -dst A.B.C.D -require -in -addr 192.168.0.0\/24 192.168.1.0\/24<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">In enc_key si auth_key se adauga cheile create pe Gateway A.<\/FONT><\/SPAN><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Se seteaza permisiunile:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chown root.wheel \/etc\/ipsec\/enc_key<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chown root.wheel \/etc\/ipsec\/auth_key<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 600 \/etc\/ipsec\/enc_key<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 600 \/etc\/ipsec\/auth_key<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Observatie !<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Ca alternativa OpenBSD pune la dispozitie un script (\/usr\/share\/ipsec\/rc.vpn) ce seteaza la rulare SAD-urile si SPD-urile.<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Acest script trebuie modificat conform nevoilor si va inlocui script-ul \/etc\/ipsec\/ipsec creat anterior.<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">**************************************************************<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">* IPsec cu schimb automat de chei folosind daemon-ul isakmpd *<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">* cu autentificare pe baza de password *<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">**************************************************************<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+ Gateway A +<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">FreeBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Instalam isakmpd din port-uri:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/usr\/ports\/security\/isakmpd<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># make install clean<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/usr\/local\/etc\/<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># mkdir isakmpd<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd isakmpd<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># touch isakmpd.conf isakmpd.policy<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 600 isakmpd.conf isakmpd.policy<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Fisierul de configurare este \/usr\/local\/etc\/isakmpd\/isakmpd.conf.<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Fisierul ce stabileste autentificarea intre gateway-uri este \/usr\/local\/etc\/isakmpd\/isakmpd.policy.<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.conf:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[General]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Listen-on= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 1]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">X.Y.Z.T= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ISAKMP-peer-GatewayB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 2]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Connections= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPsec-LANA-LANB,IPsec-GatewayA-GatewayB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[ISAKMP-peer-GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 1<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-main-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Authentication= &nbsp; &nbsp; &nbsp; &nbsp; password<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-LANA-LANB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; LANA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; LANB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.0.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.1.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-GatewayA-GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; GatewayA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; GatewayB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-main-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ID_PROT<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Transforms= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 3DES-SHA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-quick-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; QUICK_MODE<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Suites= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; QM-ESP-3DES-SHA-PFS-SUITE<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.policy:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">KeyNote-Version: 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Authorizer: \"POLICY\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Licensees: \"passphrase:password\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Conditions: app_domain == \"IPsec policy\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_present == \"yes\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_enc_alg == \"3des\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_auth_alg == \"hmac-sha\" -&gt; \"true\";<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Atentie !!!<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">password (cel din isakmpd.conf trebuie sa fie identic cu cel din isakmpd.policy)<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">trebuie inlocuit cu un string de preferinta cat mai random ce trebuie sa fie acelasi<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">cu cel din isakmpd.conf si isakmpd.policy de pe GatewayB.<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">In rc.conf trebuie modificat ipsec_enable=\"YES\" in ipsec_enable=\"NO\" deoarece<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">isakmpd seteaza automat atat SAD-urile cat si SPD-urile.<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Cream un script de pornire pentru isakmpd:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/usr\/local\/etc\/rc.d<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># touch isakmpd.sh<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chown root:wheel isakmpd.sh<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 500 isakmpd.sh<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">In isakmpd.sh adaugam:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">#!\/bin\/sh<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># start<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">isakmpd_enable=${isakmpd_enable-\"NO\"}<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">isakmpd_flags=${isakmpd_flags-\"-c \/usr\/local\/etc\/isakmpd\/isakmpd.conf\"}<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">isakmpd_pidfile=${isakmpd_pidfile-\"\/var\/run\/utility.pid\"}<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">. \/etc\/rc.subr<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">name=\"isakmpd\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">rcvar=`set_rcvar`<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">command=\"\/usr\/local\/sbin\/isakmpd\"<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">load_rc_config $name<\/FONT><\/SPAN><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">pidfile=\"${isakmpd_pidfile}\"<\/FONT><\/SPAN><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">start_cmd=\"echo \\\"Starting ${name}.\\\"; \/usr\/bin\/nice -5 ${command} ${isakmpd_flags} ${command_args}\"<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">run_rc_command \"$1\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># end<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Pentru a fi pornit la start-up e necesar sa adaugam in rc.conf isakmpd_enable=\"YES\".<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">OpenBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">OpenBSD vine cu isakmpd instalat default.<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Fisierul de configurare este \/etc\/isakmpd\/isakmpd.conf.<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Fisierul ce stabileste autentificarea intre gateway-uri este \/etc\/isakmpd\/isakmpd.policy.<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.conf:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[General]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Listen-on= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 1]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">X.Y.Z.T= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ISAKMP-peer-GatewayB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 2]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Connections= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPsec-LANA-LANB,IPsec-GatewayA-GatewayB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[ISAKMP-peer-GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 1<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-main-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Authentication= &nbsp; &nbsp; &nbsp; &nbsp; password<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-LANA-LANB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; LANA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; LANB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.0.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.1.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-GatewayA-GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; GatewayA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; GatewayB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-main-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ID_PROT<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Transforms= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 3DES-SHA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-quick-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; QUICK_MODE<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Suites= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; QM-ESP-3DES-SHA-PFS-SUITE<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.policy:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">KeyNote-Version: 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Authorizer: \"POLICY\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Licensees: \"passphrase:password\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Conditions: app_domain == \"IPsec policy\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_present == \"yes\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_enc_alg == \"3des\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_auth_alg == \"hmac-sha\" -&gt; \"true\";<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Atentie !!!<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">password (cel din isakmpd.conf trebuie sa fie identic cu cel din isakmpd.policy)<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">trebuie inlocuit cu un string de preferinta cat mai random ce trebuie sa fie acelasi<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">cu cel din isakmpd.conf si isakmpd.policy de pe GatewayB.<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+ Gateway B +<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">FreeBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Instalam isakmpd din port-uri:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/usr\/ports\/security\/isakmpd<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># make install clean<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/usr\/local\/etc\/<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># mkdir isakmpd<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd isakmpd<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># touch isakmpd.conf isakmpd.policy<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 600 isakmpd.conf isakmpd.policy<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Fisierul de configurare este \/usr\/local\/etc\/isakmpd\/isakmpd.conf.<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Fisierul ce stabileste autentificarea intre gateway-uri este \/usr\/local\/etc\/isakmpd\/isakmpd.policy.<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.conf:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[General]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Listen-on= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 1]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">A.B.C.D= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ISAKMP-peer-GatewayA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 2]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Connections= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPsec-LANB-LANA,IPsec-GatewayB-GatewayA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[ISAKMP-peer-GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 1<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-main-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Authentication= &nbsp; &nbsp; &nbsp; &nbsp; password<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-LANB-LANA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; LANB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; LANA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.1.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.0.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-GatewayB-GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; GatewayB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; GatewayA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-main-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ID_PROT<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Transforms= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 3DES-SHA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-quick-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; QUICK_MODE<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Suites= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; QM-ESP-3DES-SHA-PFS-SUITE<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.policy:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">KeyNote-Version: 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Authorizer: \"POLICY\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Licensees: \"passphrase:password\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Conditions: app_domain == \"IPsec policy\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_present == \"yes\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_enc_alg == \"3des\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_auth_alg == \"hmac-sha\" -&gt; \"true\";<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Atentie !!!<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">password (cel din isakmpd.conf trebuie sa fie identic cu cel din isakmpd.policy)<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">trebuie inlocuit cu un string de preferinta cat mai random ce trebuie sa fie acelasi<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">cu cel din isakmpd.conf si isakmpd.policy de pe GatewayB.<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">In rc.conf trebuie modificat ipsec_enable=\"YES\" in ipsec_enable=\"NO\" deoarece<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">isakmpd seteaza automat atat SAD-urile cat si SPD-urile.<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Cream un script de pornire pentru isakmpd:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/usr\/local\/etc\/rc.d<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># touch isakmpd.sh<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chown root:wheel isakmpd.sh<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 500 isakmpd.sh<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">In isakmpd.sh adaugam:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">#!\/bin\/sh<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># start<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">isakmpd_enable=${isakmpd_enable-\"NO\"}<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">isakmpd_flags=${isakmpd_flags-\"-c \/usr\/local\/etc\/isakmpd\/isakmpd.conf\"}<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">isakmpd_pidfile=${isakmpd_pidfile-\"\/var\/run\/utility.pid\"}<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">. \/etc\/rc.subr<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">name=\"isakmpd\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">rcvar=`set_rcvar`<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">command=\"\/usr\/local\/sbin\/isakmpd\"<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">load_rc_config $name<\/FONT><\/SPAN><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">pidfile=\"${isakmpd_pidfile}\"<\/FONT><\/SPAN><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">start_cmd=\"echo \\\"Starting ${name}.\\\"; \/usr\/bin\/nice -5 ${command} ${isakmpd_flags} ${command_args}\"<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">run_rc_command \"$1\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># end<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Pentru a fi pornit la start-up e necesar sa adaugam in rc.conf isakmpd_enable=\"YES\".<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">OpenBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">OpenBSD vine cu isakmpd instalat default.<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Fisierul de configurare este \/etc\/isakmpd\/isakmpd.conf.<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Fisierul ce stabileste autentificarea intre gateway-uri este \/etc\/isakmpd\/isakmpd.policy.<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.conf:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[General]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Listen-on= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 1]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">A.B.C.D= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ISAKMP-peer-GatewayA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 2]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Connections= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPsec-LANB-LANA,IPsec-GatewayB-GatewayA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[ISAKMP-peer-GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 1<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-main-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Authentication= &nbsp; &nbsp; &nbsp; &nbsp; password<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-LANB-LANA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; LANB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; LANA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.1.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.0.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-GatewayB-GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; GatewayB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; GatewayA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-main-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ID_PROT<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Transforms= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 3DES-SHA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-quick-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; QUICK_MODE<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Suites= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; QM-ESP-3DES-SHA-PFS-SUITE<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.policy:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">KeyNote-Version: 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Authorizer: \"POLICY\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Licensees: \"passphrase:password\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Conditions: app_domain == \"IPsec policy\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_present == \"yes\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_enc_alg == \"3des\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_auth_alg == \"hmac-sha\" -&gt; \"true\";<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Atentie !!!<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">password (cel din isakmpd.conf trebuie sa fie identic cu cel din isakmpd.policy)<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">trebuie inlocuit cu un string de preferinta cat mai random ce trebuie sa fie acelasi<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">cu cel din isakmpd.conf si isakmpd.policy de pe GatewayB.<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">**************************************************************<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">* IPsec cu schimb automat de chei folosind daemon-ul isakmpd *<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">* cu autentificare pe baza de certificate x509 *<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">**************************************************************<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+ Gateway A +<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">FreeBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Devenim Certificate Authority:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/etc\/ssl<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Generam cheia privata cu care vom semna certificatul:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl genrsa -out private\/ca.key 2048<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cream certification request:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl req -new -key private\/ca.key -out ca.csr<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cream certificatul x509:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl x509 -req -days 730 -in ca.csr -signkey private\/ca.key -extfile x509v3.cnf -extensions x509v3_CA -out ca.crt<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/usr\/local\/etc\/isakmpd<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Generam cheia privata:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl genrsa -out private\/local.key 2048<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 400 private\/local.key<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cream certification request:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl req -new -key private\/local.key -out private\/A.B.C.D.csr<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cream certificatul x509 pentru Gateway A:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl x509 -req -days 730 -in private\/A.B.C.D.csr -CA \/etc\/ssl\/ca.crt -CAkey \/etc\/ssl\/private\/ca.key -CAcreateserial -out \\<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">certs\/A.B.C.D.crt<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Patch-uim certificatul:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># certpatch -i A.B.C.D -k \/etc\/ssl\/private\/ca.key certs\/A.B.C.D.crt certs\/A.B.C.D.crt<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Copiem ca.crt in \/usr\/local\/etc\/isakmpd\/ca<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cp -p \/etc\/ssl\/ca.crt ca\/<\/SPAN><\/FONT><\/P>\n<P><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.conf:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[X509-certificates]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">CA-directory= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; \/usr\/local\/etc\/isakmpd\/ca\/<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cert-directory= &nbsp; &nbsp; &nbsp; &nbsp; \/usr\/local\/etc\/isakmpd\/certs\/<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Private-key= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; \/usr\/local\/etc\/isakmpd\/private\/local.key<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[General]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Listen-on= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 1]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">X.Y.Z.T= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ISAKMP-peer-GatewayB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 2]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Connections= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPsec-LANA-LANB,IPsec-GatewayA-GatewayB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[ISAKMP-peer-GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 1<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-main-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp;&nbsp; GatewayA-ID<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp;&nbsp; GatewayB-ID<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayA-ID]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-Type= &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayB-ID]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-Type= &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-LANA-LANB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; LANA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; LANB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.0.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.1.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-GatewayA-GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; GatewayA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; GatewayB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-main-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ID_PROT<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Transforms= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 3DES-SHA-RSA_SIG<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-quick-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; QUICK_MODE<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Suites= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; QM-ESP-3DES-SHA-PFS-SUITE<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.policy:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Keynote-version: 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Authorizer: \"POLICY\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Licensees: \"DN:xxx\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Conditions: app_domain == \"IPsec policy\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_present == \"yes\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_enc_alg == \"3des\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_auth_alg == \"hmac-sha\" -&gt; \"true\";<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">unde xxx este inlocuit cu output-ul comenzii:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl x509 -in \/usr\/local\/etc\/isakmpd\/ca\/ca.crt -noout -subject<\/SPAN><\/FONT><\/P>\n<P><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Atentie !!! Se inlocuieste numai ce este dupa subject= din output-ul de mai sus.<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">OpenBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Devenim Certificate Authority:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/etc\/ssl<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Generam cheia privata cu care vom semna certificatul:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl genrsa -out private\/ca.key 2048<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cream certification request:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl req -new -key private\/ca.key -out ca.csr<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cream certificatul x509:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl x509 -req -days 730 -in ca.csr -signkey private\/ca.key -extfile x509v3.cnf -extensions x509v3_CA -out ca.crt<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/etc\/isakmpd<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Generam cheia privata:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl genrsa -out private\/local.key 2048<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 400 private\/local.key<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cream certification request:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl req -new -key private\/local.key -out private\/A.B.C.D.csr<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cream certificatul x509 pentru Gateway A:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl x509 -req -days 730 -in private\/A.B.C.D.csr -CA \/etc\/ssl\/ca.crt -CAkey \/etc\/ssl\/private\/ca.key -CAcreateserial -out \\<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">certs\/A.B.C.D.crt<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Patch-uim certificatul:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># certpatch -i A.B.C.D -k \/etc\/ssl\/private\/ca.key certs\/A.B.C.D.crt certs\/A.B.C.D.crt<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Copiem ca.crt in \/etc\/isakmpd\/ca<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cp -p \/etc\/ssl\/ca.crt ca\/<\/SPAN><\/FONT><\/P>\n<P><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.conf:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[X509-certificates]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">CA-directory= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; \/usr\/local\/etc\/isakmpd\/ca\/<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cert-directory= &nbsp; &nbsp; &nbsp; &nbsp; \/usr\/local\/etc\/isakmpd\/certs\/<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Private-key= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; \/usr\/local\/etc\/isakmpd\/private\/local.key<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[General]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Listen-on= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 1]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">X.Y.Z.T= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ISAKMP-peer-GatewayB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 2]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Connections= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPsec-LANA-LANB,IPsec-GatewayA-GatewayB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[ISAKMP-peer-GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 1<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-main-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp;&nbsp; GatewayA-ID<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp;&nbsp; GatewayB-ID<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayA-ID]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-Type= &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayB-ID]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-Type= &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-LANA-LANB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; LANA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; LANB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.0.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.1.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-GatewayA-GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; GatewayA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; GatewayB<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-main-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ID_PROT<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Transforms= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 3DES-SHA-RSA_SIG<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-quick-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; QUICK_MODE<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Suites= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; QM-ESP-3DES-SHA-PFS-SUITE<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.policy:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Keynote-version: 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Authorizer: \"POLICY\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Licensees: \"DN:xxx\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Conditions: app_domain == \"IPsec policy\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_present == \"yes\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_enc_alg == \"3des\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_auth_alg == \"hmac-sha\" -&gt; \"true\";<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">unde xxx este inlocuit cu output-ul comenzii:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl x509 -in \/etc\/isakmpd\/ca\/ca.crt -noout -subject<\/SPAN><\/FONT><\/P>\n<P><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Atentie !!! Se inlocuieste numai ce este dupa subject= din output-ul de mai sus.<\/FONT><\/SPAN><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+ Gateway B +<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">+++++++++++++<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">FreeBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Se copiaza \/etc\/ssl\/ca.crt si \/etc\/ssl\/private\/local.key de pe Gateway A in \/etc\/ssl\/ si respectiv \/etc\/ssl\/private.<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/usr\/local\/etc\/isakmpd<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Generam cheia privata:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl genrsa -out private\/local.key 2048<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 400 private\/local.key<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cream certification request:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl req -new -key private\/local.key -out private\/X.Y.Z.T.csr<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cream certificatul x509 pentru Gateway B:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl x509 -req -days 730 -in private\/X.Y.Z.T.csr -CA \/etc\/ssl\/ca.crt -CAkey \/etc\/ssl\/private\/ca.key -CAcreateserial -out \\<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">certs\/X.Y.Z.T.crt<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Patch-uim certificatul:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># certpatch -i X.Y.Z.T -k \/etc\/ssl\/private\/ca.key certs\/X.Y.Z.T.crt certs\/X.Y.Z.T.crt<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Copiem ca.crt in \/usr\/local\/etc\/isakmpd\/ca<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cp -p \/etc\/ssl\/ca.crt ca\/<\/SPAN><\/FONT><\/P>\n<P><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.conf:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[X509-certificates]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">CA-directory= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; \/usr\/local\/etc\/isakmpd\/ca\/<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cert-directory= &nbsp; &nbsp; &nbsp; &nbsp; \/usr\/local\/etc\/isakmpd\/certs\/<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Private-key= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; \/usr\/local\/etc\/isakmpd\/private\/local.key<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[General]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Listen-on= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 1]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">A.B.C.D= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ISAKMP-peer-GatewayA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 2]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Connections= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPsec-LANB-LANA,IPsec-GatewayB-GatewayA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[ISAKMP-peer-GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 1<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-main-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp;&nbsp; GatewayB-ID<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp;&nbsp; GatewayA-ID<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayB-ID]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-Type= &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayA-ID]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-Type= &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-LANB-LANA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; LANB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; LANA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.1.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.0.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-GatewayB-GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; GatewayB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; GatewayA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-main-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ID_PROT<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Transforms= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 3DES-SHA-RSA_SIG<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-quick-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; QUICK_MODE<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Suites= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; QM-ESP-3DES-SHA-PFS-SUITE<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.policy:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Keynote-version: 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Authorizer: \"POLICY\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Licensees: \"DN:xxx\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Conditions: app_domain == \"IPsec policy\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_present == \"yes\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_enc_alg == \"3des\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_auth_alg == \"hmac-sha\" -&gt; \"true\";<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">unde xxx este inlocuit cu output-ul comenzii:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl x509 -in \/usr\/local\/etc\/isakmpd\/ca\/ca.crt -noout -subject<\/SPAN><\/FONT><\/P>\n<P><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Atentie !!! Se inlocuieste numai ce este dupa subject= din output-ul de mai sus.<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">OpenBSD<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">-------<\/SPAN><\/FONT><\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">Se copiaza \/etc\/ssl\/ca.crt si \/etc\/ssl\/private\/local.key de pe Gateway A in \/etc\/ssl\/ si respectiv \/etc\/ssl\/private.<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cd \/etc\/isakmpd<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Generam cheia privata:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl genrsa -out private\/local.key 2048<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># chmod 400 private\/local.key<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cream certification request:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl req -new -key private\/local.key -out private\/X.Y.Z.T.csr<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cream certificatul x509 pentru Gateway B:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl x509 -req -days 730 -in private\/X.Y.Z.T.csr -CA \/etc\/ssl\/ca.crt -CAkey \/etc\/ssl\/private\/ca.key -CAcreateserial -out \\<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">certs\/X.Y.Z.T.crt<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Patch-uim certificatul:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># certpatch -i X.Y.Z.T -k \/etc\/ssl\/private\/ca.key certs\/X.Y.Z.T.crt certs\/X.Y.Z.T.crt<\/SPAN><\/FONT><\/P>\n<P><br \/><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Copiem ca.crt in \/etc\/isakmpd\/ca<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># cp -p \/etc\/ssl\/ca.crt ca\/<\/SPAN><\/FONT><\/P>\n<P><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.conf:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[X509-certificates]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">CA-directory= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; \/usr\/local\/etc\/isakmpd\/ca\/<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Cert-directory= &nbsp; &nbsp; &nbsp; &nbsp; \/usr\/local\/etc\/isakmpd\/certs\/<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Private-key= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; \/usr\/local\/etc\/isakmpd\/private\/local.key<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[General]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Listen-on= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 1]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">A.B.C.D= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ISAKMP-peer-GatewayA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Phase 2]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Connections= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPsec-LANB-LANA,IPsec-GatewayB-GatewayA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[ISAKMP-peer-GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 1<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-main-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp;&nbsp; GatewayB-ID<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp;&nbsp; GatewayA-ID<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayB-ID]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-Type= &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayA-ID]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-Type= &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-LANB-LANA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; LANB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; LANA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.1.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[LANA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR_SUBNET<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Network= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 192.168.0.0<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Netmask= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 255.255.255.0<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[IPsec-GatewayB-GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Phase= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ISAKMP-peer= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ISAKMP-peer-GatewayA<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Configuration= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; Default-quick-mode<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Local-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; GatewayB<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Remote-ID= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; GatewayA<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayB]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; X.Y.Z.T<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[GatewayA]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">ID-type= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPV4_ADDR<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Address= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; A.B.C.D<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-main-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; ID_PROT<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Transforms= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 3DES-SHA-RSA_SIG<\/SPAN><\/FONT><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">[Default-quick-mode]<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">DOI= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; IPSEC<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">EXCHANGE_TYPE= &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; QUICK_MODE<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Suites= &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; QM-ESP-3DES-SHA-PFS-SUITE<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"><FONT face=\"GulimChe, Sans-serif\">isakmpd.policy:<\/FONT><\/SPAN><\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Keynote-version: 2<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Authorizer: \"POLICY\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Licensees: \"DN:xxx\"<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Conditions: app_domain == \"IPsec policy\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_present == \"yes\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_enc_alg == \"3des\" &amp;&amp;<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; esp_auth_alg == \"hmac-sha\" -&gt; \"true\";<\/SPAN><\/FONT><\/P>\n<P>&nbsp;<\/P>\n<P><FONT face=\"GulimChe, Sans-serif\"><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">unde xxx este inlocuit cu output-ul comenzii:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\">Code:<\/SPAN><br \/><SPAN style=\"FONT-FAMILY: \uad74\ub9bc\uccb4\"># openssl x509 -in \/etc\/isakmpd\/ca\/ca.crt -noout -subject<\/SPAN><\/FONT><\/P>\n","protected":false},"excerpt":{"rendered":"<p>############## IPsec VPN ############## Scenariu: Code: &nbsp; &nbsp; &nbsp; &nbsp; A.B.C.D &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; X.Y.Z.T[ Gateway A ] &#8212;&#8212;&#8212;- { INTERNET } &#8212;&#8212;&#8212;- [ Gateway B ]&nbsp; &nbsp; &nbsp; &nbsp;&nbsp; | &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_import_markdown_pro_load_document_selector":0,"_import_markdown_pro_submit_text_textarea":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[39],"tags":[],"class_list":["post-150","post","type-post","status-publish","format-standard","hentry","category-os_linux_unix_macos"],"_links":{"self":[{"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=\/wp\/v2\/posts\/150","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=150"}],"version-history":[{"count":0,"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=\/wp\/v2\/posts\/150\/revisions"}],"wp:attachment":[{"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=150"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=150"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=150"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}