par post » 18 Fév 2004 22:18
Merci pour vos reponses je m'y remet
<BR> IPCop v1.4.0a1 - The Bad Packets Stop Here
<BR>
<BR>ipsec verify
<BR>Checking your system to see if IPsec got installed and started correctly
<BR>Version check and ipsec on-path [OK]
<BR>Checking for KLIPS support in kernel [OK]
<BR>Checking for RSA private key (/etc/ipsec.secrets) ipsec showhostkey: no default key in "/etc/ipsec.secrets"
<BR>[FAILED]
<BR>Checking that pluto is running [OK]
<BR>DNS checks.
<BR>Looking for forward key for cem /usr/local/lib/ipsec/verify: host: command not found
<BR>[NO KEY]
<BR>Does the machine have at least one non-private address [OK]
<BR>
<BR>
<BR>cat ipsec.conf
<BR>config setup
<BR> interfaces=%defaultroute
<BR> klipsdebug=none
<BR> plutodebug=none
<BR> plutoload=%search
<BR> plutostart=%search
<BR> uniqueids=yes
<BR> nat_traversal=yes
<BR> virtual_private=%v4:10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16,%v4:!192.168.0.0/255.255.0.0,%v4:!192.168.0.0/255.255.0.0
<BR>
<BR>conn %default
<BR> keyingtries=0
<BR> disablearrivalcheck=no
<BR>
<BR>conn mexcem
<BR> left=aa.aa.aa.aaa
<BR> leftsubnet=192.168.0.0/255.255.255.0
<BR> leftnexthop=%defaultroute
<BR> right=bb.bb.bb.bbb
<BR> rightsubnet=192.168.1.0/255.255.255.0
<BR> rightnexthop=%defaultroute
<BR> dpddelay=30
<BR> dpdtimeout=120
<BR> dpdaction=hold
<BR> authby=secret
<BR> auto=add
<BR>
<BR>cat ipsec.secrets
<BR>aa.aa.aa.aaa bb.bb.bb.bbb: PSK "reposer145"
<BR>
<BR>cat rc.firewall
<BR>
<BR>
<BR> # Allow IPSec
<BR> if [ "$VPNENABLE" = "on" ]; then
<BR> /sbin/iptables -I INPUT -i ipsec0 -j ACCEPT ajout sur post belugha
<BR> /sbin/iptables -I OUTPUT -o ipsec0 -j ACCEPT ajout sur post belugha
<BR> /sbin/iptables -A IPSECRED -p 47 -i $IFACE -j ACCEPT
<BR> /sbin/iptables -A IPSECRED -p 50 -i $IFACE -j ACCEPT
<BR> /sbin/iptables -A IPSECRED -p 51 -i $IFACE -j ACCEPT
<BR> /sbin/iptables -A IPSECRED -p udp -i $IFACE --sport 500 --dport 500 -j ACCEPT
<BR> /sbin/iptables -A IPSECRED -p udp -i $IFACE --sport 4500 --dport 4500 -j ACCEPT
<BR> fi
<BR>
<BR> # Outgoing masquerading
<BR> /sbin/iptables -t nat -A RED -o $IFACE -j MASQUERADE
<BR>
<BR>sur left ipsec auto --up mexcem ca bloque , j'espere vous lire bientot Merci
<BR>
<BR>
<BR>
<BR>
<BR>
<BR>
<BR> <IMG SRC="images/smiles/icon_bawling.gif"> <IMG SRC="images/smiles/icon_bawling.gif"> <IMG SRC="images/smiles/icon_bawling.gif"> <IMG SRC="images/smiles/icon_bawling.gif"> <BR><BR><font size=-2></font>
La nuit porte conseil et le sot porte l'eau ou le contraire ...